Skip to content
Klyo Changelog

All open dependency advisories closed across the web and gateway images

The shipped web and gateway images are rebuilt to clear every open dependency advisory — 39 in total, spanning 18 high, 19 medium, and 2 low severity.

The bundled web framework upgrade closes several vulnerabilities, including server-side request forgery in server actions and rewrites, a response-cache confusion issue, denial-of-service paths in image and server-action handling, and disclosure of internal server-function endpoints. Additional fixes land in the image-decoding, HTTP-client, and HTML-sanitization libraries.

The e-mail client is upgraded to close a man-in-the-middle response-injection window during the SMTP STARTTLS handshake and to reject CR/LF in sender and recipient addresses.

No functional behavior changes; the images no longer carry the known-vulnerable versions.

Self-hosted operators must rebuild and recreate the web and gateway containers to pick up the fixes.