- Prevent Host header injection attacks on the password recovery endpoint. A new setting
commafeed.password-recovery-public-base-urlhas been added to specify the base URL to use in password recovery
emails (GHSA-hp8h-jqfm-v7x5). This setting is only required when the password recovery feature is enabled, which is not the default.