Docker images
Product Highlights
- Big feature release focused on game discovery and management quality of life.
- Added Steam wishlist sync, richer game details (IGDB, HowLongToBeat, PCGamingWiki, NexusMods), user ratings, and better download linking.
- New filters and controls across library, wishlist, calendar, and downloads.
- New stats page with Discord sharing support.
- Improved settings for preferred platform, preferred release groups, and auto-search behavior.
Security and Reliability
- Multiple SSRF fixes (including DNS rebinding hardening).
- Stronger login protection with brute-force rate limiting.
- Fixed credential exposure and information leakage risks.
- Addressed known vulnerabilities in dependencies (notably axios and node-forge).
Performance and UX Improvements
- Lazy loading for heavy dialogs and details screens.
- Better server-side filtering and memoization for faster browsing/search.
- Streamlined Steam behavior and improved IGDB data retrieval.
- Cleaner toolbar/search behavior and better notification relevance.
Bug Fixes
- Multiple downloader and indexer stability fixes (SABnzbd, Transmission, rTorrent, Torznab/Prowlarr).
- Fixed sorting, sticky headers, overflow/layout issues, and several UI state inconsistencies.
- Improved handling of API retry behavior and validation edge cases.
Dependency Updates
- Runtime dependencies updated for stability and security.
- Development dependencies refreshed as a batch.
- CI toolchain dependencies updated.
- Security-driven package upgrades included in multiple releases.
Addressed Vulnerabilities
- fast-xml-parser 5.3.7 → 5.7.1 — fixes 4 CVEs:
- CVE-2026-33036 (GHSA-8gc5-j5rx-235r, HIGH) — numeric entity expansion bypassing all expansion limits (incomplete fix for CVE-2026-26278)
- CVE-2026-27942 (GHSA-fj3w-jwp8-x2g3, LOW) — stack overflow in XMLBuilder with
preserveOrder - CVE-2026-41650 (GHSA-gh4j-gqv2-49f6, MODERATE) — XML Comment/CDATA injection via unescaped delimiters
- CVE-2026-33349 (GHSA-jp2q-39xq-3w4g, MODERATE) — entity expansion limit bypassed when set to
0(JS falsy-evaluation bug)
- node-forge 1.3.3 → 1.4.0 — fixes 4 CVEs:
- CVE-2026-33896 (GHSA-2328-f5f3-gj25, HIGH) —
basicConstraints/RFC 5280 cert-chain validation bypass - CVE-2026-33891 (GHSA-5m6q-g25r-mvwx, HIGH) — DoS via
BigInteger.modInverse(0)infinite loop - CVE-2026-33894 (GHSA-ppp5-5v6c-4jwp, HIGH) — RSA-PKCS1 v1.5 signature forgery (Bleichenbacher-style)
- CVE-2026-33895 (GHSA-q67f-28xg-22rw, HIGH) — Ed25519 signature malleability (missing canonical-scalar check)
- CVE-2026-33896 (GHSA-2328-f5f3-gj25, HIGH) —
- socket.io-parser (npm
overridespin) 4.2.5 → 4.2.6 — fixes CVE-2026-33151 (GHSA-677m-j7p3-52f9, HIGH) — unbounded binary attachments DoS - drizzle-orm 0.45.1 → 0.45.2 — fixes CVE-2026-39356 (GHSA-gpj5-g38j-94v9, HIGH) — SQL injection via improperly escaped SQL identifiers
- express-rate-limit 8.2.1 → 8.3.2 — fixes CVE-2026-30827 (GHSA-46wh-pxpv-q5gq, HIGH) — IPv4-mapped IPv6 addresses bypass per-client rate limiting on dual-stack servers
- multer 2.0.2 → 2.1.1 — fixes 3 of 5 CVEs present since multer's introduction in v1.2.1:
- CVE-2026-3520 (GHSA-5528-5vmv-3xc2, HIGH) — DoS via uncontrolled recursion
- CVE-2026-2359 (GHSA-v52c-386h-88mc, HIGH) — DoS via resource exhaustion
- CVE-2026-3304 (GHSA-xf7r-hgr6-v32p, HIGH) — DoS via incomplete cleanup
Full Changelog: https://github.com/Doezer/Questarr/blob/main/docs/CHANGELOG.md - Commits: v1.2.2...v1.3.0