github Kozea/Radicale v3.8.3
3.8.3 Fixes (Security)

4 hours ago

Fixes (Security)

  • Fix: auth: clear rights/user_groups before conditional set depending on group_type/auth_type
    • credits to @d3do-23 reporting this as FO-RAD-2026-001 incl. suggestion for a fix
  • Fix: [group] htgroup: fix not working htgroup_cache=True
    • credits to @d3do-23 reporting this as FO-RAD-2026-002 incl. suggestion for a fix

Warning

Related to FO-RAD-2026-001, users which are using group-membership (LDAP/PAM/htgroup] based sharings are adviced to update immediately to 3.8.3 or at least apply manually a fix and restart the server:

File: radicale/app/__init__.py

  • Version >= 3.8.0 (around line 600)
+        self._rights._user_groups = set([])
         if user:
            group_type = self.configuration.get("group", "type")
  • Version >= 3.3.0 && < 3.8.0 (around line 550)
+       self._rights._user_groups = set([])
        if self.configuration.get("auth", "type") == "ldap":
            try:

Note

Updated builds for Fedora/EL are already available for direct download https://koji.fedoraproject.org/koji/packageinfo?packageID=16893

Don't miss a new Radicale release

NewReleases is sending notifications on new releases.