- CVE-2026-27696 - Server-Side Request Forgery (SSRF) via Watch URLs, set env var
ALLOW_IANA_RESTRICTED_ADDRESSEStotrueto access IANA reserved URLs such as http://169.254.169.254, http://10.0.0.1/, http://127.0.0.1/, etc. - CVE-2026-27645 - Reflected XSS in RSS Single Watch request
Full Changelog: 0.53.7...0.54.1