github dunglas/mercure v1.1.1

5 hours ago

Community

Mercure 1.1.1 is a security and maintenance release. It upgrades golang.org/x/net to 0.60.0, fixing five HTTP/2 advisories reachable from the hub, including a server crash triggered by an HPACK encoder race. Subscriber logs now include the client IP, and the debugger UI recovers when the hub closes its stream. Upgrading is recommended for every 1.x deployment.

🐛 Bug Fixes

  • Security: upgrade golang.org/x/net to 0.60.0 to fix reachable HTTP/2 vulnerabilities: server crash due to an HPACK encoder race (GO-2026-6617), memory exhaustion through trailer headers (GO-2026-6603), excessive CPU from repeated initial window changes (GO-2026-6611), double flow control refund on server streams (GO-2026-6612), and malformed framing headers accepted by the transport (GO-2026-6610). by @dunglas in #1434
  • Logging: the "New subscriber" and "Subscriber disconnected" lines now log client_ip, and again log the subscriber field (ID, last event ID, matchers) lost in the switch to slog, so connections and disconnections can be correlated. The Caddy module always resolves the client IP through trusted_proxies, not only when subscription_limits is set. by @dunglas in #1432
  • Debugger: the subscribe and active subscriptions streams reconnect, resending Last-Event-ID, when the hub closes them (for instance when write_timeout expires or on shutdown). They previously stayed disconnected. by @dunglas in #1433

📖 Documentation

Enterprise

Mercure Enterprise picks up the same fixes in image v1.1.1, built with Go 1.27.2, which also fixes reachable net/http, HTTP/2 and html/template advisories in the standard library. Mercure Cloud hubs are upgraded automatically: use Mercure Cloud to get fixes like these without managing upgrades yourself.

Enterprise releases ship under the Enterprise SLA, with prioritized patches and direct support. Contact contact@mercure.rocks for the managed Cloud offering, on-premise licenses, custom development, consulting, and training.

Full Changelog: v1.1.0...v1.1.1

Don't miss a new mercure release

NewReleases is sending notifications on new releases.