Community
Mercure 1.1.1 is a security and maintenance release. It upgrades golang.org/x/net to 0.60.0, fixing five HTTP/2 advisories reachable from the hub, including a server crash triggered by an HPACK encoder race. Subscriber logs now include the client IP, and the debugger UI recovers when the hub closes its stream. Upgrading is recommended for every 1.x deployment.
🐛 Bug Fixes
- Security: upgrade
golang.org/x/netto 0.60.0 to fix reachable HTTP/2 vulnerabilities: server crash due to an HPACK encoder race (GO-2026-6617), memory exhaustion through trailer headers (GO-2026-6603), excessive CPU from repeated initial window changes (GO-2026-6611), double flow control refund on server streams (GO-2026-6612), and malformed framing headers accepted by the transport (GO-2026-6610). by @dunglas in #1434 - Logging: the "New subscriber" and "Subscriber disconnected" lines now log
client_ip, and again log thesubscriberfield (ID, last event ID, matchers) lost in the switch toslog, so connections and disconnections can be correlated. The Caddy module always resolves the client IP throughtrusted_proxies, not only whensubscription_limitsis set. by @dunglas in #1432 - Debugger: the subscribe and active subscriptions streams reconnect, resending
Last-Event-ID, when the hub closes them (for instance whenwrite_timeoutexpires or on shutdown). They previously stayed disconnected. by @dunglas in #1433
📖 Documentation
- Remove dead links from Awesome Mercure and add the Laravel Broadcasting docs, which cover the Mercure driver. by @dunglas in #1430
Enterprise
Mercure Enterprise picks up the same fixes in image v1.1.1, built with Go 1.27.2, which also fixes reachable net/http, HTTP/2 and html/template advisories in the standard library. Mercure Cloud hubs are upgraded automatically: use Mercure Cloud to get fixes like these without managing upgrades yourself.
Enterprise releases ship under the Enterprise SLA, with prioritized patches and direct support. Contact contact@mercure.rocks for the managed Cloud offering, on-premise licenses, custom development, consulting, and training.
Full Changelog: v1.1.0...v1.1.1