Ergo 2.19.1 is a release addressing recently reported security vulnerabilities, some of which are serious. We urge all affected deployments to upgrade as soon as possible.
This release includes no changes to the config file format or database file format.
Many thanks to @ajaspers and @tonghuaroot for discovering and responsibly disclosing these issues.
Security
- Fixed users being able to bypass account email verification or account suspension (GHSA-x6wg-9hcg-fc9v, thanks @ajaspers!)
- Fixed incorrect permissions controls for message redaction (GHSA-8cmp-fc56-7g44, thanks @ajaspers!)
- Fixed blind SSRF attacks against internal IPs via webpush extension (GHSA-7pw8-m2w2-f545, thanks @tonghuaroot!)
Internal
- Release builds use Go 1.26.5