Released on September 22, 2026.
- Upgraded Fedify to 2.1.24, which fixes three security vulnerabilities: unverified public key ownership that let any HTTP server have activities accepted as coming from any actor, unbounded reads of remote JSON documents (authenticated documents, NodeInfo responses, and inbox bodies) that could exhaust memory, and an SSRF flaw in outbound activity delivery where inbox URLs and redirects were not validated against private network addresses. [GHSA-q9f8-5hc7-898f, GHSA-mc44-6cfg-2v6w, GHSA-f59r-8gcj-68f2]