github tphakala/birdnet-go 20261010
BirdNET-Go 20261010

3 hours ago

This is a security release. It is built from release 20260823 with only security fixes and the dependency updates they need applied on top, so it carries none of the new features or other changes merged since 20260823; those arrive in the next regular release. Every installation should update. If you run subnet bypass behind a reverse proxy, read "Before you upgrade" first.

Before you upgrade

  • Subnet bypass behind a reverse proxy needs the proxy listed. The allowed-subnet login bypass (security.allowsubnetbypass) now honors a forwarded client address only when the request comes from a proxy listed in security.trustedproxies. If you reach BirdNET-Go through nginx, Caddy, Traefik, Home Assistant ingress, Tailscale Serve or a similar proxy and rely on the bypass, add the address the proxy connects from (for a proxy on the same host, 127.0.0.1 over IPv4 or ::1 over IPv6) to security.trustedproxies. The proxy must append X-Forwarded-For or overwrite X-Real-IP. List only the proxy's own address, not a range that also contains clients: a client inside a listed range is trusted as a proxy and can name any address. Clients that connect directly on your LAN are not affected. When forwarded headers keep the bypass from applying, the log says which peer to list.
  • Outbound integrations no longer use an environment proxy. Weather fetches, webhook notifications, the weather and eBird connection tests and the ntfy server check now go through a client that checks every destination address before connecting. These requests ignore HTTP_PROXY and HTTPS_PROXY, because a proxy would resolve the destination itself and bypass the check. Deployments that can only reach the internet through an egress proxy will see these integrations fail.
  • The ntfy server check is now a POST. GET /api/v2/notifications/check-ntfy-server?host= was replaced by POST /api/v2/notifications/check-ntfy-server with a JSON body {"host": "..."} and CSRF protection. The web UI is updated; external scripts that call the old GET need the same change.
  • Do not switch to this release from a development build. If you have run a :dev image or a build from the main branch, stay on it until the next regular release. Those builds change the dynamic threshold tables in a way this release cannot read, and it may fail to start.

Security

  • Subnet bypass decided on a verified client address. The allowed-subnet bypass and the automatic local-network check trusted CF-Connecting-IP, X-Forwarded-For and X-Real-IP from any loopback, link-local or private peer. A client on the same network or container network, or anyone reaching the app through a proxy that passed those headers through, could claim an address inside the bypass subnet and skip login. Forwarded headers now count only from a listed proxy, and every client-IP header it sends must name the same client (GHSA-wfpc-rhcf-754r). Reported by @Hama1cco.
  • Range filter rebuild and test require authentication. POST /api/v2/range/rebuild and POST /api/v2/range/species/test were reachable without login when authentication was configured and Private Mode was off (GHSA-8668-57p7-rjc9). Reported by @alex131125.
  • Recent detections limit capped. GET /api/v2/detections/recent accepted any limit and loaded that many detections into memory; it is now capped at 1000 (GHSA-g6wh-4rqg-w7qw). Reported by @alex131125.
  • Stream test host checks resolve names and reject numeric forms. The stream test endpoints blocked loopback and metadata destinations only for a few literal names. Decimal, hex, octal and short IPv4 forms, localhost. and DNS names resolving to blocked addresses are now rejected before probing (GHSA-2vxv-jv48-g3w7). Reported by @Yanyan-dd.
  • Webhook notifications guarded against SSRF. Webhook requests can no longer reach link-local or cloud metadata addresses (#4191, GHSA-85p4-7rfw-572f). Reported by @tonghuaroot.
  • Outbound probes guarded against SSRF, ntfy check protected by CSRF. Weather fetches, the weather and eBird connection tests and the ntfy server check now use the same guard (#4302, GHSA-hj22-g96h-fwvx). Reported by @tonghuaroot.
  • Dismissing the onboarding wizard requires access when authentication is configured (#4469).
  • Toolchain and dependencies. Built with Go 1.26.9, which carries the standard library security fixes released since 1.26.7, with golang.org/x/net v0.60.0, golang.org/x/crypto v0.57.0 and google.golang.org/grpc v1.83.2. Echo is updated to v4.16.0 (#4514).

Bug Fixes

  • No more crash when an SSE client disconnects. Server-sent event and streaming handlers no longer use a request context after Echo recycles it, which could crash the server or corrupt another request's response (#4293).
  • BirdWeather uploads keep their HTTP/2 health checks after the x/net update, now through the standard library configuration (#4401).

Notes

  • The web UI's map library (maplibre-gl 5.x) is listed by scanners under GHSA-jrc7-96c5-q579. BirdNET-Go never passes untrusted HTML to the map, so the issue cannot be triggered here; the next regular release ships the fixed 6.x version.

🛡️ VirusTotal Results:

Don't miss a new birdnet-go release

NewReleases is sending notifications on new releases.