1.18.3 (2026-06-02)
Important {: .error}
Please be careful using
:hackneyit is recommended to actually test the
application before assuming we did not introduce any breaking changes.
Also, be aware of the security vulnerabilities we have fixed in this release.
Some of them may cause some unexpected behavior from the middleware depending
on the assumptions made by the caller.
Features
Security CVE
- CVE-2026-48598 - Multipart part smuggling via unescaped
content-dispositionvalues - CVE-2026-48597 - Atom exhaustion via untrusted URL scheme
- CVE-2026-48596 - CRLF injection in request
Content-Typeheader viaadd_content_type_param - CVE-2026-48595 - Authorization header leaks on cross-origin redirect via case-sensitive filtering
- CVE-2026-48594 - Decompression bomb on response body