Skip to main content

Vernissage 1.38.0 is now available! 🎉

This release introduces create/announce support for user inboxes with visibility validations, a new QuietPublic visibility type on status, and an antiflood mechanism with configurable parameters. It also fixes remote comment notifications, case-insensitive status search, and image rotation issues during small image generation from ActivityPub imports.

Thank you for all your feedback and support! 🤩

github.com/VernissageApp/Verni

Iceshrimp.NET v2026.1.1-beta
This is a beta security hotfix release. It's identical to v2026.1-beta, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

  • The JSON-LD keywords @reverse, @graph and @included are now disallowed
  • JSON-LD payloads that result in more than one object after expansion are now disallowed
  • Regex timeouts during note filtering are now handled gracefully

Check out the full changelog for more information on this release.

v2026.5.1
This release contains several critical security patches, as well as minor fixes and improvements. Upgrading is strongly recommended for all server operators.

Security

  • Fixed signature bypass with certain keywords (reported by Mastodon)
  • Fixed signature bypass with improper algorithm ordering
  • Fixed XSS in emoji autocompleter
  • Disabled hashtag channel

Miscellaneous

  • Fixed service worker not properly loading

Attribution

This release was made possible by project contributors: mia

Furthermore, I want to give special thanks to Mastodon for the vulnerability disclosure.

No replies yet

Be the first to share your thoughts.