The official source reports this update: v1.107.6 (2026-09-16). 🛡️ Security A maintenance release for the v1 line, carrying the v1 backports of the four security fixes released in 2.44.0 . See each advisory for full details and affected versions. GHSA-vmxc-h2x2-jmf3 (moderate): cloud-metadata and private-IP blocklist bypass via an IPv6 zone identifier, on a URL opted into local network access. Reported by @euriconicacio . ( #8402 ) GHSA-fpf4-vwcp-v4hp (moderate): superlinear response processing in web_fetch , in both the HTML conversion and the charset decode, blocking the event loop. Reported by @BrianWillows .
Canonical AI event
Security update drops credentials on redirect origin change.
Security release v1.107.6 fixes four vulnerabilities in the v1 line. One flaw allowed bypassing cloud-metadata and private-IP blocklists via IPv6.
17 Sept 20261 verified claims1 sources1 observations
This official update documents a development concerning v1.107.6 (2026-09-16). Its practical significance depends on the scope and evidence stated by the source.
Read the official source update and verify its stated scope, evidence and timing before acting on it.
Connected knowledge
Entities affected by this event
Continue this topic
Related verified updates
Evidence trail
Sources behind the event
Editorial presentation
Open story