Qeravio
Canonical AI event

Security update drops credentials on redirect origin change.

Security release v1.107.6 fixes four vulnerabilities in the v1 line. One flaw allowed bypassing cloud-metadata and private-IP blocklists via IPv6.

17 Sept 20261 verified claims1 sources1 observations
What happened

The official source reports this update: v1.107.6 (2026-09-16). 🛡️ Security A maintenance release for the v1 line, carrying the v1 backports of the four security fixes released in 2.44.0 . See each advisory for full details and affected versions. GHSA-vmxc-h2x2-jmf3 (moderate): cloud-metadata and private-IP blocklist bypass via an IPv6 zone identifier, on a URL opted into local network access. Reported by @euriconicacio . ( #8402 ) GHSA-fpf4-vwcp-v4hp (moderate): superlinear response processing in web_fetch , in both the HTML conversion and the charset decode, blocking the event loop. Reported by @BrianWillows .

Why it matters

This official update documents a development concerning v1.107.6 (2026-09-16). Its practical significance depends on the scope and evidence stated by the source.

What to watch next

Read the official source update and verify its stated scope, evidence and timing before acting on it.

Connected knowledge

Entities affected by this event

Continue this topic
Evidence trail

Sources behind the event