← Back to all sparks
F

FreshRSS

COLLAB
Velocity3.8

Self-hosted RSS and Atom feed aggregator

FreshRSS 1.30.0 blocks local network access by default — security-first breaking change

rssself-hostedsecurityopen-sourcefeed-reader
Current state
FreshRSS 1.30.0 is a security-oriented major release that breaks backward compatibility by disabling local network access (127.0.0.1 and similar) by default, closing a server-side request forgery attack surface. The team labels it urgent and recommends the rolling `edge` channel for faster future security patches. Prior releases (1.29.x, 1.28.x) built a mature UX baseline: granular sort preferences, advanced search, feed icons, and sidebar customization.
Where it's heading
FreshRSS is pivoting toward security hardening. The 1.30.0 breaking change signals that the project now treats SSRF risks as first-class concerns, and the push to the `edge` channel for faster patches signals a more operationally demanding security posture going forward. The cadence of major releases (roughly one every 3–4 months) suggests the next version will combine more security fixes with UX additions.
Prediction
Expect 1.30.x patch releases addressing additional CVEs, and a possible tightening of outbound request controls — the SSRF fix in 1.30.0 is likely the first step in a broader hardening effort based on the accumulated CVE fixes visible across 1.26–1.29.

Recent moves

  1. 6d ago

    FreshRSS 1.30.0

    ⚡ SPARK

    FreshRSS 1.30.0 ships a breaking security change — local network access blocked by default — repositioning the project's security posture after a series of CVE fixes in prior releases.

    View source ↗
  2. 3mo ago

    FreshRSS 1.29.1

    1.29.1 adds .txt import of feed URLs and a new CLI for periodic SQLite export with configurable retention — operational tooling aimed at self-hosters who need backup automation, consistent with FreshRSS's self-hosted-first stance.

    View source ↗
  3. 4mo ago

    FreshRSS 1.29.0

    1.29.0 adds per-category and per-feed sort order preferences, feed-provided icons, and a hide-sidebar option — meaningful UX layering on an already feature-complete reader that extends personalization without architectural changes.

    View source ↗
  4. 7mo ago

    FreshRSS 1.28.1

    1.28.1 targets regressions from 1.28.0, including a performance improvement that disables expensive article counting in user label Ajax requests — a visible read-flow speedup for users with large label sets.

    View source ↗
  5. 8mo ago

    FreshRSS 1.28.0

    1.28.0 introduces sorting by user-modified date with a corresponding search operator, article length sorting, and an advanced search form — expanding filtering power and moving FreshRSS closer to a research-grade reading environment.

    View source ↗
  6. 11mo ago

    FreshRSS 1.27.1

    1.27.1 ships security and bug fixes: sort criteria persistence, Docker healthcheck support, and CSP frame-ancestors options — steady hardening ahead of the more assertive posture shift in 1.30.0.

    View source ↗