FreshRSS 1.30.1

2026-10-05 19:40 • ;Alkarex

This is a security-oriented release with several security patches and bug fixes in the continuation of 1.30.0.


Note that our rolling-release channel (edge) is recommended for faster security patches.


Bug fixes highlights 🐛:



  • Some security attack scenarios patched

  • Fix domain-wide Retry-After

  • Fix muting of feeds gone with HTTP 410


Feature highlights✨:



  • CLI: Add optional feed argument to actualize-user.php


This release has been made by @Alkarex, @andris155, @fzlzjerry, @Inverle, @jamalkamaladdin, @jtracey, @Otolock and newcomers @akine, @colons, @ethanstoner, @gigioneggiando, @Juice-de-Orange, @pavel-miniutka, @qwist1233-cpu, @Sharawey74, @shcheglovnd, @TapuGithub, @yuchenshi, @ZainnQureshii


Full changelog:



  • Deployment

    • Reword recommendations and explanations for edge (rolling release) vs. latest (versioned release) channels #9270



  • Security

    • Config + increase default values for search max length and depth #9280

    • Accept a trusted proxy address given without a subnet #9301

    • Warn during session regenerate fail #9311, #9376

    • CI/CD add zizmor workflow for action security checks #9228, #9331

    • Use PHP #[\SensitiveParameter] #9322

    • Reject token access (RSS/OPML export, feed refresh) for disabled accounts #9336

    • Require POST+CSRF for self-update mutations #9335

    • Make the login challenge nonce one-time #9334

    • Bound ZIP import against decompression bombs #9332

    • Rotate session ID on all authenticated transitions #9333

    • Minz: Remove vulnerable and unused code path for displaying errors #9395

    • Fix NAT64 feed fetching on IPv6-only hosts #9372



  • Bug fixes

    • Fix domain-wide Retry-After #9390

    • Fix muting of feeds gone with HTTP 410 #9391

    • Fix infinite redirect loop due to SCRIPT_NAME in PATH_INFO #9282, #9287

    • Restore the automatic reading view after marking articles as read, while preserving explicit filters #9288

    • Fix adaptive reading state after marking articles read #9290

    • Fix regression sharing links #9303

    • Don’t disable anonymous refresh when anonymous feed access is disabled #9354

    • Fix regression with HTTPS proxies due to wrong TLS SNI resolution #9341

    • Better enforce limits for feeds and categories #9357

    • Fix JavaScript error when opening a label menu in sidebar #9377

    • Fix custom favicon with GReader API #9409



  • CLI

    • Add optional feed argument to actualize-user.php #9319



  • UI


  • Extensions

    • Call check_url_before_add hook when previewing a feed #9343



  • I18n


  • Misc.


Read More Here: https://github.com/FreshRSS/FreshRSS/releases/tag/1.30.1