Releases: HomeLabHD/LinkStack
Releases · HomeLabHD/LinkStack
Release list
latest-dev
📦 LinkStack — v4.8.6-dev+90a4180
Release type: prerelease • Commit:
90a4180
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/linkstack |
dev-90a4180 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/linkstack |
dev-90a4180 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/linkstack |
dev-90a4180 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/linkstack
docker pull docker.io/hlhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
cr.pcfae.com/hlhd/linkstack
docker pull cr.pcfae.com/hlhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
ghcr.io/homelabhd/linkstack
docker pull ghcr.io/homelabhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
Notable Changes
Documentation
- refresh generated badges (stagefreight) ×6
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
Security
🛡️
Vulnerability details (1 high, 6 medium)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2025-3891 | apache2 | 2.4.68-r0 | — | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the... |
| Medium | CVE-2017-6485 | php83-calendar | 8.3.33-r0 | — | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the... |
| Medium | CVE-2022-4455 | php83-calendar | 8.3.33-r0 | — | A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | — | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade... |
Full changelog
- [
90a4180] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6d67c85] refresh generated badges (stagefreight) - [
1b98159] refresh generated badges (stagefreight) - [
1acc3b7] refresh generated badges (stagefreight) - [
c63943a] refresh generated badges (stagefreight) - [
d1bc19c] refresh generated badges (stagefreight) - [
bd3cae5] refresh generated badges (stagefreight)
dev-90a4180
📦 LinkStack — v4.8.6-dev+90a4180
Release type: prerelease • Commit:
90a4180
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/linkstack |
dev-90a4180 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/linkstack |
dev-90a4180 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/linkstack |
dev-90a4180 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/linkstack
docker pull docker.io/hlhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
cr.pcfae.com/hlhd/linkstack
docker pull cr.pcfae.com/hlhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
ghcr.io/homelabhd/linkstack
docker pull ghcr.io/homelabhd/linkstack@sha256:1d873e9a43d35ebfe7b04b3340f4c30fd91e32c6340436456d7063cf1c0a5e5f
Notable Changes
Documentation
- refresh generated badges (stagefreight) ×6
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
Security
🛡️
Vulnerability details (1 high, 6 medium)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2025-3891 | apache2 | 2.4.68-r0 | — | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the... |
| Medium | CVE-2017-6485 | php83-calendar | 8.3.33-r0 | — | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the... |
| Medium | CVE-2022-4455 | php83-calendar | 8.3.33-r0 | — | A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r31 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | — | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade... |
Full changelog
- [
90a4180] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6d67c85] refresh generated badges (stagefreight) - [
1b98159] refresh generated badges (stagefreight) - [
1acc3b7] refresh generated badges (stagefreight) - [
c63943a] refresh generated badges (stagefreight) - [
d1bc19c] refresh generated badges (stagefreight) - [
bd3cae5] refresh generated badges (stagefreight)