v2.36.0
Changelog (v2.35.0...v2.36.0)
- security #557 Require X-Requested-With header to prevent CSRF (@Kocal)
- security #cve-2026-49208 Parse format-less date LiveProps strictly with RFC 3339 (@Kocal)
- security #cve-2026-49209 Cap the number of actions per
_batchrequest (@Kocal) - security #cve-2026-49210 Reject malicious child component tags (@Kocal)
- security #cve-2026-49212 Bind HMAC checksum to component name and slot (@Kocal)