<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update AdGuard Home?</title>
    <link>https://bumplog.org/apps/adguard-home/</link>
    <description>Update-safety verdicts for AdGuard Home (AdguardTeam/AdGuardHome), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/adguard-home/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AdGuard Home v0.107.77 — Update with care</title>
      <link>https://bumplog.org/apps/adguard-home/</link>
      <guid isPermaLink="false">bumplog:app:adguard-home:v0.107.77:caution</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>Update with care. This release patches a path traversal vulnerability (CVE-2026-41448) in GLiNET mode authorization, making it a security-motivated update worth applying. However, it also deprecates the `response_status` query parameter in `GET /control/querylog` in favor of a new `reason` parameter — users or integrations relying on that API endpoint should review the change before updating. No breaking migrations or manual upgrade steps are noted. What changed: v0.107.77 patches a path traversal vulnerability in authorization for GLiNET mode (CVE-2026-41448), reported by a community member. The query log API gains a new `reason` query parameter on `GET /control/querylog` that replaces the now-deprecated `response_status` parameter. No other user-facing changes are included in this release. Source release: https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.77</description>
    </item>
  </channel>
</rss>
