Is it safe to update Kavita?

Tracking Kareadita/Kavita

Holds breaking changes.

The release notes explicitly state all users are strongly advised to update immediately due to a critical security vulnerability affecting all prior versions, which constitutes a mandatory upgrade step. No data migration or config changes are required, but the severity of the CVE makes skipping this update a meaningful risk. The OIDC validation change is behavioral but unlikely to affect most deployments.

Latest version
v0.9.0.2
Last checked

What changed

v0.9.0.2 is a critical security patch that all users are urged to apply immediately, addressing a vulnerability (CVE-2026-47202) affecting all prior releases. Beyond the security fix, OIDC validation has been relaxed to no longer require strict URL formats. The release also resolves a wide range of bugs including broken bookmarks (text, image, and epub), incorrect ratings always returning zero, annotation duplication and display failures, unreliable year-based search, and issues with series/collection metadata not updating correctly.

Source

Every verdict on Bumplog traces back to a GitHub release. No invented details.