<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Kavita?</title>
    <link>https://bumplog.org/apps/kavita/</link>
    <description>Update-safety verdicts for Kavita (Kareadita/Kavita), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/kavita/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Kavita v0.9.0.2 — Holds breaking changes</title>
      <link>https://bumplog.org/apps/kavita/</link>
      <guid isPermaLink="false">bumplog:app:kavita:v0.9.0.2:breaking</guid>
      <pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate>
      <description>Holds breaking changes. The release notes explicitly state all users are strongly advised to update immediately due to a critical security vulnerability affecting all prior versions, which constitutes a mandatory upgrade step. No data migration or config changes are required, but the severity of the CVE makes skipping this update a meaningful risk. The OIDC validation change is behavioral but unlikely to affect most deployments. What changed: v0.9.0.2 is a critical security patch that all users are urged to apply immediately, addressing a vulnerability (CVE-2026-47202) affecting all prior releases. Beyond the security fix, OIDC validation has been relaxed to no longer require strict URL formats. The release also resolves a wide range of bugs including broken bookmarks (text, image, and epub), incorrect ratings always returning zero, annotation duplication and display failures, unreliable year-based search, and issues with series/collection metadata not updating correctly. Source release: https://github.com/Kareadita/Kavita/releases/tag/v0.9.0.2</description>
    </item>
  </channel>
</rss>
