v0.19.0
kriasoft/react-starter-kitv0.19.0Aug 6, 2026by korridor
AI Summary
A security-focused release that addresses Host header handling vulnerabilities and fixes an invoice tax rate calculation error. It introduces strict host validation for self-hosted setups.
Key Highlights
- Security fix for Host header poisoning
- Adds trusted host validation middleware
- Requires correct `APP_URL` configuration to function
- Fixes invoice tax rate calculation
Breaking Changes
- Requests for unconfigured hostnames are now rejected with HTTP 400
- Requires `APP_URL` environment variable to be set correctly
- Requires `TRUSTED_HOSTS` environment variable for additional hostnames
New Features
- Trusted host validation middleware
- Support for wildcard subdomains via `TRUSTED_HOSTS`
Full Release Notes
> [!IMPORTANT] > This release includes a security fix for Host header handling. > > The issue only affects setups where requests can reach solidtime with arbitrary `Host` headers, for example when a reverse proxy forwards unvalidated Host headers or when no reverse proxy is used. > > solidtime Cloud and our [recommended Traefik setup](https://github.com/solidtime-io/self-hosting-examples/tree/main/0-docker-traefik-with-database) are not affected. > > Affected self-hosted installations should upgrade as soon as possible. > [!CAUTION] > Make sure your `APP_URL` is set correctly before updating, otherwise the solidtime instance will not work properly ## What's Changed * Add trusted host validation middleware to prevent Host header poisoning. Thanks to @tonghuaroot for the [security report](https://github.com/solidtime-io/solidtime/security/advisories/GHSA-rf33-hmh9-h593) * Fixed invoice tax rate by @korridor in https://github.com/solidtime-io/solidtime/pull/1184 ## For self-hosting This release adds host validation based on `APP_URL`. By default, solidtime now only accepts requests for the hostname configured in `APP_URL` and its subdomains. Requests for other hostnames are rejected with HTTP 400. If your instance is intentionally reachable through additional hostnames, configure the new `TRUSTED_HOSTS` environment variable: ```env APP_URL=https://solidtime.example.com TRUSTED_HOSTS=solidtime.internal,solidtime.tailnet-name.ts.net ``` Wildcard subdomains are supported: ```env TRUSTED_HOSTS=*.example.com ``` No database migrations are included in this release. **Full Changelog**: https://github.com/solidtime-io/solidtime/compare/v0.18.0...v0.19.0