Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076) exists() now throws when the lookup itself fails, for example on a timeout, a connection error or rejected credentials, instead of also reporting false. Callers that relied on a false result for any failure need to handle the error. Note that S3 answers 403 rather than 404 for a missing object when the credentials cannot list the bucket, so granting s3:ListBucket is needed to keep getting a clean "missing" answer.
Fixed "Update Items" and "Delete Items" operations affecting every item in a collection when given an empty or missing key or query (#27759) Nothing to target is a no-op
"Update Items" and "Delete Items" operations now return null instead of falling back to every item whenever the configuration doesn't target anything β that is, when key is empty or missing (e.g. [], "") and query is empty or missing (e.g. {}). "Update Items" additionally returns null when there is nothing to write, i.e. an empty or missing payload (e.g. {}, or [] for a batch payload). Flows that relied on the previous fallback to every item can use {"limit": -1}.
Contradictory options error
"Update Items" and "Delete Items" operations now throw an error when both key and query are defined. "Update Items" also throws when key or query is combined with a batch payload.
Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111)
The default maximum output dimension is now 6000 px. Users who rely on the previous limit of 3000 px can explicitly configure ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION.
Used the pm2 bundled with @directus/api in the Docker images instead of installing a separate copy, so its dependencies follow the versions pinned by the workspace (#28120)
If you extend the Docker image: it now boots via CMD ["node", "docker-entrypoint.cjs"], which runs the same bootstrap then pm2-runtime sequence as before. pm2-runtime is no longer on the PATH, so a custom CMD that called it directly should hand off to docker-entrypoint.cjs instead. pm2 itself remains on the PATH for docker exec diagnostics.
@directus/api
Fixed "Update Items" and "Delete Items" operations affecting every item in a collection when given an empty or missing key or query (#27759 by @ComfortablyCoding)
@directus/storage-driver-cloudinary
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
@directus/storage-driver-s3
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
@directus/storage-driver-local
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
@directus/storage-driver-supabase
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
@directus/sdk
Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)
β¨ New Features & Improvements
@directus/app
Added search-first AI tool discovery for chat and MCP tools, with schema pinned as a root chat tool. (#27797 by @bryantgillespie)
Added a caption field to the WYSIWYG image drawer, which wraps the image in a figure with a figcaption (#28026 by @alvarosabu)
Added the collection name appended to display template in item and drawer headers (#28078 by @AlexGaillard)
@directus/api
Added search-first AI tool discovery for chat and MCP tools, with schema pinned as a root chat tool. (#27797 by @bryantgillespie)
@directus/cli
Introduced @directus/cli (d6s / directus-cli) β a client-side CLI that syncs schema and configuration between Directus instances through committed JSON files, with sync pull, sync diff, sync push, and an interactive wizard (#27861 by @bryantgillespie)
@directus/types
Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)
Removed dead βSave and Quitβ dropdown row outside the content item view (#28051 by @robluton)
Fixed relational items with unsaved nested values, such as newly added translated items in a content version, rendering as -- instead of their display template (#28010 by @alvarosabu)
Fixed the repeater interface options showing empty sub-fields, and dropping their key and type on save, when the sub-fields were created through the API without repeating the key and type inside their meta (#28041 by @lazerg)
Fixed relational fields showing stale values after a manual flow updated them (#28056 by @AlexGaillard)
Fixed the Markdown interface's Edit and Preview buttons not indicating which view is currently active (#28023 by @Aniket-a14)
Fixed silent failure of dragging & dropping files with an unrecognized extension into the file library (#28093 by @alvarosabu)
Fixed a request for a non-existent item when opening an item whose Many-to-One field references an unsaved parent (#27975 by @sourav-18)
Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)
Fixed field configuration appearing to close when selecting related collection that switches interface (#28118 by @robluton)
Fixed the translations interface AI translation button only showing for admins (#28089 by @AlexGaillard)
Fixed SSO login redirecting to the last visited page instead of the originally requested page (#28080 by @AlexGaillard)
Stopped the policy creation modal from writing app access permission rows to the database, matching the policy detail page where app access permissions are applied at runtime instead of stored (#28101 by @alvarosabu)
Added block-level custom formats to the WYSIWYG interface, so block, selector and items entries in the Custom Formats option apply classes and attributes to paragraphs, headings and other block nodes from the Formats dropdown (#28044 by @alvarosabu)
Fixed WYSIWYG content the editor can't represent being hidden and unrestorable in the comparison modal (#28067 by @alvarosabu)
@directus/api
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
Added a batch-import regression test pinning that a negative temporary key maps like any other non-existent auto-increment key in merge mode (#27861 by @bryantgillespie)
Updated MCP tool descriptions and safety annotations for connector clients. (#28090 by @bryantgillespie)
Improved MS SQL Server reliability and performance by optimizing schema introspection and only enabling trigger compatibility when required (#27699 by @br41nslug)
Updated various dependencies to address CVEs (#28110 by @br41nslug)
Fixed slow extension sync from remote storage during startup. Added EXTENSIONS_STORAGE_MAX_CONCURRENCY to configure the maximum number of concurrent requests to the extensions storage location (#27989 by @dstockton)
Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111 by @ComfortablyCoding)
Fixed TranslationsService.updateMany incorrectly rejecting single-row updates containing both key and language (#28001 by @suhailopensource)
Fixed collection names with surrounding whitespace being accepted on creation (#28038 by @lazerg)
Fixed WebSocket rate limiting breaking on shared Redis setups where keys must start with a per-project prefix. The WebSocket limiter now accepts RATE_LIMITER_WEBSOCKETS_* values as overrides, including RATE_LIMITER_WEBSOCKETS_KEY_PREFIX to override the Redis key prefix. (#28107 by @AlexGaillard)
@directus/storage-driver-azure
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
@directus/storage-driver-gcs
Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
Improved MS SQL Server reliability and performance by optimizing schema introspection and only enabling trigger compatibility when required (#27699 by @br41nslug)
@directus/env
Fixed slow extension sync from remote storage during startup. Added EXTENSIONS_STORAGE_MAX_CONCURRENCY to configure the maximum number of concurrent requests to the extensions storage location (#27989 by @dstockton)
Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111 by @ComfortablyCoding)
Updated ESLint dependencies eslint, @eslint/js, eslint-plugin-vue, and typescript-eslint. Replaced eslint-plugin-import with eslint-plugin-import-x (#28047 by @br41nslug)
prevent spamming of 'stream is closed' error during shutdown (#6062)
impose a minimum value to clock rate of always-available tracks (#6086) Clock rates below 10 caused the emission of empty samples. Fix the issue by imposing a minimum value of 8khz, that rises to 22khz in case of AAC.
fix race condition during sub-stream creation (#6075) (#6095) When a stream with always-available turned on switches from offline to online, or from a publisher to another, the reader mutex was not acquired during writing of codec parameters. This is now fixed.
restore ability to run the server in a read-only file system (#6098) This was temporarily lost after the introduction of the native MoQ QUIC listener.
fix deadlock when changing configuration through file and API (#6077) (#6101) When changing configuration in parallel by editing the configuration file and calling the API, the server could get into a deadlock that prevented any further action. This is fixed.
change default value of authHTTPExclude (#6103) by default, do not exclude any action from HTTP authentication. Old value triggered several security warnings.
add destFingerprint parameter (#6106) this allows to validate self-signed certificates of forward destinations.
pmp4: fix panic in case of bad input (bluenviron/mediacommon#354) the stsc box was not checked properly. This is now fixed.
pmp4: fix panic in case of bad input (bluenviron/mediacommon#355) The parser was not checking that the MP4 was properly sending addresses of samples, resulting in samples with invalid addresses. This is now fixed.
limit maximum amount of published tracks (#6087) this prevents clients from consuming an excessive amount of memory.
make /moq URL suffix optional (#6107) In order to establish a MoQ session with WebTransport, a /moq suffix was required until now. This is now optional in order to allow connecting to the server with the standard MoQ URL format.
impose maximum size on pending reordered bytes (#6112) Decrease the maximum memory that clients can take by imposing a maximum size of 100MB on the pending reordered bytes.
RTSP
accept relative digest URI (bluenviron/gortsplib#1118) RFC 2617 section 3.2.2 allows the digest URI to be either an absolute URI or a relative path. Some clients use the latter, which was rejected with "wrong URL" since urlMatches only accepted an exact match against the absolute request URL.
send initial RTCP sender report without waiting for a period (bluenviron/gortsplib#1052) (bluenviron/gortsplib#1111) (bluenviron/gortsplib#1120) Reports were emitted only on the ticker, so the first one arrived Period after Initialize (10s by default) and later still when no RTP packet had been sent by that first tick, since report() returns nil until then and the next opportunity is another Period away.
ensure that decoders can produce only output that does not crash encoders (bluenviron/gortsplib#1123)
inform about authentication failures (#5657) (#6072) Reply with NetStream.Play.Failed or NetStream.Publish.Unauthorized when a client is not authorized to play or publish. This makes clients like OBS to stop recreating the connection in case of authentication failures.
prefer hls.js on iOS too (#6090) In the embedded HLS reader, use hls.js on iOS, that was previously disabled due to compatibility issues that should have been solved.
unlock the session-in-query+iOS combination (#6088) this was previously blocked because the session in query was meant to be dynamic, therefore incompatible with static playlists required by iOS. It is not anymore, so we can support that.
stop using cookies with plain HTTP (#6089) in case of plain HTTP, fall back to query parameters, which are safer than HTTP cookies because they are not shared between different pages/domains, although they are visible in the URL.
improve performance by ignoring mDNS candidates (#4963) (#6064) mDNS candidates sometimes require a large CPU portion, they are not involved in any connectivity method mentioned in the documentation, they work in local networks only.
SRT
apply UDP read buffer size from configuration (#6069) Use upstream datarhei/gosrt's ListenerControl config field (datarhei/gosrt#144) to set SO_RCVBUF on the SRT listener's UDP socket.
RPI Camera
fix crash when secondary stream is enabled (#6060) (#6061)
prevent invalid MJPEG sizes (#6080) width and height of MJPEG frames must be multiple of 8 and less than 2048, otherwise they cannot be routed with RTP/RTSP.
Dependencies
code.cloudfoundry.org/bytefmt updated from v0.83.0 to v0.85.0
github.com/alecthomas/kong updated from v1.16.0 to v1.16.1
github.com/asticode/go-astits updated from v1.15.0 to v1.16.0
github.com/bluenviron/gohlslib/v2 updated from v2.4.2 to v2.4.3
github.com/bluenviron/gortmplib updated from v1.0.0 to v1.0.1
github.com/bluenviron/gortsplib/v5 updated from v5.6.3 to v5.6.4
github.com/bluenviron/mediacommon/v2 updated from v2.9.2 to v2.9.3
github.com/datarhei/gosrt updated from v0.11.0 to v0.11.1-0.20260812091715-a77b40bb4b76
github.com/pion/ice/v4 updated from v4.4.0 to v4.4.1
github.com/pion/transport/v4 updated from v4.0.2 to v4.1.0
github.com/stretchr/testify updated from v1.11.1 to v1.12.0
golang.org/x/crypto updated from v0.54.0 to v0.55.0
golang.org/x/net updated from v0.57.0 to v0.58.0
github.com/davecgh/go-spew removed
github.com/pion/srtp/v3 updated from v3.0.12 to v3.0.13
github.com/pmezard/go-difflib removed
golang.org/x/text updated from v0.40.0 to v0.41.0
hls.js updated from v1.6.16 to v1.7.0
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
Reporting: inboundReportMaxSize setting, which bounds the size of a decompressed inbound DMARC or TLS report (default 25MB).
RocksDB: cacheSize setting, which bounds the total memory shared by the block caches of every column family (default 128MB).
Changed
ASN & GeoIP: Default data source URLs now point at the ip-location-db GitHub releases, as the previously used npm packages are no longer updated. Existing installations keep their configured URLs and should update them following the ASN and GeoIP documentation.
JMAP: Identity/get keeps identities in sync with the account's e-mail addresses.
MTA: Queue scheduler no longer rescans the queue from the earliest pending event and coalesces bursts of delivery completions into a single scan.
RocksDB:
Column families are tuned for the access pattern of the data they hold.
Range iteration uses bounded iterators and no longer reads values when only keys were requested.
Fixed
JMAP:
Setting uploadTtl to 1ms triggers panic.
CalendarEvent/set does not assign organizerCalendarAddress nor send scheduling messages when an event is created with participants.
CalendarEvent/get omits isOrigin when it is listed explicitly in properties.
CalendarEventNotification/changes and FileNode/changes reject with cannotCalculateChanges the state that /get returned for an account with no change history.
CalendarEvent/set and ContactCard/set do not write a vanished tombstone for the previous CalDAV/CardDAV href when calendarIds or addressBookIds moves an item between collections.
CalDAV: Attendee addresses that percent-encode a display name into the mailto: URI are queued verbatim.
Calendar: Recurring events disappear from CalDAV time-range REPORTs and JMAP CalendarEvent/query results a few years after their first occurrence.
WebDAV:
When a file node references a parent folder that no longer exists, any request on a file collection panics.
MOVE on a folder honors a Depth header of 0 or 1 instead of always moving the whole subtree.
MTA:
DSN bounces are emitted with a malformed Message-ID wrapped in doubled angle brackets.
Delivery to any MX host whose name is an IDN A-label fails permanently.
Queue strategy and quota expressions that branch on source never match at enqueue.
MTA-STS:
Policies in testing mode are enforced, turning any TLS error into a permanent failure.
mx patterns published as U-labels never authorize the MX host they name.
DMARC:
Alignment compares identifiers in their A-label form.
External reporting addresses published as U-labels are rejected as unauthorized.
Spam filter:
Some rules misfire on internationalized addresses when the envelope and the headers spell the same domain in different label forms.
Punycode labels that do not re-encode to the label they came from are no longer decoded.
WebPush: Validate push URL and use application/octet-stream as Content-Type for encrypted payloads.
Directory:
Local group membership is cleared when the external directory is configured with a group claim or attribute that it does not return.
LDAP: Directories that store aliases as additional values of the primary address attribute provision no aliases.
Mail addressed to a domain alias is rejected with 550 Relay not allowed, unless the domain's primary name happened to be resolved earlier and is still cached.
RocksDB: bufferSize setting was applied to the unused default column family and had no effect.
Sieve: include statements fail to find system and user global scripts whose name contains uppercase characters.
Task manager: totalDeadline is measured from the time a task was created instead of its first failed attempt.
The NVIDIA SDK was updated to version 13 in this release. This means that the minimum supported driver version is now 570. If you experience any issues with NVENC, please ensure that your GPU driver version is fully up to date.
Important
Due to an update to Qt, macOS 12 is no longer supported. For macOS 12, please use OBS Studio 32.1.2.
32.2.2 Hotfix Changes
Fixed an issue where plugins might not load properly on the first start after updating OBS on Windows [notr1ch]
Blocked OBS Studio from running on macOS 12 [RytoEX]
Due to a Qt update, OBS Studio 32.2.x fails to launch on macOS 12. For macOS 12, please use OBS Studio 32.1.2.
32.2.1 Hotfix Changes
Fixed game capture failing after updating OBS if the previous hook was still in use [notr1ch]
32.2 New Features
Replaced add source dropdown with new dialog [Warchamp7]
Added copy paste functions to frontend API [exeldro]
Added filter to compose SDR into HDR [jpark37]
Added delete as a hotkey to delete sources on macOS [PatTheMav]
Added dynamic bitrate support to multitrack video [lexano-ivs]
Added missing file support for filters [exeldro]
Added ability for plugins to set custom icons for new source types [cg2121]
Improved FPS selector UX [jcm93]
Included .webp files when adding a directory to Image Slide Show source [TarunCore]
32.2 Changes
Forced Intel-based installations to update to Apple Silicon version on macOS [PatTheMav]
This change means that OBS Studio versions built for Intel-based Macs but running on Apple Silicon Macs will automatically update to OBS Studio built for Apple Silicon Macs. If an installation was using third-party plugins, those plugins will no longer load until replaced with Apple Silicon versions.
Fixed audio mixer state getting out of sync when changing settings via websockets or plugins [Warchamp7]
Added theming for checked QToolButtons [glikely]
Added minimum width to spinboxes [Warchamp7]
Changed new capture devices to use fallback frame rate by default [PatTheMav]
Improved OpenGL performance slightly on low-end machines [kkartaltepe]
Set minimum size for color source to 1 pixel [exeldro]
Disallowed overwriting the crash handler [sebastian-s-beckmann]
Applied process mitigation policies for Windows [notr1ch]
Adjusted description of multitrack video [jhnbwrs]
Improved DLL loading behavior on Windows [notr1ch]
Limited multitrack video config to Custom service [PatTheMav]
Removed redundant "Monitor Only" from the Advanced Audio Properties window [Warchamp7]
Mute and Monitor are handled independently in the new Audio Mixer
Removed Close button from What's New dialog [Warchamp7]
Removed margins from What's New dialog [Warchamp7]
32.2 Bug Fixes
Fixed OAuth and dock state save corruption [PatTheMav]
Fixed group bounds not resizing when removing items [howellrl]
Fixed canvas mixes not being restored after video reset [dsaedtler]
Fixed some erroneous crashes during shutdown [Warchamp7]
Fixed display capture sometimes capturing black after a duplicator failure [ThrowTop]
Fixed color of controls dock output buttons in System theme [shiina424]
Fixed virtual camera reset failures [stephematician]
Fixed potential crash when user discards changes in the settings window [suogesi]
Fixed incorrect return value in virtualcam filter [xtfo]
Fixed source toolbar buttons not working after dragging a source into a group [Warchamp7]
Fixed properties hint icon spacing [Warchamp7]
Fixed potential crash when a video device reconnects on macOS [jcm93]
Fixed an issue where PipeWire could fail on NVIDIA GPUs [hoshinolina]
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
WebDAV: Range and If-Range header support on file downloads (RFC 7233) (#2377).
Spam filter: url_original expression variable for Url rules.
Changed
Memory allocator: Replaced the unmaintained jemallocator crate with tikv-jemallocator (contributed by @checkraisefold).
ACME registry: Use description as label property.
Fixed
MTA:
Certificates for domains publishing an enforcing MTA-STS policy are always validated, even in the fallback TLS strategy.
DSN delivery date uses wrong timestamp.
FUTURERELEASE HOLDUNTIL uses Unix timestamps instead of RFC 3339 date-times.
JMAP:
EmailSubmission/query filtering on undoStatus contradicts EmailSubmission/get, reporting held FUTURERELEASE submissions as final instead of pending.
EmailSubmission/get requests without an ids argument iterates the wrong index.
CardDAV: Accept: text/vcard version negotiation is ignored whenever another parameter such as q or charset follows version=.
Calendar: Server-side scheduling messages place the text/calendar part outside the multipart/alternative and disposed as an attachment.
Sharing: Accounts holding the impersonate permission never have their ACL grants collected, so shared items are never listed in JMAP sessions, CalDAV/CardDAV discovery or IMAP.
IMAP:
COPY/MOVE into a shared folder fails with NO [ALREADYEXISTS] when the destination account already holds the message, leaving the message in the source mailbox and clients in a retry loop.
BODYSTRUCTURE and ENVELOPE return MIME parameters, Content-Description, subjects and display names as raw UTF-8 even to sessions that never enabled UTF8=ACCEPT.
support forwarding streams natively (#5558) It is now possible to define forward destinations for each path configuration. For each destination, the server will create a client that will forward the stream to the intended destination. Supported protocols are RTSP, RTMP, SRT. API and metrics have also been improved to allow monitoring the new forwarding system. Documentation: https://mediamtx.org/docs/features/forward
Media-Over-QUIC
support publishing and reading through native QUIC (#6039)
fix inability to read some AV1 streams with RTSP (#6001) (#6006) Since v1.16.0, temporal unit delimiters were not stripped from AV1 streams anymore. This has been restored, healing AV1 streams read with RTSP.
make multicast errors on single interfaces non-fatal (bluenviron/gortsplib#1115) (#5574) When writing multicast packets to several interfaces at one, a write error to a single interface was fatal and prevented writing to the other ones. Fix this.
client: change mapping between URL and tcURL, app, streamKey (bluenviron/gortmplib#94) (#4676) URLs passed to clients are now mapped into RTMP-native fields (tcURL, app, streamKey) in this way: tcURL contains URL without credentials and without fragment, app contains path and query of tcURL, streamKey contains the fragment.
muxer: recompute PTS of MPEG-TS AAC (bluenviron/gohlslib#379) iOS requires a precise timestamp that is often not available in AAC streams. Recompute timestamp from scratch.
WebRTC
sort tracks in a deterministic way (#5988) (#5989) When ingesting tracks with WebRTC, track order was randomized, preventing multi-track always-available streams from working reliably, since they require tracks to be ordered in a precise way. WebRTC tracks are not ordered by MID, RID, trackID and streamID respectively.
reset recomputed audio PTS if it drifts too much (#6021)
fix "packet lost" error when routing streams from WebRTC (#6034) Chrome sometimes sends empty packets, that are discarded by the server, but the sequence number of following packets is not recomputed, leading downstream packet loss detectors to emit errors. This is fixed.
SRT
improve log clarity (#5990) use message 'passphrase not provided by client' when clients do not provide passphrases.
close sources immediately when path is closed (#6038)
Dependencies
code.cloudfoundry.org/bytefmt updated from v0.82.0 to v0.83.0
github.com/MicahParks/jwkset updated from v0.11.0 to v0.11.3
github.com/MicahParks/keyfunc/v3 updated from v3.8.0 to v3.8.1
github.com/bluenviron/gohlslib/v2 updated from v2.4.1 to v2.4.2
github.com/bluenviron/gortmplib updated from v0.4.1 to v1.0.0
github.com/bluenviron/gortsplib/v5 updated from v5.6.2 to v5.6.3
github.com/go-git/go-billy/v5 updated from v5.9.0 to v5.9.1
github.com/go-git/go-git/v5 updated from v5.19.1 to v5.19.2
github.com/pion/ice/v4 updated from v4.3.0 to v4.4.0
github.com/pion/interceptor updated from v0.1.46 to v0.1.47
github.com/pion/webrtc/v4 updated from v4.2.17 to v4.2.18
github.com/quic-go/quic-go updated from v0.60.0 to v0.61.0
github.com/quic-go/webtransport-go updated from v0.11.1 to v0.12.0
github.com/pion/sctp updated from v1.11.0 to v1.11.1
golang.org/x/time updated from v0.14.0 to v0.15.0
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
Prefer macos-15 over macos-15-arm64, due to better availability of the Intel runners - (c3be9d4)
Stick to macOS 15, because the FPC package is only officially qualified up to macOS 11 and uses a package format Apple has tightened in newer releases, so it no longer installs on the macos 26 runners. - (0c969da)
Cleanup
TbsSeparator TToolButton's now seem to have a default width of 8px (was 6px at some point), and TStatusBar's height now has a default height of 23px (was 28px) - (660c82d)
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
MTA: Allow System Sieve scripts to access orcpt during the DATA stage.
Changed
S3: accessKey can now be read from an environment variable or file.
Fixed
Meilisearch: Verify index existence using GET instead of creating a new task which times out on busy servers.
Branding: Stalwart logo flashes before the per-tenant logo is loaded on the login page.
Calendar: iMIP and alarm notification messages embed the default logo using bare LF line endings, producing a single 4247 octet line that strict SMTP relays reject with line too long.
DMARC: Failure reports state Identity-Alignment: none when a mechanism authenticated successfully but against an identity that is not aligned with the From domain.
Redis: Task and queue locks are never released after a worker dies, because failed lock attempts refresh the lock expiry.
Recovery mode: Download WebUI if missing.
Logging: The systemd journal tracer omits the parent span's fields.
MTA:
BDAT chunks sent without a valid MAIL FROM are answered with 552 5.3.4 Message too big for system instead of 503 5.5.1.
A maxMessageSize of 0 rejects every message with 552 5.3.4 Message too big for system instead of disabling the size limit.
Windows: Listeners bound to the unspecified IPv6 address ([::]), including all defaults, refuse IPv4 connections such as 127.0.0.1, since IPV6_V6ONLY is enabled by default on Windows.
Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996)
The minimal app permissions now grant read access to only a subset of directus_settings fields. This applies to new policies, existing policies are untouched.
Replaced the TinyMCE editor powering the WYSIWYG with Tiptap... (#27754) The WYSIWYG interface now runs on Tiptap instead of TinyMCE
tinymceOverrides no longer has any effect. Stored values are kept and a console warning is logged, but the editor ignores them. Use the fontsize/fontfamily toolbar menus and customFormats instead.
TinyMCE is no longer bundled with the app, so anything depending on it (custom plugins, skins, content CSS, the global tinymce object) no longer applies.
Existing content that contains markup the editor would normalize now locks the field read-only until the warning dialog is confirmed. Editing and autosave are blocked while locked, including raw-value editing.
Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide (#27816)
The DeploymentProjectsService.readByExternalId method now takes the deployment ID as its first argument (i.e. readByExternalId(deploymentId, externalId))
Added support for multi-collection flat data imports (#27984) Import file size is now capped by default
A new IMPORT_MAX_FILE_SIZE environment variable (default: 50mb) limits the size of uploaded import files and schema snapshots. Previously, imports were effectively unrestricted, allowing files larger than 50mb to be processed. With this change, imports exceeding the configured limit will be rejected. Increase IMPORT_MAX_FILE_SIZE to restore the previous behavior.
Updated background query flag handling for POST /utils/import/:collection
The background query flag now treats a valueless indicator (i.e. ?background) as true. If you previously relied on a valueless background flag being interpreted as false, pass an explicit value instead (i.e. ?background=false).
Added a mode parameter and partial snapshot support to the schema diff endpoint (#27984)
The SDK schemaDiff command now takes its options as an object (schemaDiff(snapshot, { force, mode }))
Added support for restricting image transformation output size via ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995) Image transformation output is now restricted
Image transformations that project an output larger than ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (default 3000 px) on either axis are now rejected with an IllegalAssetTransformationError.
@directus/app
Replaced the TinyMCE editor powering the WYSIWYG with Tiptap (#27754 by @alvarosabu)
To avoid data loss, the editor preserves attributes (class, id, title, role, lang, dir, data-*, aria-*) and non-schema semantic tags. If stored HTML still contains markup the editor would normalize, the field is locked read-only with a warning dialog, so no edit or autosave can rewrite it before you confirm; raw-value editing is disabled while locked so the warning can't be bypassed.
@directus/api
Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide (#27816 by @MahinAnowar)
Fixed the translations split view hiding the second language when resizing the window (#27681 by @valerkahere)
Fixed geometry fields losing their subtype on schema changes (#27828 by @rajkumar0932)
Fixed stale dynamic permission presets after editing current account (#27899 by @scarab-systems)
Fixed a type error in the module bar default configuration (#27944 by @kheiner)
Amended app's save-as-copy logic to not create new items when only adjusting order on relationals (#27871 by @AlexGaillard)
Fixed the auth module registering a permanent cookie polling interval (#27851 by @dstockton)
Fixed presentation fields allowing required and/or readonly to be set (#27688 by @sourav-18)
Fixed missing translations for the Datetime display timezone options (#28000 by @lazerg)
Fixed dropdown menus shifting position when flipped above their trigger. (#27958 by @Harshith-muddasani)
Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement (#27934 by @JamesW1)
Fixed live preview requesting a draft version before it exists, which caused a forbidden error (#27848 by @dstockton)
Fixed issue causing singleton primary key mismatch (#27919 by @robluton)
Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
Fixed many-to-one fields to display the saved key when the referenced item is inaccessible due to permissions (#27899 by @scarab-systems)
Fixed a Forbidden error when publishing an itemless content version without delete permission on directus_versions (#27892 by @alex-hsieh)
@directus/api
Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Added global setting for default save action (#27993 by @robluton)
Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)
Restricted license key previews to administrators after initial project setup (#27886 by @ComfortablyCoding)
Stopped logging the missing custom IP header warning on /server/ping and /server/info, which are commonly hit directly (health checks) (#27903 by @dstockton)
Updated axios, sharp, liquidjs, js-yaml, minimatch, adm-zip, brace-expansion, linkify-it, fast-xml-parser and tar to address CVEs (#27990 by @br41nslug)
Fixed parsing of the deep query parameter, GraphQL nested arguments, and CSV import headers so keys dont collide with built-in object property names (#27992 by @br41nslug)
Fixed aliased relational fields returning null in GraphQL when nested inside a Many-to-Any field (#27864 by @apoorva-01)
Fixed IP denylist not enforced for AI chat file downloads (#27994 by @br41nslug)
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
Fixed requests referencing duplicate primary keys resulting in forbidden error (#27882 by @lazerg)
Fixed manual flows triggerable by non authenticated users (#27997 by @br41nslug)
Fixed count, countAll, and PK counts being inflated when filtering across relations (#27926 by @ComfortablyCoding)
Fixed TUS uploads not respecting FILES_MIME_TYPE_ALLOW_LIST (#27793 by @amitmishra11)
Fixed WebSocket handlers not validating query parameters (#27845 by @tsushanth)
Fixed unnecessary schema cache rebuilds on permission-related changes (#27876 by @dstockton)
@directus/sdk
Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Fixed nested filters on relational fields losing type inference, so filtering a related collection's field (e.g. filter: { o2m: { id: { _eq: 5 } } }) is now type-checked instead of silently accepting any value (#27815 by @MahinAnowar)
Removed phantom timestamp from directus_operations (#27942 by @kheiner)
Fixed an unhandled rejection in the sdk realtime client when the connection closed during a heartbeat ping (#27846 by @apoorva-01)
@directus/specs
Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
Added missing /users registration and 2FA endpoint openapi specs (#27857 by @kheiner)
Removed OpenAPI query parameters that the underlying controllers never honor (#27922 by @kheiner)
Added missing id path parameter to the /comments/{id} OpenAPI spec (#27884 by @kheiner)
@directus/constants
Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement (#27934 by @JamesW1)
@directus/system-data
Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
@directus/env
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
@directus/utils
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
@directus/schema
Fixed MSSQL schema introspection reporting the byte size as max_length for non-character types (#27825 by @BIGSUS24)
@directus/storage-driver-cloudinary
Fixed Cloudinary uploads failing when the configured root contains whitespace (#27841 by @itsabhay1)
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
Changed
Fixed
JMAP:
Email/copy should return alreadyExists when copying a message to a mailbox that already contains it.
Email/copy with onSuccessDestroyOriginal destroys the copy's creation id instead of the source Email id.
CalendarEvent/set does not generate a uid on create when the client omits it.
CalendarEvent/set does not refresh the updated property (iCalendar DTSTAMP) on create or update.
EmailSubmission/set rejects valid recipients whose domain is itself a public suffix (e.g. gov.in, co.uk).
Requests are rejected with notRequest when a method name contains a JSON-escaped solidus (e.g. Core\/echo).
MTA: Panic when MTA-STS is disabled and a remote MTA fetched /.well-known/mta-sts.txt.
Auth: Scoped credentials with SysApiKeyCreate or SysApiKeyUpdate permissions can regain its own account's full rights.
Web Push: Valid VAPID keys are rejected when PEM-encoded with explicit EC parameters, in SEC1 (EC PRIVATE KEY) format, or with a leading byte-order mark.
Encryption at rest: Appended messages are encrypted for accounts that did not opt in to encryptOnAppend.
Cache: Account caches silently discard entries larger than a single quick-cache shard, causing constant database rebuilds.
Registry: Id references (e.g. #certificate-...) fail to resolve on defaultCertificateId, defaultAdminRoleIds, listenerIds and publicKey.
Search: reindex drops calendar and contact index tasks for accounts with fewer than a full batch of items.
Migration: Abort --import when the target already contains data in the key range being imported.
Cluster: Broadcast subscriber re-subscribes after every message, losing bursts of cluster broadcasts during the reconnect window.
Enterprise: Per-tenant logo is not shown on the OAuth login password and OTP screens, which are served from the server's canonical host rather than the tenant domain.
The OpenWrt community is proud to announce the newest stable release of the OpenWrt 24.10 stable series.
This release fixes many security issues, several of them remotely triggerable in network services that are enabled by default. We strongly recommend everyone to upgrade.
The OpenWrt 24.10 series is in security maintenance (only security problems are fixed), with end of life (EoL) projected for September 2026. We recommend migrating to OpenWrt 25.12 before then.
Download firmware images using the OpenWrt Firmware Selector:
Main changes between OpenWrt 24.10.7 and OpenWrt 24.10.8
Only the main changes are listed below. See changelog-24.10.8 for the full changelog.
Security fixes
This release fixes several remotely triggerable vulnerabilities in core network
services that are enabled by default. Updating is strongly recommended.
odhcpd (DHCPv6/DHCPv4/RA server, enabled by default): multiple vulnerabilities reachable by a network-adjacent, unauthenticated attacker were fixed:
CVE-2026-53921 (Critical): stack buffer overflow in the DHCPv6 IA reply serialization, triggerable with crafted DHCPv6 REQUEST packets. GHSA-7fwx-hhrg-3496
Reconfigure-Accept stack buffer overflow (High, no CVE assigned): the Reconfigure-Accept reply block wrote 36 bytes into the response buffer without checking the remaining space, leading to a pre-auth out-of-bounds write. https://github.com/openwrt/openwrt/security/advisories/GHSA-q6wx-p68j-chp9
CVE-2026-53918 (High): use-after-free through a dangling first-lease pointer in the DHCPv6 IA handler. GHSA-44ff-jcwh-wgc2
CVE-2026-53920 (High): stack memory disclosure via a truncated DHCPv6 IA_NA/IA_PD option. GHSA-p769-5v73-pc4f
CVE-2026-53922 (Moderate): pre-auth denial of service via a size_t underflow in DHCPv6 IA handling. GHSA-7hcw-g2jh-pqv5
NDP hop-limit spoofing (Moderate, CVSS 5.4, no CVE assigned): the NDP relay accepted IPv6 Neighbor Solicitations with a hop limit other than 255 (RFC 4861 violation), letting an off-link attacker spoof NS packets through the relay. Only relevant when the NDP relay is enabled. https://github.com/openwrt/odhcpd/security/advisories/GHSA-qvg7-9jf5-wgjc
odhcpd / LuCI stored XSS: CVE-2026-62948 (Critical): an unauthenticated DHCPv6 client could inject lease-file lines through a crafted FQDN hostname, resulting in stored cross-site scripting on the LuCI DHCPv6 leases status page. Fixed by escaping client hostnames in the lease state file. GHSA-hhmc-92hw-535f
uhttpd (web server, serves LuCI): three HTTP request smuggling issues on keep-alive connections were fixed:
CVE-2026-55612 (High): invalid chunk-length state reset. GHSA-p55c-rmhc-qfm5
CVE-2026-55613 (Moderate): ubus POST body parse-error desync. GHSA-wgwp-64hh-f52p
In addition uhttpd received hardening without an assigned CVE: a one-byte overflow in uh_urldecode(), an off-by-one out-of-bounds read in uh_b64decode(), constant-time password comparison and stricter handling of $p$ crypt-hash entries in the authentication realm.
rpcd: ACL bypass through symlinks (High): the file plugin matched ACL grants against the textual path but then followed symlinks unchecked, so a symlink inside an ACL-covered directory let a limited account read or write arbitrary root-owned files. The path is now re-resolved and re-authorized for every operation that dereferences the final component. https://github.com/openwrt/openwrt/security/advisories/GHSA-q5gr-86pq-vvwr
cgi-io (file upload/download helper used by LuCI, installed by default with LuCI):
CVE-2026-62947 (Moderate): ACL bypass and arbitrary root file read β the download and exec paths were checked against the ACL before being canonicalized, so path traversal let an authenticated user with wildcard read permission read any root-readable file (e.g. /etc/shadow). GHSA-jw5r-xhf5-2xcq
LuCI (web interface): several issues in LuCI modules and applications were fixed. The privilege-escalation issues only apply if the affected app is installed and a limited (delegated) account with the relevant ACL exists:
luci-app-ddns (High): the ucode status backend passed DDNS UCI values such as lookup_host, dns_server and the section name to system() as an unquoted shell string, so anyone able to write DDNS configuration could execute commands as root. The invocations now use the array form of system(). https://github.com/openwrt/openwrt/security/advisories/GHSA-32r4-3wh2-qvq3
luci-app-samba4 (High): the read ACL granted exec permission for smbd in general rather than only smbd -V, allowing read-only accounts to run arbitrary commands as root. GHSA-vx64-mmp7-h36c
luci-app-upnp (High): stored XSS β an unauthenticated LAN client can inject JavaScript through a UPnP port-mapping description, which the underlying daemon does not sanitize. The description is now HTML-escaped. GHSA-8v49-6387-7f89
luci-mod-status (High): stored XSS via a DHCP/DHCPv6 lease hostname shown in the lease status tables. Together with the odhcpd fix above this closes the injection path from an unauthenticated DHCP client into the LuCI admin UI. GHSA-686p-p8p9-x6fh
luci-base: the dispatcher now escapes the URL path and user name when logging, so crafted login requests can no longer pollute the system log.
The LuCI rpcd ACL files were adjusted for the symlink-aware rpcd ACL check mentioned above, so that /proc paths that are symlinks (such as /proc/mounts) keep working.
umdns (mDNS responder): CVE-2026-55492 (Moderate, CVSS 6.5): an unauthenticated attacker on the local network segment could flood the daemon with unique mDNS records; the unbounded cache exhausted the heap and took the whole device into out-of-memory. Fixed by bounding the cache size and clamping hostile TTLs. GHSA-jg8f-fhfw-jg46
ead (Emergency Access Daemon): CVE-2026-55490 (Moderate): an integer underflow in handle_send_a() allowed an unauthenticated attacker on the local segment to crash the daemon with a single crafted packet. GHSA-9558-77jp-g3fw
dropbear (SSH): security fixes from upstream 2026.90 were backported:
CVE-2019-6111: a malicious server could make the scp client overwrite unexpected local files (missing OpenSSH patch). Note the accompanying upstream behaviour change: scp -r is now rejected when the target directory already exists.
CVE-2026-35385: scp did not clear setuid/setgid bits on received files.
An authenticated user could bypass an authorized_keysforced_command option when dropbear runs with -t; authorized_keys is now opened non-blocking (local denial of service via special files); and a close() on a file descriptor obtained from an out-of-bounds read was fixed.
musl libc: backport of the upstream fixes for CVE-2026-6042 (algorithmic-complexity denial of service in iconv) and CVE-2026-40200 (stack corruption in qsort with sufficiently large inputs).
In addition, the packages feed shipped with this release moved a number of
optional packages to newer upstream versions that contain security fixes, among
them curl (8.12.1 to 8.19.0), expat (2.7.4 to 2.8.2), BIND (9.20.23 to 9.20.26),
PHP 8 (8.3.29 to 8.3.32), Tor (0.4.8.22 to 0.4.9.10), unbound (1.24.2 to 1.25.1),
lighttpd (1.4.82 to 1.4.85), haproxy (3.0.19 to 3.0.25) and rsync (3.4.2 to 3.4.3).
collectd also received a fix for a use-after-free in the ping plugin. These
packages are not part of the default images β you have to update the installed
packages on your device to receive them.
Beyond the issues listed above, this release fixes a number of further security
and robustness problems in odhcpd, odhcp6c, rpcd and uhttpd for which no CVE
number or dedicated advisory was assigned. We strongly recommend upgrading to
the latest OpenWrt release and installing all available package updates.
Device support
No new devices were added in this security maintenance release.
Device fixes:
airoha: update the PCS driver to a newer proposed upstream version (EN7581 Ethernet SerDes)
ipq806x: Extreme Networks AP3935 - disable PHY hibernation on LAN1, which otherwise stayed dead when no cable was connected at power-on
WiFi fixes and improvements
mac80211: update the backported wireless stack and drivers from 6.12.61 to 6.12.96, containing many upstream fixes for ath10k, ath11k, rtw88, rtlwifi and iwlwifi, among them:
ath10k: skip WMI and beacon transmission when the device is wedged
ath11k: fix a warning on unbind and fix peer resolution on the RX path
rtw88: fix memory leaks on USB write failures
mac80211/nl80211: reject oversized EMA RNR lists and fix multi-link element defragmentation
hostapd / wpa_supplicant: multi-link (MLO) parsing validation fixes, see the security section above
wireless-regdb: update to 2026.05.30
Network and service improvements
odhcpd received many DHCPv6/DHCPv4 correctness and robustness fixes on top of the security fixes listed above, among them bounded nested relay recursion, correct handling of DHCPv4 Pad/End option encoding, fixed reallocation error handling and a memory leak on reload
odhcp6c: several fixes to DHCPv6 option parsing, RFC 6603 prefix-exclude handling, Reconfigure message validation and script invocation
rpcd: fixes for a use-after-free in the async exec reply path, a double close of exec pipe descriptors, an integer overflow in the UCI apply timeout and several memory leaks
umdns: update to a current version with the cache limits mentioned above
Other changes
busybox: the shell command history is now saved again. To avoid flash wear, it is written only when a shell session exits and it is stored in /tmp, so it is lost on reboot. The location can be changed in /etc/profile.d/busybox-history-file.sh.
Core components update
Linux kernel: update from 6.6.141 to 6.6.144
OpenSSL: update from 3.0.20 to 3.0.21 (multiple security fixes, see above)
dnsmasq: update from 2.90 to 2.93
mac80211: update from 6.12.61 to 6.12.96
wireless-regdb: update from 2026.03.18 to 2026.05.30
ca-certificates: update from 20260223 to 20260601 (refreshed root CA bundle)
Upgrading to 24.10
Sysupgrade can be used to upgrade a device from 23.05 to 24.10, and configuration will be preserved in most cases.
For for upgrades inside the OpenWrt 24.10 stable series for example from a OpenWrt 24.10 release candidate Attended Sysupgrade is supported in addition which allows preserving the installed packages too.
Sysupgrade from 22.03 to 24.10 is not officially supported.
There is no configuration migration path for users of the ipq806x target for Qualcomm Atheros IPQ806X SoCs because it switched to DSA. You have to upgrade without saving the configuration.
''Image version mismatch. image 1.1 device 1.0 Please wipe config during upgrade (force required) or reinstall. Config cannot be migrated from swconfig to DSA Image check failed''
User of the Linksys E8450 aka. Belkin RT3200 running OpenWrt 23.05 or earlier will need to run installer version v1.1.3 or later in order to reorganize the UBI layout for the 24.10 release. A detailed description is in the OpenWrt wiki. Updating without using the installer will break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of the Xiaomi AX3200 aka. Redmi AX6S running OpenWrt 23.05 or earlier have to follow a special upgrade procedure described in the wiki. This will increase the flash memory available for OpenWrt. Updating without following the guide in the wiki break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of Zyxel GS1900 series switches running OpenWrt 23.05 or earlier have to perform a new factory install with the initramfs image due to a changed partition layout. Sysupgrade will show a warning before doing an incompatible upgrade and is not possible. After upgrading, the config file /etc/config/system should not be restored from a backup, as this will overwrite the new compat_version value.
Users of scp from the dropbear package: recursive copies (scp -r) into an already existing target directory are now rejected. This is an intentional upstream change that comes with the fix for CVE-2019-6111. Use rsync or copy into a non-existing directory instead.
Known issues
LEDs for Airoha AN8855 are not yet supported. Devices like the Xiaomi AX3000T with an Airoha switch will have their switch LEDs powered off. This will not be addressed in the OpenWrt 24.10 series any more, it is fixed in OpenWrt 25.12.
5GHz WiFi is non-functional on certain devices with ath10k chipsets. Affected models include the Phicomm K2T, TP-Link Archer C60 v3 and possibly others. For details, see issue #14541.
The NVIDIA SDK was updated to version 13 in this release. This means that the minimum supported driver version is now 570. If you experience any issues with NVENC, please ensure that your GPU driver version is fully up to date.
Important
Due to an update to Qt, macOS 12 is no longer supported. For macOS 12, please use OBS Studio 32.1.2.
32.2.1 Hotfix Changes
Fixed game capture failing after updating OBS if the previous hook was still in use [notr1ch]
32.2 New Features
Replaced add source dropdown with new dialog [Warchamp7]
Added copy paste functions to frontend API [exeldro]
Added filter to compose SDR into HDR [jpark37]
Added delete as a hotkey to delete sources on macOS [PatTheMav]
Added dynamic bitrate support to multitrack video [lexano-ivs]
Added missing file support for filters [exeldro]
Added ability for plugins to set custom icons for new source types [cg2121]
Improved FPS selector UX [jcm93]
Included .webp files when adding a directory to Image Slide Show source [TarunCore]
32.2 Changes
Forced Intel-based installations to update to Apple Silicon version on macOS [PatTheMav]
This change means that OBS Studio versions built for Intel-based Macs but running on Apple Silicon Macs will automatically update to OBS Studio built for Apple Silicon Macs. If an installation was using third-party plugins, those plugins will no longer load until replaced with Apple Silicon versions.
Fixed audio mixer state getting out of sync when changing settings via websockets or plugins [Warchamp7]
Added theming for checked QToolButtons [glikely]
Added minimum width to spinboxes [Warchamp7]
Changed new capture devices to use fallback frame rate by default [PatTheMav]
Improved OpenGL performance slightly on low-end machines [kkartaltepe]
Set minimum size for color source to 1 pixel [exeldro]
Disallowed overwriting the crash handler [sebastian-s-beckmann]
Applied process mitigation policies for Windows [notr1ch]
Adjusted description of multitrack video [jhnbwrs]
Improved DLL loading behavior on Windows [notr1ch]
Limited multitrack video config to Custom service [PatTheMav]
Removed redundant "Monitor Only" from the Advanced Audio Properties window [Warchamp7]
Mute and Monitor are handled independently in the new Audio Mixer
Removed Close button from What's New dialog [Warchamp7]
Removed margins from What's New dialog [Warchamp7]
32.2 Bug Fixes
Fixed OAuth and dock state save corruption [PatTheMav]
Fixed group bounds not resizing when removing items [howellrl]
Fixed canvas mixes not being restored after video reset [dsaedtler]
Fixed some erroneous crashes during shutdown [Warchamp7]
Fixed display capture sometimes capturing black after a duplicator failure [ThrowTop]
Fixed color of controls dock output buttons in System theme [shiina424]
Fixed virtual camera reset failures [stephematician]
Fixed potential crash when user discards changes in the settings window [suogesi]
Fixed incorrect return value in virtualcam filter [xtfo]
Fixed source toolbar buttons not working after dragging a source into a group [Warchamp7]
Fixed properties hint icon spacing [Warchamp7]
Fixed potential crash when a video device reconnects on macOS [jcm93]
Fixed an issue where PipeWire could fail on NVIDIA GPUs [hoshinolina]
fix error message (#5922) 'all' is a synonym for 'all_others'
fix clearing lists with environment variables (#5410) (#5924) MTX_AUTHINTERNALUSERS_0_IPS, MTX_LOGDESTINATIONS and MTX_RTSPTRANSPORTS can now be used to clear their corresponding list by setting them to an empty value.
add runOnOnline / runOnOffline hooks (#5399) (#5956) These are triggered and a stream is online (i.e. not just provided by an offline segment).
rename runOnReady into runOnAvailable, runOnNotReady into runOnUnavailable (#5957)
fix wrong PTS and wrong playback of alwaysAvailableFile (#5436) (#5960) PTS offset of samples was not properly considered, and sleep between samples was PTS-based instead of being DTS-based.
avoid potential timing attack when validating SHA256 credentials (#5961) The == operator is vulnerable to timing attacks as it short-circuits on a mismatch. Use ConstantTimeCompare to avoid this vector. Co-authored-by: Tristan Matthews tmatth@videolan.org
normalize authentication error messages (#5421) (#5959) Log authentication errors as soon as possible, use the "warn" level, use the same message whatever the author or protocol.
adjust code to prevent security scan false positives (#5963) about string escaping.
ask for credentials only in case of protocols that support it (#5966) When clients connect with some protocols (SRT, RTMP), they are unable to provide credentials even if they are asked to. In this case, it's useless to wait for credentials, and it's better to immediately log authentication errors and apply the anti-brute force algorithm.
generate most of OpenAPI automatically (#5918) enums and structs are now generated automatically. This eliminates some inconsistencies and makes development easier.
Media-Over-QUIC
fix race condition during startup (#5965) allocate the HTTP server only after the MoQ server has been initialized.
fix several panics and OOM errors (#5964) Check for limits before allocating memory by using sizes passed from the remote peer. Also add fuzzing to all MoQ primitives.
support draft-19 of the specification (#5968) * support draft-19 of the specification * support subscribing the same track multiple times.
prevent excessive CPU consumption in reorderer (#5976) do not iterate by maxGroupID (passed by user) but iterate by internal pending packets (uncontrolled by user).
WebRTC
prevent cross-origin unauthorized access (#5975) when a user had previously inserted credentials into a MediaMTX instance through a browser, and AllowOrigins was set to a wildcard, third-party websites visited by the user were allowed to read streams without restrictions. This is now prevented by returning "*" in Access-Control-Allow-Origins when AllowOrigins is a wildcard, a behavior that prevents browsers from sharing credentials with third-party websites.
RTSP
restrict UDP port range to 32768-60999 (#5398) (#5958) this is the default Linux ephemeral port range.
use session ID in requests to the external authentication server (#5977) Co-authored-by: Cycle1337 Cycle1337@outlook.com
prevent cross-origin unauthorized access (#5975) when a user had previously inserted credentials into a MediaMTX instance through a browser, and AllowOrigins was set to a wildcard, third-party websites visited by the user were allowed to read streams without restrictions. This is now prevented by returning "*" in Access-Control-Allow-Origins when AllowOrigins is a wildcard, a behavior that prevents browsers from sharing credentials with third-party websites.
SRT
fix compatibility with StreamToStudio app (#5414) (#5928)
Dependencies
code.cloudfoundry.org/bytefmt updated from v0.78.0 to v0.82.0
github.com/alecthomas/kong updated from v1.15.0 to v1.16.0
github.com/bluenviron/gohlslib/v2 updated from v2.4.0 to v2.4.1
github.com/bluenviron/gortmplib updated from v0.4.0 to v0.4.1
github.com/bluenviron/gortsplib/v5 updated from v5.6.1 to v5.6.2
github.com/bluenviron/mediacommon/v2 updated from v2.9.1 to v2.9.2
github.com/matthewhartstonge/argon2 updated from v1.5.5 to v1.5.6
github.com/pion/ice/v4 updated from v4.2.8-0.20260604162030-72f5001c4596 to v4.3.0
github.com/pion/interceptor updated from v0.1.45 to v0.1.46
github.com/pion/rtcp updated from v1.2.16 to v1.2.17
github.com/pion/rtp updated from v1.10.2 to v1.10.5
github.com/pion/webrtc/v4 updated from v4.2.15 to v4.2.17
github.com/pires/go-proxyproto updated from v0.12.0 to v0.15.0
github.com/quic-go/webtransport-go updated from v0.11.0 to v0.11.1
golang.org/x/crypto updated from v0.53.0 to v0.54.0
golang.org/x/net updated from v0.56.0 to v0.57.0
golang.org/x/sync updated from v0.21.0 to v0.22.0
golang.org/x/sys updated from v0.46.0 to v0.47.0
golang.org/x/term updated from v0.44.0 to v0.45.0
github.com/pion/datachannel updated from v1.6.0 to v1.6.2
github.com/pion/dtls/v3 updated from v3.1.4 to v3.1.5
github.com/pion/sctp updated from v1.10.0 to v1.11.0
github.com/pion/stun/v3 updated from v3.1.5 to v3.1.6
github.com/pion/turn/v5 updated from v5.0.9 to v5.0.12
golang.org/x/text updated from v0.38.0 to v0.40.0
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
UpSnap is, and always will be, free and open source software.
If someone is asking you to pay money for access to UpSnap binaries, source code, or licenses, you are being scammed.
The official and only trusted source for UpSnap is this repository (and its linked releases).
Do not pay third parties for something that is provided here for free.
The NVIDIA SDK was updated to version 13 in this release. This means that the minimum supported driver version is now 570. If you experience any issues with NVENC, please ensure that your GPU driver version is fully up to date.
Important
Due to an update to Qt, macOS 12 is no longer supported. For macOS 12, please use OBS Studio 32.1.2.
32.2 New Features
Replaced add source dropdown with new dialog [Warchamp7]
Added copy paste functions to frontend API [exeldro]
Added filter to compose SDR into HDR [jpark37]
Added delete as a hotkey to delete sources on macOS [PatTheMav]
Added dynamic bitrate support to multitrack video [lexano-ivs]
Added missing file support for filters [exeldro]
Added ability for plugins to set custom icons for new source types [cg2121]
Improved FPS selector UX [jcm93]
Included .webp files when adding a directory to Image Slide Show source [TarunCore]
32.2 Changes
Forced Intel-based installations to update to Apple Silicon version on macOS [PatTheMav]
This change means that OBS Studio versions built for Intel-based Macs but running on Apple Silicon Macs will automatically update to OBS Studio built for Apple Silicon Macs. If an installation was using third-party plugins, those plugins will no longer load until replaced with Apple Silicon versions.
Fixed audio mixer state getting out of sync when changing settings via websockets or plugins [Warchamp7]
Added theming for checked QToolButtons [glikely]
Added minimum width to spinboxes [Warchamp7]
Changed new capture devices to use fallback frame rate by default [PatTheMav]
Improved OpenGL performance slightly on low-end machines [kkartaltepe]
Set minimum size for color source to 1 pixel [exeldro]
Disallowed overwriting the crash handler [sebastian-s-beckmann]
Applied process mitigation policies for Windows [notr1ch]
Adjusted description of multitrack video [jhnbwrs]
Improved DLL loading behavior on Windows [notr1ch]
Limited multitrack video config to Custom service [PatTheMav]
Removed redundant "Monitor Only" from the Advanced Audio Properties window [Warchamp7]
Mute and Monitor are handled independently in the new Audio Mixer
Removed Close button from What's New dialog [Warchamp7]
Removed margins from What's New dialog [Warchamp7]
32.2 Bug Fixes
Fixed OAuth and dock state save corruption [PatTheMav]
Fixed group bounds not resizing when removing items [howellrl]
Fixed canvas mixes not being restored after video reset [dsaedtler]
Fixed some erroneous crashes during shutdown [Warchamp7]
Fixed display capture sometimes capturing black after a duplicator failure [ThrowTop]
Fixed color of controls dock output buttons in System theme [shiina424]
Fixed virtual camera reset failures [stephematician]
Fixed potential crash when user discards changes in the settings window [suogesi]
Fixed incorrect return value in virtualcam filter [xtfo]
Fixed source toolbar buttons not working after dragging a source into a group [Warchamp7]
Fixed properties hint icon spacing [Warchamp7]
Fixed potential crash when a video device reconnects on macOS [jcm93]
Fixed an issue where PipeWire could fail on NVIDIA GPUs [hoshinolina]