# Jellyseerr v3.1.1 — Release v3.1.1 - Product: Jellyseerr (https://whatsnew.fyi/product/jellyseerr) - Vendor: Jellyseerr - Date: 2026-04-13 - Version: v3.1.1 - Original notes: https://github.com/seerr-team/seerr/releases/tag/v3.1.1 - Permalink: https://whatsnew.fyi/product/jellyseerr/releases/v3.1.1 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Patch CVE-2026-40175 - Unrestricted Cloud Metadata Exfiltration via Header Injection Chain - **fixed** — Type axios instance in imageproxy ##### [3.1.1](https://github.com/seerr-team/seerr/compare/v3.1.0..v3.1.1) - 2026-04-13 This update addresses a critical security vulnerability discovered in one of our core dependencies (axios). **This is not the same vulnerability where axios was hijacked.** ###### 🛡️ Security - Patch [CVE-2026-40175](https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx) - Unrestricted Cloud Metadata Exfiltration via Header Injection Chain - ([3ca6422](https://github.com/seerr-team/seerr/commit/3ca64222ae48db41476c76f8508a7f5612dc579e)) ###### 🐛 Bug Fixes - *(imageproxy)* Type axios instance - ([74100e9](https://github.com/seerr-team/seerr/commit/74100e9669d3f2dc67a39f9f8fdfe7c5975b980f))