# Kavita v0.9.0.2 — v0.9.0.2 - Security Hotfix - Product: Kavita (https://whatsnew.fyi/product/kavita) - Vendor: Kavita - Date: 2026-05-14 - Version: v0.9.0.2 - Original notes: https://github.com/Kareadita/Kavita/releases/tag/v0.9.0.2 - Permalink: https://whatsnew.fyi/product/kavita/releases/v0.9.0.2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Critical vulnerability fixed (CVE-2026-47202) - **changed** — OIDC validation no longer requires super safe urls - **fixed** — Fixed reading list detail tab not having tabs wired up - **fixed** — Fixed series/chapter rating always returning 0 if you had rated it - **fixed** — Fixed bookmarks not loading - **fixed** — Fixed text & image bookmarks being switched - **fixed** — Fixed long chapter names causing wrapping in activity overview - **fixed** — Fixed epub bookmarks not loading - **fixed** — Fixed people not being removed from series if chapter metadata has none - **fixed** — Fixed series not being added to a collection under some circumstances - **fixed** — Fixed early reloading causing double K+ plus calls when matching on the series page - **fixed** — Fixed annotations duplicating & swallowing text under some circumstances - **fixed** — Fixed annotations not being shown under specific circumstances - **fixed** — Fixed external links containing sometimes being scoped out of a book - **fixed** — Fixed search being unreliable when searching with year metadata **All users are strongly advised to update immediately.** There has been a critical vulnerability discovered in Kavita. Please update your instances. All versions prior to this release are impacted. If you are holding out on an old release due to some change in Kavita, please raise a FR and I will work with you to help bridge that feature gap. Details/CVE will be shared at a later date to give users time to update. Edit: CVE Published: CVE-2026-47202 #### Changed - Changed: OIDC validation no longer requires super safe urls. #### Fixed - Fixed: Fixed reading list detail tab not having tabs wired up. - Fixed: Fixed series/chapter rating always returning 0 if you had rated it. - Fixed: Fixed bookmarks not loading. - Fixed: Fixed text & image bookmarks being switched. - Fixed: Fixed long chapter names causing wrapping in activity overview. - Fixed: Fixed epub bookmarks not loading. - Fixed: Fixed text & image bookmarks being switched. - Fixed: Fixed long chapter names causing wrapping in activity overview. - Fixed: Fixed people not being removed from series if chapter metadata has none. - Fixed: Fixed series not being added to a collection under some circumstances. - Fixed: Fixed early reloading causing double K+ plus calls when matching on the series page. - Fixed: Fixed annotations duplicating & swallowing text under some circumstances. - Fixed: Fixed annotations not being shown under specific circumstances. - Fixed: Fixed external links containing sometimes being scoped out of a book. - Fixed: Fixed search being unreliable when searching with year metadata.