# Miniflux 2.2.17 — Miniflux 2.2.17 - Product: Miniflux (https://whatsnew.fyi/product/miniflux) - Vendor: Frédéric Guillot - Date: 2026-02-13 - Version: 2.2.17 - Original notes: https://github.com/miniflux/v2/releases/tag/2.2.17 - Permalink: https://whatsnew.fyi/product/miniflux/releases/2.2.17 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Do not expose the Miniflux version on unauthenticated endpoints - **security** — Improve HTML sanitizer by switching from the tokenizer to the golang.org/x/net/html parser to better match browser behavior and reduce the risk of injection issues - **security** — Enforce blocked resource checks on srcset URLs - **security** — Improve blocked resource handling including updates to blocked URL substrings - **security** — Add validation for TRUSTED_REVERSE_PROXY_NETWORKS configuration to prevent silent misconfiguration - **security** — Prevent possible deadlock when cleaning removed entries - **security** — Ensure HTTP response bodies are always closed, even on client errors - **changed** — Rewrite srcset parser to follow HTML specifications and handle edge cases more correctly - **changed** — Improve sanitizer performance with various optimizations including reduced allocations and better attribute handling - **changed** — Handle deeply nested HTML more robustly in the sanitizer - **added** — Add scraper and rewrite rules for bleepingcomputer.com and vnexpress.net - **changed** — Support malformed JSON feeds with author objects in the authors array - **fixed** — Avoid panic when parsing null feeds - **changed** — Improve JSON Feed title fallback logic - **changed** — Include external_url in JSON entry hash fallback - **changed** — Ignore WordPress wp-json API endpoint during JSON feed discovery - **added** — Add unread status filter to search results - **changed** — Improve timezone handling internals and performance - **fixed** — Do not keep old enclosures when an updated entry has none - **fixed** — Handle sql.ErrNoRows properly in IconByFeedID - **removed** — Remove FILTER_ENTRY_MAX_AGE_DAYS configuration option ###### Security * Do not expose the Miniflux version on unauthenticated endpoints (deprecated since version 2.0.49). * Improve HTML sanitizer by switching from the tokenizer to the `golang.org/x/net/html` parser to better match browser behavior and reduce the risk of injection issues. * Enforce blocked resource checks on `srcset` URLs. * Improve blocked resource handling (including updates to blocked URL substrings). * Add validation for `TRUSTED_REVERSE_PROXY_NETWORKS` configuration to prevent silent misconfiguration. * Prevent possible deadlock when cleaning removed entries. * Ensure HTTP response bodies are always closed, even on client errors. ###### Improvements * Rewrite `srcset` parser to follow HTML specifications (WebKit-style parsing) and handle edge cases more correctly. * Improve sanitizer performance (various optimizations, including reduced allocations and better attribute handling). * Handle deeply nested HTML more robustly in the sanitizer. * Add scraper and rewrite rules for: * `bleepingcomputer.com` * `vnexpress.net` * Improve JSON Feed support: * Support malformed feeds with `author` objects in the `authors` array. * Avoid panic when parsing `null` feeds. * Improve title fallback logic. * Include `external_url` in JSON entry hash fallback. * Ignore WordPress `wp-json` API endpoint during JSON feed discovery. * Add unread status filter to search results. * Improve timezone handling internals and performance. * Improve API payload structures and Godoc comments. * Improve JavaScript code readability and keyboard shortcut handling. * Restore cmd/ctrl/shift-click behavior on main navigation. * Fix Safari PWA behavior for the `v` shortcut to open links in the main browser. ###### Bug Fixes * Do not keep old enclosures when an updated entry has none. * Handle `sql.ErrNoRows` properly in `IconByFeedID`. * Change `FindRemoteIP` to fall back to `127.0.0.1`. ###### Configuration Changes * Removed `FILTER_ENTRY_MAX_AGE_DAYS`. This option can be replaced with a filter rule such as `max-age:`. Global environment variables should be reserved for process-level configuration. ###### Dependencies * Update `github.com/lib/pq` to 1.11.2. * Update: * `golang.org/x/net` to 0.50.0 * `golang.org/x/crypto` to 0.48.0 * `golang.org/x/image` to 0.36.0 * `golang.org/x/oauth2` to 0.35.0 * `golang.org/x/term` to 0.40.0 * Update Debian packager Docker image to Trixie. --- As always, thank you to all contributors who helped improve Miniflux in this release.