# Tautulli v2.17.2 — Tautulli v2.17.2 - Product: Tautulli (https://whatsnew.fyi/product/tautulli) - Vendor: Tautulli - Date: 2026-06-16 - Version: v2.17.2 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.2 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.2 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Line breaks in Gotify notification body text - **security** — XSS in newsletter cron value (CVE-2026-49995) - **security** — Reflected XSS in search query string (CVE-2026-45381) - **fixed** — Duplicated activity card progress timers - **fixed** — X-Api-Key header check crashing server - **security** — Path traversal in uploaded database and config file names (CVE-2026-52835) - **fixed** — Empty host fallback in URL when launching browser - **security** — Open redirect via whitespace bypass in /auth/redirect (CVE-2026-54915) ##### Changelog ###### v2.17.2 (2026-06-16) * Notifications: * Fix: Line breaks in Gotify notification body text. (#2702) * Newsletters: * Fix: XSS in newsletter cron value. (CVE-2026-49995) (Thanks @elvinsuleymanov) * UI: * Fix: Reflected XSS in search query string. (CVE-2026-45381) (Thanks @JakePeralta7, @sondt99, @kah-ja) * Fix: Duplicated activity card progress timers. (#2716) (Thanks @omglazrgunpewpew) * Other: * Fix: Fix X-Api-Key header check crashing server. (#2711) * Fix: Path traversal in uploaded database and config file names. (CVE-2026-52835) (Thanks @tonghuaroot) * Fix: Empty host fallback in URL when launching browser. (#2722) (Thanks @upmcplanetracker) * Fix: Open redirect via whitespace bypass in /auth/redirect (CVE-2026-54915) (Thanks @sondt99) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.2-universal.pkg`](https://www.virustotal.com/gui/file-analysis/NzM1YzY3ZDQxODAwY2Q1NDJkNTUwZDUzYmJiOTIyMTA6MTc4MTYyNTk2MA==/detection) * [`Tautulli-windows-v2.17.2-x64.exe`](https://www.virustotal.com/gui/file-analysis/MDMxNjI4NTdmMzFmYmI1ZGEzYmE4OGRiOTVkYTdiNjk6MTc4MTYyNTk1OA==/detection)