v2.3.0
We haven't tagged a release in a while. That's not how we like it and we have some solid plans to set a routine for releases so they are tagged for your convenience.
Development has still been active with major contributions by both SmartRent and NervesCloud and occasional improvements from others.
This release comes with a security advisory. Available here as CVE-2025-64097
Big credit to Redwire Labs for the discovery and PoC. This has not been seen in the wild. It is a brute-force attack on the generated auth token. The CVE rating system makes it out to a critical level. Most operators of NervesHub do not need to worry. Just update.
It is worth mentioning some of the nuances that the rating doesn't indicate. There are several circumstances where it is not exploitable. Most people we've talked to have their NervesHub instance behind a VPN or similar which fully mitigates the issue. It also requires some knowledge about when an API key was generated to constrain the search space of the attack.