CrystalJohannes Müller1 min readrelease notesintro
Crystal 1.21.1 is released!
Summary
Crystal 1.21.1 is a patch release addressing critical security vulnerabilities in its HTTP server and deserialization, along with a regression fix for socket connections on macOS 26.7 and 27. Users are advised to upgrade to mitigate potential request smuggling, resource exhaustion, and application crashes.
- Fixes non-blocking Socket#connect on macOS 26.7/27, which was previously faulty.
- Patches HTTP::Server against request smuggling via unconsumed request bodies.
- Mitigates resource exhaustion attacks (zip bombs) in HTTP request body decompression.
- Resolves process crashes in XML and YAML parsers due to unusual self-referencing or malformed constructs.
Crystal users should upgrade immediately to patch critical security vulnerabilities in the HTTP server and deserialization, and to fix a macOS socket connection regression.
4/10

