././@PaxHeader 0000000 0000000 0000000 00000000034 00000000000 010212 x ustar 00 28 mtime=1787067271.5019178
SABnzbd-5.1.1/README.mkd 0000644 0000000 0000000 00000011635 15241075610 013646 0 ustar 00runner staff Release Notes - SABnzbd 5.1.1
=========================================================
## Critical authentication vulnerability resolved in 5.1.1 (GHSA-xrfq-jhgh-wqch)
You are only affected if an untrusted party can reach the web interface.
By default, SABnzbd is only accessible from your own device and `External internet access`
is set to `No access`. If either of those is still at its default, or if you use a proxy
service for authentication, you are not affected.
If the SABnzbd login page is reachable from outside your network, an attacker could
obtain a valid session in version 5.1.0 and earlier, even when SABnzbd is protected with
a username and password. This means that all information in SABnzbd would be exposed.
If you rely on the SABnzbd username and password to keep out other users on your
network or the internet, it is recommended that you change the following
sensitive information after applying the update:
* SABnzbd username and password.
* SABnzbd API-key.
* Usenet server passwords.
* API-keys from indexers used within RSS-feeds.
* Authentication information for notification services.
If you cannot update right away, the only mitigations are to ensure the web interface is not
reachable by untrusted parties, or to lower `External internet access` to `Full API` or below.
More information: https://sabnzbd.org/auth-bypass
## Other bug fixes in 5.1.1
* Styling cache issues could occur after updating.
* RSS items were removed too eagerly from RSS-history after download.
* The RSS-feed `Clear Downloaded` button did not do anything.
## Changelog 5.1.0
This release brings a fundamental improvement to "Retry": instead of
re-downloading any files with missing data, only the articles that were actually
missing are fetched again. RSS got an overhaul under the hood, the interface is
refreshed, and we added quite a long list of long-requested features and bugfixes.
## New features in 5.1.0
* Refreshed the interface.
* When Retrying a job, only the actually missing articles are tried again.
This only works for jobs downloaded in 5.1.0 (or newer).
* RSS items are now stored in the database instead of on disk.
* New RSS `Age` rule to filter jobs based on their age.
* Downloaded RSS items are cleared from the RSS database after 3 days.
* Added support for filename and path pattern matching to the `Cleanup List`.
* `Unwanted extensions` will also be removed after unpacking.
* Allow job setting changes directly from `Extra queue columns`.
* Added support for unpacking `.tar` files during post-processing.
* Improved anonymization of the logs when using `Show Logging`.
* Added `SAB_FILES` environment variable to Post-processing scripts,
listing all files that resulted from the job.
* New Servers will default to 16 connections instead of 8.
* Use media duration as part of `Ignore Samples` detection.
* Added option to (auto) sort the queue by Remaining Percentage.
* Improved support for screen readers.
* Parsing of header-encrypted RARs will use significantly fewer resources.
* Add Ayatana AppIndicator tray support on GNOME.
* Removed redundant `INSTALL.txt` file.
* Dropped support for Python 3.9.
* Windows and macOS: Updated Python to 3.14.6, Unrar to 7.23 and 7zip to 26.02.
## Bug fixes in 5.1.0
* Prevent incorrect warnings about non-writeable directories.
* Files unrelated to job could get removed by the `Cleanup List` logic.
* Prevent path traversal in orphaned job APIs.
* `Disk Full` errors from unrar were not handled gracefully during unpacking.
* Memory leak could occur during article decoding.
* In containers (like Docker), the Article Cache could exceed the memory limit.
* Diskspace checks would be too strict when unpacking to different disk.
* Prevent deadlock when a second signal arrives during shutdown procedure.
* Verification using SFV-checks could fail, even though files were correct.
* Don't log Warning during clean shutdowns.
* Windows: Uninstall would not remove Settings or Windows Service.
* Windows: Warn for OS-limit if more than 1024 connections are configured.
* macOS: AppleDouble files could result in failures in `Moving` stage.
* macOS: Restarting the application resulted in Terminal window.
* macOS: Included par2cmdline-turbo will now use all available CPU-features.
## Upgrade notices
* You can directly upgrade from version 3.0.0 and newer.
* Upgrading from older versions will require performing a `Queue repair`.
## Known problems and solutions
* Read `ISSUES.txt` or https://sabnzbd.org/wiki/introduction/known-issues
## Code Signing Policy
Windows code signing is provided by SignPath.io using a SignPath Foundation certificate.
## About
SABnzbd is an open-source cross-platform binary newsreader.
It simplifies the process of downloading from Usenet dramatically, thanks to its web-based
user interface and advanced built-in post-processing options that automatically verify, repair,
extract and clean up posts downloaded from Usenet.
(c) Copyright 2007-2026 by The SABnzbd-Team (sabnzbd.org)
././@PaxHeader 0000000 0000000 0000000 00000000034 00000000000 010212 x ustar 00 28 mtime=1787067271.5172527
SABnzbd-5.1.1/ISSUES.txt 0000644 0000000 0000000 00000005062 15241075610 013765 0 ustar 00runner staff *******************************************
*** Known issues ***
*******************************************
- To prevent unexpectedly large NZBs from eating your download quota you can set
the option 'size_limit' on the Config->Special page.
Any NZB larger than this size will be set to paused and get a low priority.
- When par2 or unrar hang up, never just stop SABnzbd.
Instead use your operating system's task manager to stop the par2 or unrar program.
Forcing SABnzbd to quit may damage your queues.
- Some Usenet servers have intermittent login (or other) problems.
For these the server blocking method is not very favourable.
There is an INI-only option that will limit blocks to 1 minute.
no_penalties = 1
See: https://sabnzbd.org/wiki/configuration/3.4/special
- Some third-party utilities try to probe SABnzbd API in such a way that you will
often see warnings about unauthenticated access.
If you are sure these probes are harmless, you can suppress the warnings by
setting the option "api_warnings" to 0.
See: https://sabnzbd.org/wiki/configuration/3.4/special
- On macOS you may encounter downloaded files with foreign characters.
The par2 repair may fail when the files were created on a Windows system.
The problem is caused by the PAR2 utility and we cannot fix this now.
This does not apply to files inside RAR files.
- The "Watched Folder" sometimes fails to delete the NZB files it has
processed. This happens when other software still accesses these files.
Some third-party utilities supporting SABnzbd are known to do this.
We cannot solve this problem, because the Operating System (read Windows)
prevents the removal.
- When SABnzbd cannot send notification emails, check your virus scanner,
firewall or security suite. It may be blocking outgoing email.
- When you are using external drives or network shares on macOS or Linux
make sure that the drives are mounted.
The operating system will simply redirect your files to alternative locations.
You may have trouble finding the files when mounting the drive later.
On macOS, SABnzbd will not create new folders in /Volumes.
The result will be a failed job that can be retried once the volume has been mounted.
- If you use a mounted drive as "temporary download folder", it must be present when SABnzbd
starts up. If not, SABnzbd will use the default location.
You can make SABnzbd wait for a mount of the "temporary download folder" by setting
Config->Special->wait_for_dfolder to 1.
SABnzbd will appear to hang until the drive is mounted.
././@PaxHeader 0000000 0000000 0000000 00000000034 00000000000 010212 x ustar 00 28 mtime=1787067271.5173767
SABnzbd-5.1.1/COPYRIGHT.txt 0000644 0000000 0000000 00000002070 15241075610 014316 0 ustar 00runner staff
(c) Copyright 2007-2026 by The SABnzbd-Team (sabnzbd.org)
The SABnzbd-Team is:
Active team:
Safihre
mnightingale
sanderjo
jcfp
inpheaux
zoggy
Sleeping members:
ShyPike
sw1tch
pairofdimes
rAf
Honorary member (and original author):
Gregor Kaufmann
The contributors and moderators of the translations are credited in the
header of each translation file in the po/ directory.
This program is free software; you can redistribute it and/or
modify it under the terms of the GNU General Public License
as published by the Free Software Foundation; either version 2
of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, see
You are only affected if an untrusted party can reach the web interface.
By default, SABnzbd is only accessible from your own device and External internet access
is set to No access. If either of those is still at its default, or if you use a proxy
service for authentication, you are not affected.
If the SABnzbd login page is reachable from outside your network, an attacker could
obtain a valid session in version 5.1.0 and earlier, even when SABnzbd is protected with
a username and password. This means that all information in SABnzbd would be exposed.
If you rely on the SABnzbd username and password to keep out other users on your
network or the internet, it is recommended that you change the following
sensitive information after applying the update:
If you cannot update right away, the only mitigations are to ensure the web interface is not
reachable by untrusted parties, or to lower External internet access to Full API or below.
More information: https://sabnzbd.org/auth-bypass
Clear Downloaded button did not do anything.This release brings a fundamental improvement to "Retry": instead of
re-downloading any files with missing data, only the articles that were actually
missing are fetched again. RSS got an overhaul under the hood, the interface is
refreshed, and we added quite a long list of long-requested features and bugfixes.
Age rule to filter jobs based on their age.Cleanup List.Unwanted extensions will also be removed after unpacking.Extra queue columns..tar files during post-processing.Show Logging.SAB_FILES environment variable to Post-processing scripts,Ignore Samples detection.INSTALL.txt file.Cleanup List logic.Disk Full errors from unrar were not handled gracefully during unpacking.Moving stage.Queue repair.ISSUES.txt or https://sabnzbd.org/wiki/introduction/known-issuesWindows code signing is provided by SignPath.io using a SignPath Foundation certificate.
SABnzbd is an open-source cross-platform binary newsreader.
It simplifies the process of downloading from Usenet dramatically, thanks to its web-based
user interface and advanced built-in post-processing options that automatically verify, repair,
extract and clean up posts downloaded from Usenet.
(c) Copyright 2007-2026 by The SABnzbd-Team (sabnzbd.org)