Release Notes - v4.4.2 🚀
April 23, 2026
This release includes a security fix in Axios and user interface adjustments in the PEEC and POQTROL modules.
🌐 General
Bug Fixes
- Updated Axios dependency to mitigate vulnerability CVE-2026-40175 (#1112)
Impact Analysis (CVE-2026-40175)
Prevented Attack Vector: Using a vulnerable version of Axios exposes backend functions (such as the Siigo API integration and Telegram bot) to attack vectors like Server-Side Request Forgery (SSRF) or HTTP header injection. By patching the library, we eliminate at the root the possibility of manipulated data compromising server network requests, keeping Midna's external communications secure.
Note: Considering the methods in question are not currently being used in any active product (Siigo is in testing phase and My Process no longer uses this function), we see no apparent risk; however, it remains a critical security update.
🔬 PEEC
Bug Fixes
- Increased chart resolution for PEEC reports (#1103)
📈 POQTROL
Bug Fixes
- Fixed glucometer numeric formatting in POQTROL (#1105)