BTCPay Server 2.4.3 Tightens Access Boundaries; Shared Hosts Should Upgrade
BTCPay Server 2.4.3 remains the latest stable release five days after publication. The project calls it a security release and recommends upgrading, especially on servers shared by many users. No later release or amended note was present in the official release inventory when Satoshi Gazette rechecked it on August 29. The public comparison with 2.4.2 shows a broad access-boundary hardening pass: tighter permission checks around user API keys, server-admin store membership and legacy store tokens; current-password verification for email or password changes; narrower exposure of invitation URLs; and added controls on public form and NFC request paths. The diff does not establish that every change belongs to one vulnerability, and the project has not published an advisory naming the flaw, severity, affected-version range or active exploitation. That is the self-hosting bargain in concrete form. BTCPay lets a merchant accept Bitcoin without handing payment control to a processor, but no intermediary can patch a self-hosted server on the operator’s behalf. Operators should identify the version they run, preserve a recovery path and use BTCPay’s official upgrade procedure. Until the project discloses more, the defensible message is direct: shared-server operators have a current reason to upgrade, while everyone else should avoid inventing an attack story the evidence does not provide.
Primary record: github.com