What changed, and why it matters
This commit only adds a changelog entry for BTCPay Server version 2.4.5. The changelog itself describes several security-related fixes and one breaking change that blocks private-network outbound requests by default to prevent server-side request forgery (SSRF). It also mentions fixes for invoice search scoping, antiforgery validation, payout scoping, refund permissions, and URL validation. Because the commit is just documentation summarizing prior changes, the direct code risk is low, but the listed changes indicate that the 2.4.5 release addresses multiple security issues.
Treat this changelog as a security release note for BTCPay Server 2.4.5. Operators should upgrade to 2.4.5 and review the new ssrfexceptions configuration if they rely on private-network Lightning, LNURL, notification, or webhook targets. Administrators should also audit store-scoped permissions and refund/payout workflows.
Security signals we found
SSRF mitigation: private-network outbound requests blocked by default for Lightning, LNURL, invoice notifications, and webhooks
Permission escalation fix: employees without approved-pull-payment permission can no longer auto-approve overpayment refunds
Cross-store access fix: invoice searches and payout payment actions scoped to current store
CSRF protection: antiforgery validation required when changing invoice status in browser
URL validation: generated account/password-reset/store-invitation links use configured Base URL and reject non-HTTP(S) values
URL validation: Store Website URLs restricted to absolute HTTP/HTTPS in UI and Greenfield API
Access-token scoping: failed token revocations kept scoped to authorized store
Evidence from the diff
Commit 0cb14ec is a documentation-only change adding the 2.4.5 changelog to Changelog.md. The changelog enumerates security-relevant changes merged in other commits, including: default blocking of private-network destinations for Lightning, LNURL, invoice notifications, and webhooks to mitigate SSRF; permission checks for auto-approving overpayment refunds; antiforgery validation on invoice status changes; scoping of invoice searches and payout actions to the current store; validation of Store Website URLs and server Base URLs; and store-scoping of access-token revocation failures. No source code is modified in this commit, so exploitability depends entirely on the prior commits it references.
Changed components
Changelog.mdLightning/LNURL outbound HTTP clientInvoice notification URLs and webhooksRefund/payout workflowInvoice search and status managementStore settings / Greenfield APIAccess token managementGenerated account/password-reset/store-invitation linksInspect captured patch +48 / −0
### Changelog.md
@@ -1,5 +1,53 @@
# Changelog
+## 2.4.5
+
+### Breaking changes
+
+* **Outbound HTTP requests**: Block private-network destinations for Lightning connections, LNURL requests, invoice notification URLs, and webhooks by default to prevent SSRF. Operators using private services must [allow them with `ssrfexceptions`](https://docs.btcpayserver.org/Operators/#allow-private-outbound-destinations) (#7581 #7626 #7627 #7635 #7636 #7637 #7638 #7644 #7646) @NicolasDorier
+* **Refunds**: Employees without permission to create approved pull payments can no longer auto-approve invoice overpayment refunds; another user must approve the payout (#7649) @NicolasDorier
+
+### New features
+
+* **Greenfield**: Add APIs for discovering and running store reports (#7608) @NicolasDorier
+* **Plugins**: Simplify registering and migrating plugin-owned EF Core database contexts (#7611) @NicolasDorier
+* **Invoices**: Add the `btcpay.store.canmanageinvoicestatus` permission for marking invoices as settled or invalid (#7643) @NicolasDorier
+* **Access Tokens**: Add the `btcpay.store.canmanagelegacyaccesstokens` permission for managing legacy BitPay-compatible tokens and pairing requests (#7502 #7612 #7631) @okjodom @NicolasDorier
+
+### Fixes
+
+* **Invoices**: Avoid invoice creation crashes when a payment method reuses another invoice's destination ([btcpayserver-monero-plugin#57](https://github.com/btcpay-monero/btcpayserver-monero-plugin/issues/57), #7483) @CaMoPeZzz
+* **Invoices**: Keep invoice searches scoped to the current store (#7599) @NicolasDorier
+* **Invoices**: Require antiforgery validation when changing invoice status in the browser (#7643) @NicolasDorier
+* **Payouts**: Complete payouts and send update webhooks when an RBF replacement confirms (#7625 #7641) @NicolasDorier
+* **Payouts**: Scope payout payment actions to the current store (#7642) @NicolasDorier
+* **Refunds**: Calculate refundable and overpaid amounts only from settled payments (#7600) @NicolasDorier
+* **Refunds**: Require permission to create approved pull payments before auto-approving invoice overpayment refunds (#7649) @NicolasDorier
+* **Reports**: Correct All Time and rolling date ranges (#7608) @NicolasDorier
+* **Lightning**: Persist replacement invoices before canceling previous invoices to keep payments available when replacement fails (#7630) @NicolasDorier
+* **Lightning**: Use LND's WebSocket invoice subscription instead of long polling (#7621) @NicolasDorier
+* **Lightning**: Use only the authorized store when redisplaying setup and settings forms (#7618) @Team1-dev
+* **Generated links**: Use the configured server Base URL for account, password-reset, and store-invitation links, and reject non-HTTP(S) Base URLs (#7590 #7628) @NicolasDorier
+* **Store settings**: Accept only absolute HTTP or HTTPS Store Website URLs in the UI and Greenfield API (#7604) @NicolasDorier, reported by @gn00295120
+* **API Keys**: Show an error instead of a server error when confirming a removed API key (#7568 #7570) @monasco
+* **Access Tokens**: Keep failed token revocations scoped to the authorized store (#7629) @NicolasDorier
+* **Server users**: Return Not Found instead of a server error when sending a verification email to a deleted user (#7571 #7572) @monasco
+* **Plugins**: Run registered plugin database migrations reliably during startup (#7588) @NicolasDorier
+
+### Improvements
+
+* **Invoices**: Create invoices noticeably faster by avoiding unnecessary Lightning node and on-chain fee lookups (#7632 #7633 #7634) @NicolasDorier, reported by @bigg-bb
+* **Access Tokens**: Warn against using legacy BitPay-compatible tokens for new integrations (#7624) @NicolasDorier
+* **Server settings**: Organize administration pages into clearer labeled sections (#7501) @dstrukt
+* **Server administration**: Refresh `btcpay-host` deployment capabilities on `SIGHUP` without restarting BTCPay Server (#7576) @NicolasDorier
+* **LND**: Warn administrators when Docker's LND REST or gRPC endpoint is available but its reverse-proxy route is disabled (#7593) @NicolasDorier
+* **Receipts**: Show the original invoice amount alongside the amount paid on overpaid receipts (#7595 #7597) @NicolasDorier
+* **Documentation**: Rewrite the plugin development guides to make plugins easier to build with coding agents (#7598) @NicolasDorier
+
+### Miscellaneous
+
+* **Invoices**: Deprecate invoice notification URLs in favor of webhooks and remove the notification URL from manual invoice creation (#7647) @NicolasDorier
+
## 2.4.4
### Breaking changesWhy this scored 79/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.