| v2.2.0 | ## Added - Optional MCP OAuth protected-resource mode with resource discovery, signed access-token validation and authenticated legacy-session ownership. Static-token deployments and STDIO remain available. See the OAuth configuration guide for provider and HTTPS routing requirements. ([#277](https://github.com/ihor-sokoliuk/mcp-searxng/pull/277)) ## Fixed and security - Block private IPv4 destinations embedded in IPv6 and native non-global IPv6 URL targets. ([#266](https://github.com/ihor-so | High | 9/9/2026 |
| v2.1.0 | ## Fixed - **Reliable time-range validation for explicit engines:** Searches that explicitly select engines now verify each engine's live time-range capability before sending the request. Unsupported, unknown, or unavailable capability information fails closed with an actionable error instead of returning a misleading empty result, while requests without both `engines` and `time_range` keep their existing behavior. ([#244](https://github.com/ihor-sokoliuk/mcp-searxng/pull/244)) ## Build / CI - | Medium | 8/25/2026 |
| v2.0.0 | ## Breaking Changes - **Node.js 22 or later is now required:** Node.js 20 is no longer supported, and the PDF extraction runtime now uses `unpdf` 1.8.1 with loading-task teardown. Consumers and deployments must upgrade to Node.js 22 or a newer supported release before installing mcp-searxng 2.0.0. ([#251](https://github.com/ihor-sokoliuk/mcp-searxng/pull/251), [#253](https://github.com/ihor-sokoliuk/mcp-searxng/pull/253)) - **STDIO post-connect logging notifications were removed:** The modern | High | 8/21/2026 |
| v1.14.1 | ### Fixed - **Built HTTP transport regression coverage now exercises real loopback TCP:** The end-to-end suite launches the compiled CLI in both stateful and stateless modes and verifies session negotiation, tool listing, bounded readiness and diagnostics, process cleanup, and narrowly classified address-in-use retries. This is test-only hardening; supported transport behavior is unchanged. ([#237](https://github.com/ihor-sokoliuk/mcp-searxng/pull/237)) ### Changed - **Compatible runtime depe | High | 8/7/2026 |
| v1.12.0 | ### Fixed - **Established HTTP sessions now receive the configured session rate limit:** Each `POST /mcp` request now passes through exactly one limiter. Requests with a currently live `mcp-session-id` use the session allowance, while initialization requests and missing, malformed, unknown, or stale session identifiers retain the stricter initialization limit. ([#179](https://github.com/ihor-sokoliuk/mcp-searxng/pull/179)) - **Logging now honors all eight MCP severity levels:** Filtering recog | High | 7/26/2026 |
| v1.11.1 | ### Fixed - **Hardened HTTP mode no longer rejects every request on non-default ports:** With `MCP_HTTP_HARDEN` enabled and `MCP_HTTP_ALLOWED_HOSTS` left unset, the default DNS-rebinding Host allowlist contained only the bare hostnames `127.0.0.1` and `localhost`. Because the transport matches the raw `Host` header — port included — with an exact list-membership check, any bind to a port other than 80 caused every request (including the initial `initialize`) to fail with `403`. The bind port is | High | 7/14/2026 |
| v1.10.1 | ### Fixed - **`USER_AGENT` now applied to the `/config` and suggestions requests:** The configured `USER_AGENT` header is now sent on the SearXNG `/config` instance-info fetch and on search-suggestion fetches. These two paths previously always used the default agent while the main search and `web_url_read` paths already honored `USER_AGENT`, so instances that filter or rate-limit by User-Agent behaved inconsistently. The header is now merged in one shared request-config helper covering every ou | High | 7/4/2026 |
| v1.8.0 | ### Added - **Multi-instance failover and optional parallel fanout for `SEARXNG_URL`:** `SEARXNG_URL` now accepts several semicolon-separated SearXNG replica URLs that are treated as interchangeable. In the default failover mode a search tries each instance in order until one returns results; an instance with 3 consecutive hard failures is skipped for 60 seconds, while a `200 OK` with an empty result set is treated as healthy and does not trigger cooldown. Set the new `SEARXNG_FANOUT=true` to i | High | 6/23/2026 |
| v1.6.0 | This release rolls up **everything since v1.4.0**. Note: `1.5.0` was published to npm and Docker Hub on 2026-06-12 but never received a GitHub release — those changes are included below alongside the new 1.6.0 work. ## ✨ Added - **`engines` parameter on `searxng_web_search`** — a comma-separated list (e.g. `google,bing,duckduckgo`) routes a search to specific SearXNG engines instead of the category defaults. - **Validated & normalized `categories` / `engines`** — values are trimmed and matched | High | 6/16/2026 |
| v1.3.3 | ### Fixed - `test:coverage` script now enforces the coverage threshold mechanically. - Gitignored AI process artifacts (plans, drafts) so they can never be committed. ### Security - Docker base image (`node:lts-alpine`) is now pinned by digest and bumped automatically via Dependabot. - Added a weekly rebuild workflow: when upstream patches the base image, the published Docker image is rebuilt from the latest release tag, re-scanned with Trivy, and republished under the same version tags. Publis | High | 6/10/2026 |
| v1.1.0 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v1.0.4...v1.1.0 In two words: fixed the URL FETCH tool and added the MCP_HTTP_HOST parameter to customize the MCP Server address binding. | High | 6/3/2026 |
| v1.0.4 | ## What's Changed * fix: escape user input in extractSection regex to prevent ReDoS (CWE-1333) by @sebastiondev in https://github.com/ihor-sokoliuk/mcp-searxng/pull/71 * docs: improve tool description to prevent LLM using `prompt` instead of `query` by @MikeWang0316tw in https://github.com/ihor-sokoliuk/mcp-searxng/pull/80 * fix: add mcp-protocol-version to CORS allowedHeaders by @michaeltg17 in https://github.com/ihor-sokoliuk/mcp-searxng/pull/77 ## New Contributors * @sebastiondev made | High | 5/23/2026 |
| v1.0.3 | ## What's Changed * fix: create new McpServer per HTTP session to prevent 'Already connected' crash by @frap129 in https://github.com/ihor-sokoliuk/mcp-searxng/pull/66 ## New Contributors * @frap129 made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/66 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v1.0.1...v1.0.3 | High | 4/5/2026 |
| v1.0.1 | ## What's Changed * Enhance SEARXNG_URL validation, error handling, and documentation by @ihor-sokoliuk in https://github.com/ihor-sokoliuk/mcp-searxng/pull/64 ## New Contributors * @ihor-sokoliuk made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/64 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.10.5...v1.0.1 | Medium | 4/1/2026 |
| v0.10.1 | Mainly, the dependencies are updated to the latest version to address vulnerabilities. **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.10.0...v0.10.1 | Medium | 3/30/2026 |
| v0.10.0 | ## What's Changed * feat: add separate proxy config and custom user_agent for web_url_read by @531014023 in https://github.com/ihor-sokoliuk/mcp-searxng/pull/55 * Add troubleshooting docs for SearXNG JSON format 403 error by @Copilot in https://github.com/ihor-sokoliuk/mcp-searxng/pull/58 ## New Contributors * @531014023 made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/55 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.9.2... | Low | 3/21/2026 |
| v0.9.2 | Add handler for listing resource templates **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.9.1...v0.9.2 | Low | 3/11/2026 |
| v0.9.1 | ## What's Changed * Track package-lock.json in version control by @Copilot in https://github.com/ihor-sokoliuk/mcp-searxng/pull/50 * Update console.log to console.error for better MCP STDIO compliance by @SamAcctX in https://github.com/ihor-sokoliuk/mcp-searxng/pull/51 * Release 0.9.1 by @Copilot in https://github.com/ihor-sokoliuk/mcp-searxng/pull/52 ## New Contributors * @SamAcctX made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/51 **Full Changelog** | Low | 2/22/2026 |
| v0.8.0 | Added a User-Agent header to requests **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.7.11...v0.8.0 | Low | 11/9/2025 |
| v0.7.11 | Added linux/arm64 Docker image **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.7.9...v0.7.11 | Low | 10/29/2025 |
| v0.7.9 | Added `NO_PROXY` env variable **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.7.8...v0.7.9 | Low | 10/29/2025 |
| v0.7.8 | Code cleanup and proxy fix ## What's Changed * refactor(logging): merge message and data in notification params by @sheldonxxxx in https://github.com/ihor-sokoliuk/mcp-searxng/pull/29 ## New Contributors * @sheldonxxxx made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/29 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.7.0...v0.7.8 | Low | 10/19/2025 |
| v0.7.0 | ## What's Changed * Fix error when connecting via HTTP by @cdzombak in https://github.com/ihor-sokoliuk/mcp-searxng/pull/25 * Allow reading a page in parts by @cdzombak in https://github.com/ihor-sokoliuk/mcp-searxng/pull/24 ## New Contributors * @cdzombak made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/25 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.6.2...v0.7.0 | Low | 9/25/2025 |
| v0.6.2 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.6.1...v0.6.2 | Low | 9/6/2025 |
| v0.6.1 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.6.0...v0.6.1 | Low | 8/24/2025 |
| v0.6.0 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.5.2...v0.6.0 | Low | 8/23/2025 |
| v0.5.2 | ## What's Changed * Add 'score' to the result, update dependencies * adds eval testing by @mclenhard in https://github.com/ihor-sokoliuk/mcp-searxng/pull/10 ## New Contributors * @mclenhard made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/10 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.5.1...v0.5.2 | Low | 8/9/2025 |
| v0.5.1 | regular monitor and addressing of CVEs **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.5.0...v0.5.1 | Low | 7/7/2025 |
| v0.5.0 | ## What's Changed * Make it work with Goose by @genkernel in https://github.com/ihor-sokoliuk/mcp-searxng/pull/9 * Add support for HTTP Basic Auth by @hutchisr in https://github.com/ihor-sokoliuk/mcp-searxng/pull/12 ## New Contributors * @genkernel made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/9 * @hutchisr made their first contribution in https://github.com/ihor-sokoliuk/mcp-searxng/pull/12 **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-s | Low | 6/2/2025 |
| v0.4.5 | Fixed NPM installation | Low | 4/22/2025 |
| v0.4.1 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.4.0...v0.4.1 | Low | 4/19/2025 |
| v0.4.0 | **Full Changelog**: https://github.com/ihor-sokoliuk/mcp-searxng/compare/v0.3.4...v0.4.0 | Low | 4/19/2025 |
| v0.3.3 | Automatically generated release for version 0.3.3 Changes since v0.3.2: Merge branch 'main' of github.com:ihor-sokoliuk/mcp-searxng | Low | 4/17/2025 |
| v0.3.2 | Automatically generated release for version 0.3.2 Changes since v0.3.1: fix: Update auto-release workflow to use Ubuntu runner and simplify Git configuration steps | Low | 4/17/2025 |