Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1933 verified publisher records · Page 19 of 20

HELMHELM-3.21.2

Helm v3.21.2

Helm v3.21.2 is a patch release to correct bump the Kubernetes client libraries (client-go, etc) to match the expected Kubernetes v1.36 release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes Update Kubernetes client libraries to v1.36 Installation and Upgrading Download Helm v3.21.2. The common platform binaries are here: MacOS amd64 ( checksum / 82ac9105e657267cb029b5bf27ed28e35db104777328a036a84d345046f9f329) MacOS arm64 ( checksum / aea537342b4c03cf58e089cb8dc99468087bb1a0218531df40462faca3f6c5d3) Linux amd64 ( checksum / 0a745198de24545d0055cd8414bc8d2ba10363ef5f5d38369ea1b399671cc083) Linux arm ( checksum / d6c5ea4a0c0d8b68a525caa4fe969c5db5627365c66dc2878fe72ac1d6325f15) Linux arm64 ( checksum / bbd559fc0547f1d96ccbc68fe4f1cb98f01808f36538139e669369066b781267) Linux i386 ( checksum / 4f1d9f68c884cc143fc768d583c32cf23317713fc1e8ccbf309bb1d1ddafa15f) Linux ppc64le ( checksum / 8f0e57e13260e0c0008fec80629b560dc8891281ba3f0cd5d57895b8a5f76d8e) Linux s390x ( checksum / daf652ddbf37d5e896187d1ccc1f2868df8f261c1af5b5f2f1639022623aeefb) Linux riscv64 ( checksum / 9e4dbd48868bf92835dd0de11387b1d82636330740b8943064da233b12791964) Windows amd64 ( checksum / 5f346e3338617e9fd1b8c216065383061bdb3bde26cb6b3abc8ce0481354a513) Windows arm64 ( checksum / e77859867482549e5613255605e7680bc72b308ea62b91ecc4626ed4ba116670) This release was signed by @gjenkins8 with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739 . Please use the attached signatures for verifying this release using gpg. The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 3.21.3 will contain only bug fixes. 3.22.0 is the next (and final) Helm 3 feature release Changelog chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) fixes b52e276 (Matheus Pimenta) chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) Full Changelog : v3.21.1...v3.21.2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-4.2.2

Helm v4.2.2

Helm v4.2.2 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes Revert: Fixed a race condition in WaitForDelete where the status observer canceled the watch too early, causing intermittent failures when running a full test suite #32214 Installation and Upgrading Download Helm v4.2.2. The common platform binaries are here: MacOS amd64 ( checksum / 10c1e36ee8c5f2e2ee25a16599cb03ab74c0953cd889cacb980a49ba4b6574ba) MacOS arm64 ( checksum / 5410a0dae3d5d91f45653b161260d9301aabc4ae80ae50a6605d66884b6df8ea) Linux amd64 ( checksum / 9adafecab4d406853bba163a70e9f104f47dbbf65ce24b7653bae7e36150bcb6) Linux arm ( checksum / 7e9490169874695e04ab1af47c5620621fc13c84219a258fcc1afdcd40ca7438) Linux arm64 ( checksum / 78803142087a0069fa4b50d3f32a84d3ef25c14d1ee8a40fbccf86a6216d2f36) Linux i386 ( checksum / 8e1fdcda4a476ffc5d1179c7f16d33a3d54267efa08fd720f7678277d68bc2d5) Linux loong64 ( checksum / b8bfe96b8b0b0e2af51af4a00ef521cc5a7e03793aea3568cf8500a63ae05041) Linux ppc64le ( checksum / 814a80fd98eb9e4c5a9d610f3b9c15ffe120c2f5e39df16a2f491723ebc90126) Linux s390x ( checksum / d84cdf1123f20cfbef19a2af1cd6afe8b00626bd9846bccb9dae978c810c8274) Linux riscv64 ( checksum / f07c105180dff2619ab45134b9b47b7845387e8f3299e12ebe0efb87c7548717) Windows amd64 ( checksum / 5fad8562e98c34fa5af3ef904086a5874a6701050f9bf36e30238c975df94dcd) Windows arm64 ( checksum / 2e993d6a1dd8197a33e65d8e90b26df9d248ff3501701dea401856aa265a2dab) This release was signed by @gjenkins8 with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739 . Please use the attached signatures for verifying this release using gpg. The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.2.3 and 3.21.2 are the next patch releases scheduled for July 8, 2026 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026 Changelog Revert "fix(kube): prevent spurious early exit in WaitForDelete during informer sync" b05881c (George Jenkins) Full Changelog : v4.2.1...v4.2.2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
NGINXNGINX-1.30.3

release-1.30.3

nginx-1.30.3 stable version has been released, with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module ( CVE-2026-42055 ), and buffer overread vulnerability in the ngx_http_charset_module ( CVE-2026-48142 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.3 with security fixes by @arut in #1475 Full Changelog : release-1.30.2...release-1.30.3

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
NGINXNGINX-1.31.2

release-1.31.2

nginx-1.31.2 mainline version has been released, with fixes for use-after-free vulnerability in the ngx_http_v3_module ( CVE-2026-42530 ), buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module ( CVE-2026-42055 ), and buffer overread vulnerability in the ngx_http_charset_module ( CVE-2026-48142 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Use SipHash to speed up $request_id generation by @jimf5 in #1392 SSL: add $ssl_sigalgs variable by @VadimZhestikov in #1361 Xslt: fixed handle vsnprintf return value by @afonot in #747 GH: remove the set-creation-date.yaml workflow by @ac000 in #1435 Split clients: improved calculation of range boundaries by @pluknet in #1334 Style by @pluknet in #1440 GH: Fix the whitespace checker workflow by @ac000 in #1453 Secure link: Compare hashes in constant time by @sbhowmikf5 in #1433 Access log: Fix "request_length" format length by @nitin9977 in #1432 Updated OpenSSL used for win32 builds by @pluknet in #1469 Nginx 1.31.2 with security fixes (HTTP/2 proxy, grpc, HTTP/3, charset) by @arut in #1474 New Contributors @afonot made their first contribution in #747 @sbhowmikf5 made their first contribution in #1433 @nitin9977 made their first contribution in #1432 Full Changelog : release-1.31.1...release-1.31.2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.0.3

v2.0.3

SECURITY: auth/radius: Added case_insensitive_names toggle to prevent username collisions and enable case-insensitive user handling. core/acl: Fix LIST ACL bypass where a trailing-slash request could skip a more-specific deny rule. core: Use constant-time recovery token comparison secrets/spiffe (enterprise): Ensure template values are properly escaped. transform (enterprise): Add appropriate db specific quoting and escaping. CHANGES: auth/cf: Update plugin to v0.23.1 core/acl: LIST requests with a trailing slash now correctly respect more-specific deny policies. Previously, a deny on path "kv/*" { deny } could be bypassed for LIST kv/private/ if a broader allow path "kv/*" also existed. Policies relying on the previous (incorrect) behavior may now be denied. core: Vault will now redirect non-canonicalized paths (containing /./ , /../ , or // ) to a cleaned path, instead of rejecting these requests secrets/azure: Update plugin to v0.26.5+ent FEATURES: AI Agent Support (Beta/Enterprise) : Adds beta support for first-class AI agents. Adds an Agent Registry to register agents, and adds support for using Vault as an OAuth resource server for registered agent entities. When configured, allows OAuth 2.0 JWTs to be used to directly authorize requests to Vault, without needing a Vault token. IMPROVEMENTS: consumption-billing: Add a new sys/billing/config endpoint to allow configuration of billing data retention (min 13 months, max 6 years). core (Enterprise): Make deadlock detection in sealwrap configurable by adding "sealwrap" to existing configuration detect_deadlocks. identity/scim (enterprise): Update PATCH operations on scim/v2/Users to allow multiple modifications in the same patch call, support for patch operations on user metadata and name in addition to active status, and allow specifying path value in patch operations sdk/helper/keysutil: The lock manager's GetPolicy function now always returns a locked Policy, even when caching is enabled. The PolicyRequest struct has a new field to indicate whether the caller requires a write lock on the policy. ui (enterprise): Migrate charts from Lineal to Carbon Charts in the Client usage overview and Vault usage dashboard. BUG FIXES: core/rotationMgr: Fix storage routing for local mounts in namespaces to prevent metadata replication and ensure GDPR compliance. kmip (enterprise): Fix a bug that prevents the legacy CA from working on a named listener. secret-sync (enterprise): Fix GCP Secret Manager replication policy persistence across Vault restarts. secrets/database/mssql: Deregister stale TLS configurations when MySQL connection TLS settings change or the connection is closed, preventing retained certificate pools from accumulating. secrets/pki: Fix PKI certificate issuance not_after time to respect max TTL. secrets/transit: Add managed key support to Transit rewrap endpoint. storage/raft: reject performance_multiplier values less than or equal to zero

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.2.8

RabbitMQ 4.2.8

RabbitMQ 4.2.8 is a maintenance release in the 4.2.x release series . It is strongly recommended that you read 4.2.0 release notes in detail if upgrading from a version prior to 4.2.0 . Minimum Supported Erlang Version RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Users created without a password or a password hash (for example, those that rely on X.509 certificate-based authentication) over the HTTP API are now stored correctly, exactly like the users whose password was cleared with rabbitmqctl clear_password . GitHub issues: #16629 , #16633 Consumer activity status of classic queue consumers was not always correctly updated and reported when single active consumer was enabled. GitHub issues: #16532 , #16450 Default queue type (DQT) validation now treats empty strings the same way as a missing value: by falling back to the default (classic queues). GitHub issues: #16481 , #16488 Enhancements The per-node channel limit ( channel_max_per_node ) is now also enforced for channels opened on direct Erlang client connections used by the Shovel and Federation plugins, matching the behavior enforced for "regular" AMQP 0-9-1 clients. GitHub issues: #16616 , #16618 Modules are now loaded in parallel early on node boot, reducing node startup time. GitHub issue: #16479 Several new rabbitmq.conf keys now support encrypted values . GitHub issue: #16632 CLI Tools Bug Fixes rabbitmqctl add_vhost now validates the provided default queue type value. GitHub issue: #16481 Stream Plugin Bug Fixes Fixed a frame assembly performance regression in the stream protocol reader. GitHub issue: #16588 Enhancements Several stream protocol reader optimizations: stream metadata queries now contact cluster nodes concurrently, subscription lookups use a more efficient data structure, and frame processing short-circuits when a connection reaches a terminal state. GitHub issue: #16588 Management Plugin Bug Fixes CORS hardening: access-control-request-headers values are now validated and a wildcard ( * ) origin header value is rejected. GitHub issue: #16544 Definitions import now limits the size of multipart upload bodies, and definitions export download filenames are restricted to a safe character set. GitHub issue: #16544 HTTP API 500 responses no longer include internal error details in the response body. GitHub issue: #16544 Several HTTP response headers are now consistently lowercase, and a previously missing content-type header was added to certain responses. GitHub issue: #16544 Enhancements A one-time warning is now logged when the HSTS or CSP headers are disabled. GitHub issue: #16544 The timestamp of the oldest message in a stream is now displayed on the stream page. GitHub issue: #15412 Prometheus Plugin Enhancements More plugin configuration keys, such as prometheus.ssl.password , now support encrypted values in rabbitmq.conf . GitHub issues: #16516 , #16521 MQTT Plugin Bug Fixes mqtt.tcp_listen_options.* settings in rabbitmq.conf did not take effect due to a configuration translation issue. GitHub issue: #16529 Dependency Changes cuttlefish was upgraded to 3.9.1 cowboy was upgraded to 2.16.0 cowlib was upgraded to 2.17.0 gun was upgraded to 2.4.0

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.2

RabbitMQ 4.3.2

RabbitMQ 4.3.2 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Enabling the tie_binding_to_dest_with_keep_while_cond feature flag could fail in some rare cases. GitHub issue: #16587 Users created without a password or a password hash (for example, those that rely on X.509 certificate-based authentication) over the HTTP API are now stored correctly, exactly like the users whose password was cleared with rabbitmqctl clear_password . GitHub issues: #16629 , #16633 Consumer activity status of classic queue consumers was not always correctly updated and reported when single active consumer was enabled. GitHub issues: #16532 , #16450 The values of the x-consumer-timeout and x-consumer-disconnected-timeout optional arguments are now validated at queue declaration time. GitHub issue: #16557 Default queue type (DQT) validation now treats empty strings the same way as a missing value: by falling back. to the default (classic queues). GitHub issues: #16481 , #16488 Feature flag operations now avoid unnecessary work: flags that are already enabled on all cluster nodes are excluded from synchronization, and enabling an empty set of flags is a no-op. GitHub issue: #16497 Configuration changes for deprecated features are now honored when possible. GitHub issue: #16500 Enhancements The per-node channel limit ( channel_max_per_node ) is now also enforced for channels opened on direct Erlang client connections used by the Shovel and Federation plugins, matching the behavior enforced for "regular" AMQP 0-9-1 clients. GitHub issues: #16616 , #16618 Modules are now loaded in parallel early on node boot, reducing node startup time. GitHub issue: #16479 Several new rabbitmq.conf keys now supports encrypted values . GitHub issue: #16632 CLI Tools Bug Fixes rabbitmqctl set_topic_permissions now validates target user and exchange for existence. GitHub issue: #16590 rabbitmqctl add_vhost now validates the provided default queue type value. GitHub issue: #16481 Stream Plugin Bug Fixes Fixed a frame assembly performance regression in the stream protocol reader. GitHub issue: #16588 Enhancements Several stream protocol reader optimizations: stream metadata queries now contact cluster nodes concurrently, subscription lookups use a more efficient data structure, and frame processing short-circuits when a connection reaches a terminal state. GitHub issue: #16588 Management Plugin Bug Fixes CORS hardening: access-control-request-headers values are now validated and a wildcard ( * ) origin header value is rejected. GitHub issue: #16544 Definitions import now limits the size of multipart upload bodies, and definitions export download filenames are restricted to a safe character set. GitHub issue: #16544 HTTP API 500 responses no longer include internal error details in the response body. GitHub issue: #16544 Several HTTP response headers are now consistently lowercase, and a previously missing content-type header was added to certain responses. GitHub issue: #16544 Enhancements A one-time warning is now logged when the HSTS or CSP headers are disabled. GitHub issue: #16544 The timestamp of the oldest message in a stream is now displayed on the stream page. GitHub issue: #15412 The queue list page can now display a "Delayed" message count column, for example, for quorum queues that have a retry policy configured. GitHub issue: #16639 Prometheus Plugin Enhancements More plugin configuration keys, such as prometheus.ssl.password , now support encrypted values in rabbitmq.conf . GitHub issues: #16516 , #16521 MQTT Plugin Bug Fixes mqtt.tcp_l

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSALERTMANAGER-0.33.0

0.33.0 / 2026-06-12

[CHANGE] The '--enable-feature=auto-gomaxprocs' option has been removed. This flag had no effect since v0.29 and was deprecated in v0.32. It can be safely removed from any startup scripts. #5090 , #5251 [CHANGE] Add group-key-in-metrics feature flag. #5047 [CHANGE] Move AlertMarker , GroupMarker to marker package. #5047 [CHANGE] Remove alertmanager_marked_alerts . #5047 [CHANGE] Remove the following from types package: MemMarker , AlertState* , AlertStatus . #5047 [FEATURE] Introduce per aggregation group AlertMarkers and drop Global Alert Marker. #5047 [FEATURE] ui: Add support for silence annotations. #5017 [FEATURE] api: Add receiver labels and receiver_matchers filter to /api/v2/receivers , /api/v2/alerts , and /api/v2/alerts/groups . #5152 [FEATURE] eventrecorder: Add structured event recorder behind --enable-feature=event-recorder , with file, webhook, and kafka outputs. #5072 , #5246 [ENHANCEMENT] Add the use_aws_http_client config option to the sns notifier. #5178 [ENHANCEMENT] template: Add now function to get current time. #5188 [ENHANCEMENT] docs: Clarify YAML quoting vs matcher token quoting in UTF-8 matchers section. #5264 [BUGFIX] jira: Allow disabling the resolve transition when resolve_transition is not set. #4821 [BUGFIX] jira: Include unresolved issues in wont_fix_resolution JQL to prevent duplicate issue creation. #5185 [BUGFIX] sns: Support the AWS_CA_BUNDLE env variable for the sns notifier. #5178

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DENODENO-2.8.3

v2.8.3

2.8.3 / 2026.06.11 feat(cli): suggest DENO_TLS_CA_STORE on untrusted TLS certificate ( #34756 ) feat(cli): support --env-file in dependency and registry subcommands ( #34843 ) feat(compile): support watch mode ( #34860 ) feat(config): support globs in links ( #34849 ) feat(ext/crypto): implement SubtleCrypto.supports() static method ( #34903 ) feat(ext/crypto): support ML-DSA JWK import/export ( #34914 ) feat(ext/fetch): support priority in RequestInit ( #34716 ) feat(ext/node): auto-instrument node:http2 with OpenTelemetry ( #34510 ) feat(ext/node): notify control socket when node:http server starts serving ( #34949 ) feat(ext/telemetry): honor OTEL_SPAN_ATTRIBUTE_COUNT_LIMIT ( #34787 ) feat(ext/telemetry): honor OTEL_SPAN_EVENT_COUNT_LIMIT ( #34795 ) feat(ext/telemetry): support OTEL_TRACES_SAMPLER ( #34764 ) feat(fmt): add JSON trailing comma config ( #33383 ) feat(info): add localPath to npm packages in deno info --json ( #34806 ) feat(info): support --minimum-dependency-age flag ( #34762 ) feat(lsp): add "Debug" code lens for test steps ( #34742 ) feat(lsp): add Deno.test ignore and only code actions ( #34861 ) feat(lsp): diagnose import map files ( #34864 ) feat(lsp): provide hover info for import map resolutions ( #34854 ) feat(lsp): report deno doc --lint diagnostics ( #34733 ) feat(lsp): show no-slow-types diagnostics for JSR packages ( #34740 ) feat(outdated): warn about packages skipped due to registry errors ( #34974 ) feat(test): forward shebang permissions into deno test --doc ( #35052 ) feat(workspace): auto-discover external deno.json import maps ( #34803 ) feat(x): add deno x --ignore-scripts ( #34952 ) feat: bump-version -c to handle deno.json + package.json in same dir ( #34770 ) fix(add): accept npm version ranges on the command line ( #34799 ) fix(bundle): apply node-style CJS interop on all platforms ( #34939 ) fix(bundle): don't panic when esbuild binary is busy or unavailable ( #34845 ) fix(bundle): instantiate .wasm imports instead of emitting raw bytes ( #34923 ) fix(bundle): rename sourcemap for HTML entrypoints ( #34901 ) fix(bundle): respect --check and run the type checker ( #33514 ) fix(cache): retry locked cache database instead of deleting it ( #34873 ) fix(check): honor ts suppressions for unresolved imports ( #34163 ) fix(check): ignore doc comment dynamic imports ( #34888 ) fix(check): surface unresolved imports in .d.ts entrypoints ( #34168 ) fix(check): treat .d.ts in ESM-supporting npm packages as ESM ( #34613 ) fix(clean): keep cleaning when cache files are locked and report holders ( #34946 ) fix(clean): support deno clean --dry-run without --except ( #34846 ) fix(cli): accept allow-import for deno add ( #35019 ) fix(cli): check worker's own permissions for dynamic asset imports ( #34707 ) fix(cli): collect re-exported names for deno test --doc injection ( #33511 ) fix(cli): don't let --env-file set Deno's own runtime control vars ( #35032 ) fix(cli): don't suggest non-existent subcommand-flag combinations ( #34810 ) fix(cli): generate type-only doc-test imports under verbatimModuleSyntax ( #33508 ) fix(cli): include the typed name in unrecognized subcommand error ( #34882 ) fix(cli): strip trailing CR from args so CRLF shebangs work ( #34968 ) fix(compile): prune managed npm snapshot to graph-reachable packages ( #34741 ) fix(compile): resolve bare npm imports in --bundle worker sources ( #34967 ) fix(compile): run forked child's module instead of entrypoint ( #34687 ) fix(compile): support fs.fstatSync on vfs ( #34892 ) fix(console): %c colors with same red component as previous color ( #34784 ) fix(core): don't set ERR_MODULE_NOT_FOUND code on module linking errors ( #34800 ) fix(core): externalize lazy loaded sources ( #34936 ) fix(core): silence too_many_arguments on Callable trait method ( #33475 ) fix(core): use isolate_unchecked accessors for fast &v8::Isolate args ( #33474 ) fix(coverage): exclude linked/patched packages from coverage report ( #34834 ) fix(coverage): improve HT

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-3.5.15

v3.5.15

🐞 Bug Fixes Artemis auto-configuration uses a predictable default location for the embedded broker's data #50743 MailSender auto-configuration does not enable hostname verification #50742 SSL should not be enabled when a SSL bundle is overridden to an empty string #50624 Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50501 Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50451 RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50429 GraphQL WebSocket support does not configure allowed origins #50391 Buildpack module does not validate long-to-int casts #50382 MappingsEndpoint reports the context's own ID as parentId when a parent exists #50373 Created StackTracePrinter instances have no access to the Environment #50303 NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50301 Spring Boot Loader Does Not Support RSA and EC Signed Jars #50292 ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50273 Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50254 Meter registries are not removed from the global registry when the context is closed #50235 ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50225 Apply HTML escaping to timestamp attribute in Whitelabel error page #50205 NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50118 EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50095 📔 Documentation Fix reference to Gradle documentation for module replacement #50641 Remove the use of Optional from Data Neo4j repository examples #50600 Fix typos in documentation #50593 Document Java 25 requirement for AOT cache #50482 Clarify dependency requirement for Bean Validation support #50290 Document SSL reloading with Let's Encrypt #50222 Polish InvalidConfigurationPropertyValueException constructor javadoc #50212 Document known testcontainers lifecycle issues #50210 Document configuring multiple connectors with Jetty #50206 Fix typo in Spring Security OAuth2 client registration documentation #50193 🔨 Dependency Upgrades Upgrade to Caffeine 3.2.4 #50308 Upgrade to Cassandra Driver 4.19.3 #50670 Upgrade to Glassfish JAXB 4.0.9 #50671 Upgrade to Groovy 4.0.32 #50310 Upgrade to Hibernate 6.6.53.Final #50721 Upgrade to Jackson Bom 2.21.4 #50673 Upgrade to Jakarta Json Bind 3.0.2 #50674 Upgrade to Jakarta XML Bind 4.0.5 #50313 Upgrade to Jaxen 2.0.6 #50722 Upgrade to Jetty 12.0.36 #50676 Upgrade to Jetty Reactive HTTPClient 4.0.14 #50723 Upgrade to jOOQ 3.19.35 #50724 Upgrade to Logback 1.5.34 #50677 Upgrade to Maven Failsafe Plugin 3.5.6 #50678 Upgrade to Maven Surefire Plugin 3.5.6 #50679 Upgrade to Micrometer 1.15.12 #50511 Upgrade to Micrometer Tracing 1.5.12 #50512 Upgrade to Netty 4.1.135.Final #50680 Upgrade to Postgresql 42.7.11 #50317 Upgrade to Pulsar 4.0.11 #50725 Upgrade to R2DBC MySQL 1.4.2 #50319 Upgrade to Reactor Bom 2024.0.18 #50513 Upgrade to SAAJ Impl 3.0.6 #50726 Upgrade to SLF4J 2.0.18 #50533 Upgrade to Spring AMQP 3.2.11 #50514 Upgrade to Spring Authorization Server 1.5.8 #50515 Upgrade to Spring Batch 5.2.6 #50516 Upgrade to Spring Data Bom 2025.0.12 #50517 Upgrade to Spring Framework 6.2.19 #50518 Upgrade to Spring GraphQL 1.4.6 #50739 Upgrade to Spring HATEOAS 2.5.3 #50519 Upgrade to Spring Integration 6.5.9 #50520 Upgrade to Spring Kafka 3.3.16 #50521 Upgrade to Spring LDAP 3.3.8 #50522 Upgrade to Spring Pulsar 1.2.18 #50523 Upgrade to Spring RESTDocs 3.0.6 #50524 Upgrade to Spring Retry 2.0.13 #50525 Upgrade to Spring Security 6.5.11 #50526 Upgrade to Spring Session 3.5.7 #50527 Upgrade to Spring WS 4.1.4 #50528 Upgrade t

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.0.7

v4.0.7

🐞 Bug Fixes MailSender auto-configuration does not enable hostname verification #50746 Artemis auto-configuration uses a predictable default location for the embedded broker's data #50744 NullPointerException in reactor-netty SniProvider and unmapped SSL bundle with RSocket #50640 SSL should not be enabled when a SSL bundle is overridden to an empty string #50634 Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50617 RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50611 NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50609 Test auto-configuration no longer integrates Spring Security with HtmlUnitDriver #50602 Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50509 ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50416 Created StackTracePrinter instances have no access to the Environment #50413 MappingsEndpoint reports the context's own ID as parentId when a parent exists #50411 Buildpack module does not validate long-to-int casts #50409 GraphQL WebSocket support does not configure allowed origins #50393 Configuration property metadata includes incorrect class references #50375 Spring Boot Loader Does Not Support RSA and EC Signed Jars #50297 Meter registries are not removed from the global registry when the context is closed #50286 Nullable annotations from AbstractErrorController.getErrorAttributes are not aligned with implementation #50265 EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50260 Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50257 ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50233 NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50227 Apply HTML escaping to timestamp attribute in Whitelabel error page #50215 Setting server.servlet.session.cookie.partitioned=true has no effect when using Tomcat #50201 📔 Documentation Fix reference to Gradle documentation for module replacement #50646 Document SSL reloading with Let's Encrypt #50629 Remove the use of Optional from Data Neo4j repository examples #50621 Fix typos in documentation #50619 Clarify dependency requirement for Bean Validation support #50613 Document Java 25 requirement for AOT cache #50484 Add links for Java CAS Client Spring Boot Starter #50281 Document known testcontainers lifecycle issues #50219 Document adding multiple connectors for Jetty #50217 Polish InvalidConfigurationPropertyValueException constructor javadoc #50213 Fix typo in Spring Security OAuth2 client registration documentation #50198 🔨 Dependency Upgrades Upgrade to Caffeine 3.2.4 #50322 Upgrade to Cassandra Driver 4.19.3 #50681 Upgrade to Glassfish JAXB 4.0.9 #50682 Upgrade to Groovy 5.0.6 #50324 Upgrade to Hibernate 7.2.19.Final #50733 Upgrade to Jackson 2 Bom 2.21.4 #50684 Upgrade to Jackson Bom 3.1.4 #50685 Upgrade to Jakarta Json Bind 3.0.2 #50686 Upgrade to Jakarta XML Bind 4.0.5 #50328 Upgrade to Jaxen 2.0.6 #50717 Upgrade to Jetty 12.1.10 #50688 Upgrade to Jetty Reactive HTTPClient 4.1.5 #50718 Upgrade to jOOQ 3.19.35 #50719 Upgrade to Liquibase 5.0.3 #50554 Upgrade to Logback 1.5.34 #50689 Upgrade to Maven Enforcer Plugin 3.6.3 #50555 Upgrade to Maven Failsafe Plugin 3.5.6 #50690 Upgrade to Maven Surefire Plugin 3.5.6 #50691 Upgrade to Micrometer 1.16.6 #50535 Upgrade to Micrometer Tracing 1.6.6 #50536 Upgrade to Neo4j Java Driver 6.1.0 #50556 Upgrade to Netty 4.2.15.Final #50692 Upgrade to Postgresql 42.7.11 #50332 Upgrade to R2DBC MySQL 1.4.2 #50333 Upgrade to Reactor Bom 2025.0.6 #50537 Upgrade to SAAJ Impl 3.0.6 #50720 Upgrade to SLF4J 2.0.18 #50558 Upgrade to

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.1.0

v4.1.0

Full release notes for Spring Boot 4.1 are available on the wiki. ⭐ New Features Add public constructor to InvalidConfigurationPropertyValueException that accepts a cause #50211 Reduce memory consumption when repeatedly calling WritableJson.toByteArray #49428 🐞 Bug Fixes MailSender auto-configuration does not enable hostname verification #50747 Artemis auto-configuration uses a predictable default location for the embedded broker's data #50745 Embedded LDAP SSL should not be enabled when its bundle is empty #50700 InetAddressFilter.externalAddresses does not exclude special purpose addresses from RFC 6890 #50668 NullPointerException in reactor-netty SniProvider and unmapped SSL bundle with RSocket #50645 SSL should not be enabled when a SSL bundle is overridden to an empty string #50635 Test auto-configuration no longer integrates Spring Security with HtmlUnitDriver #50633 Configuration property metadata includes incorrect class references #50632 Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50618 RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50612 NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50610 SpringJtaPlatform should have been deprecated since 4.1.0-M3 #50592 Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50510 ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50417 Created StackTracePrinter instances have no access to the Environment #50414 MappingsEndpoint reports the context's own ID as parentId when a parent exists #50412 Buildpack module does not validate long-to-int casts #50410 Gradle gRPC support fails if protobuf-java dependency is used instead of protobuf-java-util #50405 GraphQL WebSocket support does not configure allowed origins #50394 Spring Boot Loader Does Not Support RSA and EC Signed Jars #50298 Meter registries are not removed from the global registry when the context is closed #50287 DataSourceBuilder cannot derive a DataSource from a lazy connection proxy #50271 Nullable annotations from AbstractErrorController.getErrorAttributes are not aligned with implementation #50266 Bean definitions can be added with an initializer before setAllowBeanDefinitionOverriding is called #50264 EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50261 Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50258 ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50234 NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50228 Missing dependency management for spring-boot-web-server-test #50224 Spring Batch support for MongoDB modules are not included in dependency management #50223 Apply HTML escaping to timestamp attribute in Whitelabel error page #50216 GrpcServerHealthScheduler is not started in servlet environments #50209 Setting server.servlet.session.cookie.partitioned=true has no effect when using Tomcat #50204 📔 Documentation Fix reference to Gradle documentation for module replacement #50647 Document SSL reloading with Let's Encrypt #50630 Remove the use of Optional from Data Neo4j repository examples #50622 Fix typos in documentation #50620 Clarify dependency requirement for Bean Validation support #50614 Document Java 25 requirement for AOT cache #50485 Add links for Java CAS Client Spring Boot Starter #50285 Document known testcontainers lifecycle issues #50220 Document adding multiple connectors for Jetty #50218 Polish InvalidConfigurationPropertyValueException constructor javadoc #50214 Fix typo in Spring Security OAuth2 client registration documentation #50199 🔨 Dependency Upgrades Upgrade to ActiveMQ

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-066C142821A1384B

Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00

Published 9 Jun 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-A8AC2B01FECBA6FF

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

Published 9 Jun 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-DEDFA211C00C8A90

Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

Published 9 Jun 2026 · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-1.10.13

v1.10.13 (Enterprise)

SECURITY: cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [ GH-28063 ] IMPROVEMENTS: build: Updated Go to 1.26.4 [ GH-28080 ] vault: adds token renewal retries [ GH-27947 ] BUG FIXES: audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [ GH-28025 ] client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [ GH-27960 ] client: fix a bug where we could accidentally overwrite task states [ GH-27944 ] consul: re-write consul service identity token when reattaching to task [ GH-27936 ] job (Enterprise): Renabled use of multiple vault namespaces in a single job plugins: store verified and canonicalised plugin configuration in the agent [ GH-28083 ] template: Fixed a bug where templates with change_mode=noop would stop monitoring templates that fatally fail after initial rendering [ GH-28016 ] ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [ GH-28095 ] ui: Fix service detail page not rendering [ GH-28005 ] ui: Fixed a bug where the evaluation detail panel would render improperly [ GH-27987 ] ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [ GH-28074 ] ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [ GH-28047 ] ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [ GH-28029 ] ui: Fixed the namespace list being continually fetched when on the job overview page [ GH-28074 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-1.11.7

v1.11.7 (Enterprise)

SECURITY: cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [ GH-28063 ] IMPROVEMENTS: build: Updated Go to 1.26.4 [ GH-28080 ] vault: adds token renewal retries [ GH-27947 ] BUG FIXES: audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [ GH-28025 ] client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [ GH-27960 ] client: fix a bug where we could accidentally overwrite task states [ GH-27944 ] consul: re-write consul service identity token when reattaching to task [ GH-27936 ] job (Enterprise): Renabled use of multiple vault namespaces in a single job plugins: store verified and canonicalised plugin configuration in the agent [ GH-28083 ] template: Fixed a bug where templates with change_mode=noop would stop monitoring templates that fatally fail after initial rendering [ GH-28016 ] ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [ GH-28095 ] ui: Fix service detail page not rendering [ GH-28005 ] ui: Fixed a bug where the evaluation detail panel would render improperly [ GH-27987 ] ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [ GH-28074 ] ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [ GH-28047 ] ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [ GH-28029 ] ui: Fixed the namespace list being continually fetched when on the job overview page [ GH-28074 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-2.0.3

v2.0.3

FEATURES: core: timeouts for batch jobs [ GH-27803 ] SECURITY: cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [ GH-28063 ] IMPROVEMENTS: acl: Support uploading client ACL tokens [ GH-27741 ] alloc: don't restore when allocDir is inaccessible [ GH-27933 ] api: added agent reload endpoint [ GH-27106 ] build: Updated Go to 1.26.4 [ GH-28080 ] client: Adds default_ineligible configuration option [ GH-27965 ] identity: allow additional claims to be added to workload identities [ GH-27786 ] vault: adds token renewal retries [ GH-27947 ] BUG FIXES: audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [ GH-28025 ] cli: Fixed job dispatch and job periodic force failing with a paginator error against servers older than the CLI [ GH-27680 ] client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [ GH-27960 ] consul: re-write consul service identity token when reattaching to task [ GH-27936 ] job (Enterprise): Renabled use of multiple vault namespaces in a single job plugins: store verified and canonicalised plugin configuration in the agent [ GH-28083 ] template: Fixed a bug where templates with change_mode=noop would stop monitoring templates that fatally fail after initial rendering [ GH-28016 ] ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [ GH-28095 ] ui: Fix service detail page not rendering [ GH-28005 ] ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [ GH-28074 ] ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [ GH-28047 ] ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [ GH-28029 ] ui: Fixed the namespace list being continually fetched when on the job overview page [ GH-28074 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENSEARCHOPENSEARCH-3.7.0

3.7.0

Version 3.7.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.7.0 Features Add dynamic properties support for pattern-based field definitions without cluster state mapping updates ( #20816 ) Add pluggable data format engine with DataFormatAwareEngine for multi-format indexing ( #21181 ) Add Lucene engine implementation for pluggable data formats ( #21299 ) Add merge support for Parquet data format plugin via streaming k-way merge sort ( #21079 ) Add directory and IndexInput layers for WritableWarm tiered storage ( #21178 ) Add server-side implementation for tiering status APIs (GetTieringStatus and ListTieringStatus) ( #21220 ) Add server-side implementation for HotToWarm, WarmToHot, and CancelTiering APIs ( #21295 ) Add prefetch settings and stored fields prefetch for WritableWarm tiered storage ( #21285 ) Add slow logs, per-query metrics, and migration metrics for WritableWarm tiered storage ( #21332 ) Add module wiring and integration tests for WritableWarm tiered storage ( #21427 ) Add tiered object storage crate for warm node file routing ( #21204 ) Add event-driven scheduler and stage execution for analytics engine ( #21242 ) Add coordinator-side DataFusion reduce with streaming Arrow batches ( #21356 ) Add distributed aggregation with partial/final mode for analytics engine ( #21457 ) Add distributed join planning and execution for analytics engine ( #21639 ) Add PPL append command support with multi-child stage runtime for Union ( #21474 ) Add PPL dedup command support via ROW_NUMBER window function ( #21622 ) Add PPL eventstats and streamstats window function support ( #21734 ) Add PPL top and rare command support via window functions ( #21593 ) Add PPL parse command with regex mode via Rust UDFs ( #21573 ) Add PPL rex command with sed and extract modes ( #21550 ) Add PPL spath command with auto-extract mode via json_extract_all UDF ( #21664 ) Add 7 PPL JSON scalar functions to analytics engine route ( #21513 ) Add 23 PPL datetime scalar functions to analytics engine route ( #21556 ) Add 14 additional PPL datetime functions (Wave A) including strftime, date_format, maketime ( #21582 ) Add 30+ PPL math scalar functions to analytics engine ( #21520 ) Add PPL string scalar functions to analytics engine (18 functions) ( #21543 ) Add PPL conditional functions (coalesce, isempty, isblank, case, if, ifnull) to analytics engine ( #21643 ) Add PPL conversion scalar functions (num, auto, memk, rmcomma, dur2sec, ctime, mktime) to analytics engine ( #21628 ) Add PPL cryptographic functions (md5, sha1, sha2, crc32) to analytics engine ( #21611 ) Add PPL array constructor and 8 multivalue functions to analytics engine ( #21554 ) Add PPL bucketing scalars (span_bucket, width_bucket, minspan_bucket, range_bucket) ( #21621 ) Add PPL TAKE, FIRST, LAST, LIST, VALUES aggregate functions ( #21731 ) Add Lucene filter delegation from DataFusion for full-text search predicates ( #21555 ) Add performance delegation to Lucene for selective filter predicates ( #21701 ) Add native Arrow transport path with zero-copy transfer for stream transport ( #21253 ) Stream Arrow batches on data-node fragment execution path ( #21418 ) Add support for extra_fields outside _source indexing for improved vector ingestion throughput ( #20635 ) Add gRPC support for Min, Max, and Terms aggregations ( #21205 ) Add partition strategy setting for flexible shard-to-partition mapping in pull-based ingestion ( #21165 ) Add SplitToFieldsProcessor for distributing split values to target fields ( #21216 ) Add native memory based admission control for transport request throttling ( #21191 ) Add native memory search backpressure for off-heap query cancellation ( #21647 ) Add unified native allocator framework for Arrow allocations with elastic rebalancing ( #21703 ) Add on-demand jemalloc heap profiling support via JMX CLI tool ( #21599 ) Add search.max_buckets to workload group settings for per-tenant bucket limits ( #21721 ) Add additional sea

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-6.2.19

v6.2.19

⚠️ Security Fixes This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs: CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module" CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux" CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux" CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux" CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux" CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux" CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux" CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils" CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags" CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher" CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions" CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL" CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions" CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux" CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder" CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters" ⭐ New Features Avoid too many character access attempts in AntPathMatcher #36886 Track operations during SpEL expression evaluation #36887 Ensure getters have non-void return types in SpEL #36888 Expose ClassLoader from DefaultDeserializer #36839 Refine default view name resolution #36794 Refine Jackson JMS converters #36792 Improve ABNF rule checks in RfcUriParser #36788 Detect custom deserialized NullValue instances in AbstractValueAdaptingCache #36728 Warn against unsafe static resource locations in MVC and WebFlux #36693 Consistent compatibility with Woodstox as an alternative to Xerces #36683 🐞 Bug Fixes Data is lost for joined DataBuffer in DataBufferUtils #36874 CronExpression skips days on midnight DST gap #36873 Concurrency issue against shared cookie field in CookieLocaleResolver#setLocaleContext #36870 Server Sent Event does not support multi-line comments #36867 Regression in 6.2.0+: ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36849 Bean Background Bootstrap and Lazy Init #36847 Fix JSP tag processing #36798 Fix script processing capabilities #36796 Parsing failure for MIME type with quoted parameter values #36734 Circular dependency between supplier-created beans is silently ignored on startup #36732 Non-deterministic "Body token not expected" in org.springframework.http.codec.multipart.PartGenerator #36722 Regression on value class parameter handling #36720 Cache collisions in CachingResourceResolver #36718 Unexpected path element removal when resolving versioned resources #36699 📔 Documentation Fix broken links to Selenium documentation #36877 Fix applicability note on setAutoGrowCollectionLimit #36864 Javadoc of nestingLevel parameter in MethodParameter constructor is inconsistent with actual implementation #36848 🔨 Dependency Upgrades Upgrade to JUnit 5.14.4 #36707 Upgrade to Micrometer 1.15.12 #36881 Upgrade to Reactor 2024.0.18 #36882

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-7.0.8

v7.0.8

⚠️ Security Fixes This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs: CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module" CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux" CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux" CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux" CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux" CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux" CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux" CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils" CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags" CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher" CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions" CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL" CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions" CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux" CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder" CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters" ⭐ New Features Include zone ID in CronTrigger's equals/hashCode implementations #36871 Expose ClassLoader from DefaultDeserializer #36833 Use immutable map for SEPARATORS static field in DefaultPathContainer #36821 Track operations during SpEL expression evaluation #36801 Ensure getters have non-void return types in SpEL #36800 Avoid too many character access attempts in AntPathMatcher #36799 Refine default view name resolution #36793 Refine Jackson JMS converters #36791 Improve ABNF rule checks in RfcUriParser #36787 Restrict SpringVersion.getVersion() to "major.minor.patch" format #36785 Runtime compatibility with JPA 4.0 M4 and corresponding Hibernate 8.0 snapshots #36784 Allow specifying the charset to use in ExchangeFilterFunctions#basicAuthentication #36777 Use CollectionUtils to initialize HashMap in DefaultUriBuilderFactory #36763 Improve error messages in SpEL #36756 Improve pattern caching in SpEL #36755 Avoid ResolvableType#forType contention for implicit cache cleanup #36745 Switch to JdkIdGenerator for WebSocket Sessions #36740 Detect custom deserialized NullValue instances in AbstractValueAdaptingCache #36727 LiteWebJarsResourceResolver does not resolve directories #36726 Warn against unsafe static resource locations in MVC and WebFlux #36692 Consistent compatibility with Woodstox as an alternative to Xerces #36682 Improve principal checks for SockJS session #36681 Set host header consistently in STOMP relay CONNECT frames #36673 Support Micrometer context propagation in Kotlin Flow #36667 Reliable detection of broadcast messages in UserDestinationMessageHandler #36662 🐞 Bug Fixes Concurrency issue against shared cookie field in CookieLocaleResolver#setLocaleContext #36869 Server Sent Event does not support multi-line comments #36866 CronExpression skips days on midnight DST gap #36865 Regression in 6.2.0+: ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36835 Preserve generic type info in awaitEntity() #36834 Bean Background Bootstrap and Lazy Init #36844 Back-off for DefaultMessageListenerContainer with OracleAQ has changed and is very short in SpringBoot 4 #36809 Character outside of permitted range in Content Disposition #36805 Fix JSP tag processing #36797 Fix script processing capabilities #36795 Jaxb2XmlEncoder exclusivity prevents JacksonXmlEncoder usage and hinders POJO serialization #36776 Jac

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CADDYCADDY-2.11.4

v2.11.4

This release patches more security, security-adjacent, and normal bugs. The FrankenPHP project has collaborated on PHP-adjacent patches, which we are grateful for. The recent surge of patches is mostly attributed to token predictors. We have had to reject more than 75% of "security" reports because they were AI slop spam (or just lazy/incorrect). Please use LLMs and agents wisely to avoid wasting precious maintainer resources. We have started blocking offending accounts that spam slop reports. Thank you to all who submit responsible reports following our security policy to make the project better. We appreciate that the community deems the Caddy project worthy of contribution to improve the broader ecosystem! Security-related patches: caddyhttp: Normalize Windows backslashes in path matcher (thanks @Vincent550102 ) rewrite: Prevent placeholder re-expansion in injected query (thanks @WhiskerEnt ) templates: Improved stripHTML action to more reliably remove malformed HTML (thanks to @jmrcsnchz ) caddyhttp: Ignore header fields with underscores to prevent collisions (thanks @Vincent550102 for the report and @dunglas for the patch) ⚠️ These security patches may be breaking if your application relies on the buggy behaviors. There are also several other various fixes and enhancements by many other contributors. Thank you everyone who participated! What's Changed reverseproxy: further prevent body closes from dial errors by @jameshartig in #7715 caddytls: Fix client auth (fix #7724 ) by @mholt in #7727 chore: deps upgrade by @mohammed90 in #7751 caddyhttp: omit Last-Modified for unusable mod times by @bb4242 in #7740 caddytls: fix TLS state races and ECH rotation retry by @broady in #7756 chore: clean up wording and typo fixes by @steadytao in #7745 reverseproxy: Add regression test for DialInfo network override by @eyupcanakman in #7758 caddyauth: add candidate placeholders for rejected identities by @steadytao in #7698 cmd: support caddy start on IPv6-only hosts by @steadytao in #7744 caddyfile: preserve implicit TLS issuer semantics by @steadytao in #7743 reverseproxy: wraps request body to prevent closing if not read by @WeidiDeng in #7719 caddytls: match IDN SNI in connection policies by @steadytao in #7742 build(deps): bump the all-updates group across 1 directory with 9 updates by @dependabot [bot] in #7752 caddyhttp: normalize Windows backslashes in path matcher by @Vincent550102 in #7763 go.mod: update x/net by @steadytao in #7767 rewrite: prevent placeholder re-expansion in injected query by @WhiskerEnt in #7761 perf(replacer): optimize memory allocation for file placeholders by @Jualhosting in #7773 caddytls: skip idna.ToASCII for pure ASCII SNI values by @sleet0922 in #7770 encode: prioritize zstd and br over gzip in content negotiation by @Jualhosting in #7772 httpcaddyfile: fix incorrect error message on duplicate matchers by @Brunotlps in #7780 Patch for GHSA-vcc4-2c75-vc9v by @jmrcsnchz in #7785 New Contributors @jameshartig made their first contribution in #7715 @bb4242 made their first contribution in #7740 @broady made their first contribution in #7756 @eyupcanakman made their first contribution in #7758 @Vincent550102 made their first contribution in #7763 @WhiskerEnt made their first contribution in #7761 @Jualhosting made their first contribution in #7773 @sleet0922 made their first contribution in #7770 @Brunotlps made their first contribution in #7780 @jmrcsnchz made their first contribution in #7785 Full Changelog : v2.11.3...v2.11.4

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RUST FOUNDATIONRUST-1.96.0

Rust 1.96.0

Language Allow passing expr metavariable to cfg Always coerce never types in tuple expressions Avoid incorrect inference guidance of function arguments in rare cases Support s390x vector registers in inline assembly Allow using constants of type ManuallyDrop as patterns (fixing a regression introduced in 1.94.0) Compiler Enable link relaxation feature for LoongArch Linux targets Update riscv64gc-unknown-fuchsia baseline to RVA22 + vector Libraries Support iterating over ranges of NonZero integers refactor 'valid for read/write' definition: exclude null; add that as an exception on individual methods instead Fix SGX delayed host lookup via ToSocketAddr Stabilized APIs assert_matches! debug_assert_matches! From<T> for AssertUnwindSafe<T> From<T> for LazyCell<T, F> From<T> for LazyLock<T, F> core::range::RangeToInclusive core::range::RangeToInclusiveIter core::range::RangeFrom core::range::RangeFromIter core::range::Range core::range::RangeIter Cargo Allow a dependency to specify both a git repository and an alternate registry. Just like with crates.io, the git repository will be used locally, but the registry version will be used when published. Added target.'cfg(..)'.rustdocflags support in configuration. Fixed CVE-2026-5222 and CVE-2026-5223 . Rustdoc Deprecation notes are now rendered like any other documentation . Previously they used the css white-space: pre-wrap; property and stripped any <p> elements from the rendered html, however this caused issues and unintuitive behavior. The new behavior should be more predictable, however some multi-line deprecation notes will now be rendered as as single lines. If this is undesirable, you can use the standard markdown method of forcing a linebreak, which is two spaces followed by a newline ( "\n" ). Don't emit rustdoc missing_doc_code_examples lint on impl items Separate methods and associated functions in sidebar Compatibility Notes Fix layout of #[repr(Int)] enums in some edge cases involving fields of uninhabited zero-sized types Prevent unsize-coercing into Pin<Foo> where Foo doesn't implement Deref . Some such coercions were previously allowed, but produce a type with no useful public API. rustc: Stop passing --allow-undefined on wasm targets Gate the accidentally stabilized #![reexport_test_harness_main] attribute Error on return-position-impl-trait-in-traits whose types are too private Report the uninhabited_static lint in dependencies and make it deny-by-default Distributed builds now contain non-split debuginfo for windows-gnu This appears to improve the quality of backtraces. This change has no effect on the defaults for the output of rustc/cargo on these targets. Check const generic arguments are correctly typed in more positions Remove -Csoft-float Importing structs with ::{self [as name]} , e.g., struct S {}; use S::{self as Other}; , is now no longer permitted because {self} imports require a module parent. For export_name , link_name , and link_section attributes, if multiple of the same attribute is present, the first one now takes precedence. Update the minimum external LLVM to 21 On avr targets, C's double type is 32-bit by default, so change c_double to f32 on avr targets to match . This is a breaking change, but necessary to make c_double match C's double. BTreeMap::append() was optimized, which may now cause panics for types with incorrect Ord impls Internal Changes These changes do not affect any public interfaces of Rust, but they represent significant improvements to the performance or internals of rustc and related tools. JSON targets: aarch64 softfloat targets now have to have rustc_abi set to "softfloat" target specs: stricter checks for LLVM ABI values, and correlate that with cfg(target_abi)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.0.2

v2.0.2

BREAKING CHANGES: containers: Remove cap_ipc_lock capability on vault at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call mlock() to lock memory. Operators should set disable_mlock = true in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety. secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829 CHANGES: core: Bump Go version to 1.26.4 secrets/azure (enterprise): Update plugin to v0.26.4+ent BUG FIXES: plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin. ui/transit: Fix key version dropdown selected state when editing a transit key.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DENODENO-2.8.2

v2.8.2

2.8.2 / 2026.06.03 feat(compile): improve --bundle dependency resolution and add --minify ( #34536 ) feat(compile): scope --bundle npm embed to packages actually reached ( #34532 ) feat(ext/crypto): add ChaCha20-Poly1305, SHAKE, cSHAKE, TurboSHAKE, SHA-3 HMAC ( #34417 ) feat(ext/crypto): add ML-DSA (FIPS 204) post-quantum signatures ( #34448 ) feat(ext/crypto): implement ML-KEM (FIPS 203) post-quantum KEM ( #34447 ) feat(ext/node): env/global proxy support for node:http and node:https ( #34257 ) feat(ext/node): support DENO_SERVE_ADDRESS override in node:http servers ( #34662 ) feat(jupyter): rewrite kernel in JS, drop zeromq/runtimelib deps ( #34083 ) feat(lsp): autocomplete jsr:/npm:/node: in deno.json(c) imports ( #34724 ) feat(publish): unfurl import specifiers in Wasm modules ( #34549 ) feat(task): support --env-file flag ( #34508 ) feat(task): support exclusion groups in task name wildcards ( #34506 ) feat(unstable): add --bundle flag to deno compile ( #34527 ) feat: bump deno_task_shell to 0.33.0 ( #34642 ) fix(add): handle version tags like @latest in deno add for JSR packages ( #32859 ) fix(add): replace panic with error when deno.json discovery fails ( #34517 ) fix(bundle): skip decorator pass when module has no decorators ( #34489 ) fix(bundle): use node-style CJS interop for the Deno platform ( #34533 ) fix(cache): skip WAL journal mode on WSL-1 ( #34499 ) fix(cache_dir): EnsureCachedStrategy must surface cached redirects ( #34563 ) fix(check): make node:stream/web types alias the globals ( #34606 ) fix(check): resolve npm packages without types when type checking ( #34551 ) fix(cli): suppress bug-report banner on broken pipe print panics ( #34552 ) fix(cli/task): run recursive workspace tasks in parallel ( #34512 ) fix(compile): allow process.chdir() into the VFS ( #34610 ) fix(compile): bundle workers separately under --bundle ( #34531 ) fix(compile): cover CJS-deep imports under --bundle ( #34534 ) fix(compile): create code cache when importing JSON or Wasm modules ( #34614 ) fix(compile): detect svelte-adapter-deno build output ( #34535 ) fix(compile): don't surface graph errors for --include files ( #34568 ) fix(compile): embed workspace package.json files in the VFS ( #34530 ) fix(compile): enable ANSI colors on Windows in compiled binaries ( #34701 ) fix(compile): handle CJS and native addons in --bundle ( #34529 ) fix(compile): respect npm registry sub-paths when flattening node_modules ( #34575 ) fix(compile): support workers loaded from blob URLs ( #34574 ) fix(compile): transpile TypeScript imported at runtime ( #34616 ) fix(config): hook up verbatimModuleSyntax for the emit pipeline ( #34495 ) fix(config): make config auto-discovery skip the same errors on every platform ( #34558 ) fix(config): surface invalid "exports" map in linked/workspace packages ( #34473 ) fix(config): warn instead of erroring when start dir is not a workspace member ( #34458 ) fix(config): warn instead of erroring when workspace member dir is missing ( #34511 ) fix(core): TLA hang on dyn import when async dep triggers lazy ESM load ( #34469 ) fix(core): preserve WebAssembly streaming callback across new contexts ( #34679 ) fix(crypto): correct X448 PKCS#8 handling ( #34578 ) fix(doc): don't lint private-type-ref for cross-package types ( #34339 ) fix(doc): handle non-ASCII doc lint diagnostics ( #34626 ) fix(ext/console): degrade gracefully when getKeys throws ( #24980 ) ( #34464 ) fix(ext/fetch): implement missing Request properties ( #34607 ) fix(ext/fetch): preserve static request body length ( #34546 ) fix(ext/ffi): match V8 stack-arg layout in turbocall trampoline on Apple silicon ( #34561 ) fix(ext/fs): error when copyFile source and destination are the same file ( #34718 ) fix(ext/fs): retry without FILE_FLAG_BACKUP_SEMANTICS on Windows when driver rejects it ( #34686 ) fix(ext/fs): surface non-UTF-8 file names from read_dir ( #34623 ) fix(ext/http): reject Response-like return from respondWith ( #34589 ) fix(ext/http): r

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-D5A44571571C4CD6

Linux Kernel vulnerability Dirty Frag

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().CVE-2026-43500In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec(). Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused. Revised on 2026-06-03 00:00:00

Published 3 Jun 2026 · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPPACKER-1.15.4

v1.15.4

1.15.4 (June 3, 2026) BUG FIXES: builder: update build constraints to support arm architecture on FreeBSD GH-13650 IMPROVEMENTS: hcp: removes Syft binary download/handling from the HCP SBOM provisioner GH-13636 SECURITY: deps: upgraded crypto version GH-13645 deps: upgraded go-git version GH-13645 deps: bump github.com/hashicorp/packer-plugin-sdk to 0.6.9 GH-13640 INTERNAL: build: bump Go to 1.25.10 and refresh dependencies GH-13646 GH-13647 deps: update cloud.google.com/go and aws-sdk-go-v2 related dependencies GH-13610

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
NGINXNGINX-1.30.2

release-1.30.2

nginx-1.30.2 stable version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module ( CVE-2026-9256 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed nginx-1.30.2-RELEASE by @pluknet in #1397 Full Changelog : release-1.30.1...release-1.30.2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
NGINXNGINX-1.31.1

release-1.31.1

nginx-1.31.1 mainline version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module ( CVE-2026-9256 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Fix the set-creation-date.yaml workflow by @ac000 in #1353 Mp4: avoid adding or comparing to null pointer by @arut in #1360 HTTP/2: limit Content-Type and Location response header length by @arut in #1359 Mail error path fixes by @arut in #1358 Rewrite: harden escape flags control by @arut in #1381 Rewrite: fix buffer overflow with overlapping captures by @arut in #1395 nginx-1.31.1-RELEASE by @pluknet in #1396 Full Changelog : release-1.31.0...release-1.31.1

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-2.0.2

v2.0.2

2.0.2 (May 22, 2026) BUG FIXES: acl: fix rpc permission denied error when using node_pool="all" [ GH-27973 ] ui: Fixed a bug where the client detail page would fail to render [ GH-27958 ] ui: Fixed a bug where the topology page would fail to render [ GH-27958 ] ui: Fixed a bug where the evaluation detail panel would render improperly [ GH-27987 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.0.1

v2.0.1

BREAKING CHANGES: containers: set cap_ipc_lock capability on vault at build time. Container runtimes will need to add IPC_LOCK capabilities when running the vault container. SECURITY: api: Update golang.org/x/net to resolve GO-2026-4918" core/identity: reject wildcards in rendered identity templates core: Resolve GHSA-j88v-2chj-qfwx by removing our dependency on github.com/jackc/pgx/v3 and github.com/jackc/pgx/v4 core: Update github.com/Azure/go-ntlmssp to fix security vulnerability v0.1.1. core: Update github.com/apache/thrift to fix security vulnerability GHSA-wf45-q9ch-q8gh core: Update github.com/jackc/pgx/v5 to fix security vulnerability GHSA-j88v-2chj-qfwx . core: Update golang.org/x/net to resolve GO-2026-4918" core: Validate both path and file_path cannot be empty for requests to sys/audit/{path} sdk: Resolve GHSA-j88v-2chj-qfwx by removing our dependency on github.com/jackc/pgx/v3 and github.com/jackc/pgx/v4 sdk: Update github.com/Azure/go-ntlmssp to fix security vulnerability v0.1.1. sdk: Update github.com/jackc/pgx/v5 to fix security vulnerability GHSA-j88v-2chj-qfwx . sdk: Update golang.org/x/net to resolve GO-2026-4918" CHANGES: auth/jwt: Update plugin to v0.26.3 core: Bump Go version to 1.26.3 identity: Require sudo capability to invoke the identity entity merge API endpoint (identity/entity/merge). secrets/azure: Update plugin to v0.26.2+ent secrets/openldap: Update plugin to v0.18.1+ent FEATURES: Billing metrics dashboard: Create a new billing dashboard with responsive layout to display metric data. Secrets Sync UI: Added Workload Identity Federation (WIF) support in the UI for AWS, Azure, and GCP sync destinations IMPROVEMENTS: api: Add start_month and end_month parameters to /sys/billing/overview endpoint to allow querying billing data for specific time ranges. api: Add migration_done_at_epoch to sys/seal-status response. consumption-billing: Add billing tracking for OS Local Account static roles to support consumption-based billing metrics and high-water mark (HWM) tracking. consumption-billing: Added consumption billing metrics for OIDC tokens. consumption-billing: Added consumption billing metrics for PKI External CA certificates. consumption-billing: Added consumption billing metrics for SPIFFE JWT tokens. consumption-billing: Enabled sys/billing/overview endpoint in admin namespace. consumption-billing: Float64 values returned by sys/billing/overview are now rounded to 4 decimal places. consumption-billing: Increased billing data retention from 2 months to 37 months. The /sys/internal/billing/overview API endpoint now returns 37 months of historical consumption billing data by default. consumption-billing: The /sys/internal/billing/overview API endpoint now always returns all metric types in the response, even when their values are zero. This ensures consistent response structure for easier client-side parsing. core (Enterprise): Sanitized config now shows kms_library config. core/seal (enterprise): Make it possible for new nodes to join a cluster configured with Seal High Availability. scim: The SCIM Group PATCH handler now supports the path field in the form members[value eq "id"] on remove operations. sdk: Expand support for docker test cluster options like seals, kms libraries, and entropy augmentation. DockerClusterNode.UpdateConfig now takes a full set of cluster options instead of just node config. sdk: add WIF and rotation helpers for checking if params were updated to allow the consumer to know when changes need to be persisted to storage secrets/pki (enterprise): Allow SCEP to use an issuer that is backed by an RSA based PKCS#11 managed key secrets/transit: Change to using Trail of Bits libraries for PQC signature implementation in Transit ui/dashboard: Reorganized dashboard widgets to improve layout and usability. Updated widgets to use HDS table components for better consistency. Enhanced the Quick Actions card with frequently used links alongside existing actions. ui: Set pagination size to

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.1.4

v5.1.4

What's Changed ✨ Improvements feat: add stop lifecycle hook for external providers by @glours in #13779 🐛 Fixes fix: route OCI artifact pulls through Docker Desktop HTTP proxy by @glours in #13770 fix: restore stoppingEvent/stoppedEvent helpers for plugin stop hook by @glours in #13794 fix(publish): flag literal inline environment values by @glours in #13760 🔧 Internal ci: remove unused e2e job from merge workflow by @glours in #13740 chore: update cagent-action to v1.4.4 by @derekmisler in #13745 Change verb tense in Docker Compose reference documentation by @ryanjbonnell in #13773 pkg/compose: go fix by @thaJeztah in #13782 refactor: code deduplication and simplification by @ndeloof in #13759 fix: make e2e tests pass reliably locally with Docker Desktop by @glours in #13741 refactor: drop Desktop beta-settings check; gate hint on LogsTab flag by @glours in #13755 ⚙️ Dependencies build(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 by @dependabot [bot] in #13731 build(deps): bump github.com/docker/cli from 29.4.0+incompatible to 29.4.2+incompatible by @dependabot [bot] in #13768 build(deps): bump github.com/moby/moby/client from 0.4.0 to 0.4.1 by @dependabot [bot] in #13752 build(deps): bump github.com/docker/cli from 29.4.2+incompatible to 29.4.3+incompatible by @dependabot [bot] in #13776 build(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0 by @dependabot [bot] in #13775 build(deps): update to go 1.26.3 by @thaJeztah in #13783 build(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 by @dependabot [bot] in #13791 build(deps): bump github.com/compose-spec/compose-go/v2 from 2.10.2 to 2.11.0 by @dependabot [bot] in #13798 build(deps): bump github.com/docker/cli from 29.4.3+incompatible to 29.5.1+incompatible by @dependabot [bot] in #13796 build(deps): bump golang.org/x/sys from 0.42.0 to 0.44.0 by @dependabot [bot] in #13788 New Contributors @ryanjbonnell made their first contribution in #13773 Full Changelog : v5.1.3...v5.1.4

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GITEAGITEA-1.26.2

v1.26.2

SECURITY fix(permissions): Fix reading permission ( #37769 ) fix(actions): make artifact signature payloads unambiguous ( #37707 ) fix: Unify public-only token filtering in API queries and repo access checks ( #37118 ) fix: Add missed token scope checking ( #37735 ) fix(oauth): bind token exchanges to the original client request ( #37704 ) fix(oauth): strengthen PKCE validation and refresh token replay protection ( #37706 ) fix(web): enforce token scopes on raw, media, and attachment downloads ( #37698 ) fix(security): enforce wiki git writes and LFS token access at request time ( #37695 ) feat(api): encrypt AWS creds ( #37679 ) fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test fix(packages): Add label for private and internal package and fix composor package source permission check ( #37610 ) fix(git): Fix smart http request scope bug ( #37583 ) Fix basic auth bug ( #37503 ) Fix allow maintainer edit permission check ( #37479 ) ( #37484 ) Fix URL sanitization to handle schemeless credentials ( #37440 ) ( #37471 ) Fix attachment Content-Security-Policy ( #37455 ) ( #37464 ) chore(deps): bump go-git/go-git/v5 to 5.19.0 ( #37608 ) BUGFIXES fix(pull): handle empty pull request files view to allow reviews ( #37783 ) fix(markup): make RenderString never fail ( #37779 ) fix: add natural sort to sortTreeViewNodes ( #37772 ) fix: package creation unique conflict ( #37774 ) fix!: add DEFAULT_TITLE_SOURCE setting for pull request title default behavior ( #37465 ) fix: Allow direct commits for unprotected files with push restrictions ( #37657 ) fix(actions): wrong assumption that run id always >= job id ( #37737 ) fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register ( #37564 ) ( #37588 ) fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState ( #37692 ) fix(repo): /generate must sync the branch table for the new repo ( #37693 ) build: Fix snap build (1.26) fix(actions): run TransferLogs on UpdateLog{Rows:[], NoMore:true} ( #37631 ) fix show correct mergebase fix: make clone URL respect public URL detection setting ( #37615 ) fix: "run as root" check ( #37622 ) chore(deps): update dependency go to v1.26.3 ( #37601 ) Compare dropdown fails when selecting branch with no common merge-base ( #37470 ) fix: treat email addresses case-insensitively ( #37600 ) fix(actions): fix blank lines after ::endgroup:: ( #37597 ) fix(actions): report individual step status in workflow job API response ( #37592 ) fix: Invalid UTF-8 commit messages in JSON API responses ( #37542 ) fix: use consistent GetUser family functions ( #37553 ) fix(api): return 409 message instead of empty JSON for wrong commit id ( #37572 ) fix(actions): prevent panic when workflow contains null jobs ( #37570 ) Make ServeSetHeaders default to download attachment if filename exists ( #37552 ) ( #37555 ) Fix(actions): validate workflow param to prevent 500 error ( #37546 ) ( #37554 ) Don't unblock run-level-concurrency-blocked runs in the resolver ( #37461 ) ( #37538 ) Fix(packages): use file names for generic web downloads ( #37514 ) ( #37520 ) Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once ( #37512 ) ( #37516 ) Fix update branch protection order ( #37508 ) ( #37513 ) Fix mCaptcha broken after Vite migration ( #37492 ) ( #37509 ) Fix review submission from single-commit PR view ( #37475 ) ( #37485 ) Fix scheduled action panic with null event payload ( #37459 ) ( #37466 ) Make GetPossibleUserByID can handle deleted user ( #37430 ) ( #37431 ) Remove excessive quote from terraform instructions ( #37424 ) ( #37426 ) Fix color regressions, add priority color ( #37417 ) ( #37421 ) MISC Add CurrentURL template variable back ( #37444 ) ( #37449 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.2.7

RabbitMQ 4.2.7

RabbitMQ 4.2.7 is a maintenance release in the 4.2.x release series . It is strongly recommended that you read 4.2.0 release notes in detail if upgrading from a version prior to 4.2.0 . Minimum Supported Erlang Version RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes A virtual host could be falsely considered to be deleted in certain metadata store error and timeout scenarios. GitHub issue: #16422 Passive queue and exchange declarations are now allowed for users that have any permission on the virtual host ( configure , write , or read ), not only configure . GitHub issue: #16272 Classic queue message store: garbage collection is now stopped cleanly during node shutdown. GitHub issue: #15498 Fixed a bug where quorum queue's at-least-once dead lettering could direct commands to the wrong member (replica). GitHub issue: #16203 Stream queue argument validation was improved. GitHub issue: #16285 Enhancements channel_max was renamed to max_channels in rabbitmq.conf . The original name is still supported as an alias. GitHub issue: #16347 connection_max was renamed to max_connections in rabbitmq.conf . The original name is still supported as an alias. GitHub issue: #16347 The per-node max_connections limit is now enforced for AMQP 1.0 connections as well as AMQP 0-9-1 ones. GitHub issue: #16300 The permission cache is now traversed less often during AMQP 1.0 management and AMQP 0-9-1 channel checks. GitHub issue: #16274 Stream Plugin Bug Fixes Stream protocol: an open frame with empty properties is now handled correctly. GitHub issue: #16341 Enhancements It is now possible to cap the maximum number of concurrent Stream Protocol client connections using the stream.max_connections configuration key in rabbitmq.conf . GitHub issue: #16341 Management Plugin Bug Fixes HTTP API GET /api/connections could return a 500 response when STOMP connections were present. GitHub issue: #16435 Enhancements It is now possible to cap the maximum number of concurrent HTTP API connections using the management.tcp.max_connections , management.ssl.max_connections configuration keys in rabbitmq.conf . GitHub issue: #16407 The peer (client) certificate serial number is now exposed in the management UI and select CLI commands. GitHub issue: #16463 Prometheus Plugin Enhancements It is now possible to cap the maximum number of concurrent HTTP API connections using the prometheus.tcp.max_connections , prometheus.ssl.max_connections configuration keys in rabbitmq.conf . GitHub issue: #16407 MQTT Plugin Bug Fixes The MQTT connection process no longer fails and logs an exception when keepalive checks encounter socket errors on an already-closed connection. GitHub issue: #16391 Enhancements It is now possible to cap the maximum number of concurrent MQTT client connections using the mqtt.max_connections configuration key in rabbitmq.conf . GitHub issue: #16367 Federation Plugin Bug Fixes Federation links could fail to start during rolling cluster restarts. GitHub issues: #16234 , #16224 LDAP Plugin Enhancements New rabbitmq.conf configuration settings for TLS cipher suites: auth_ldap.ssl_options.ciphers.* . GitHub issue: #16226 HTTP Auth Backend Plugin Enhancements New rabbitmq.conf configuration settings for TLS cipher suites: auth_http.ssl_options.ciphers.* . GitHub issue: #16226 Auth Backend Cache Plugin Bug Fixes The cache was not effective for reconnecting clients. GitHub issues: #16255 , #16258 Trust Store Plugin Bug Fixes A user-provided fail_if_no_peer_cert value in the plugin's TLS options is now respected. Previously, an internal default could override the configured value. GitHub issue: #16201 Enhancements New rabbitmq.conf configuration settings for TLS cipher suites: trust_store.ssl_options.ciphers.* . GitHub issue: #16226 Depende

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.1

RabbitMQ 4.3.1

RabbitMQ 4.3.1 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes If a queue was bound to a topic exchange using an empty binding key ( "" ), messages published to any topic exchange with an empty routing key would be incorrectly routed to that queue. To apply the fix, enable the new topic_binding_projection_v5 feature flag after upgrading all cluster nodes. GitHub issue: #16271 A virtual host could be falsely considered to be deleted in certain metadata store error and timeout scenarios. GitHub issue: #16422 Passive queue and exchange declarations are now allowed for users that have any permission on the virtual host ( configure , write , or read ), not only configure . GitHub issues: #16272 , #16085 Classic queue shared message store GC could fall behind other queue activity under heavy load GitHub issues: #16142 , #16141 Classic queue message store: garbage collection is now stopped cleanly during node shutdown. GitHub issue: #15498 Quorum queues now gracefully handle negative priority values. GitHub issue: #16280 Quorum queues: delayed retry-related policy keys are now accepted in policy definitions. GitHub issues: #16395 , #16398 Fixed a bug where quorum queue's at-least-once dead lettering could direct commands to the wrong member (replica). GitHub issue: #16203 Quorum queues: reintroduced Raft WAL max entries default of 500K. GitHub issue: #16382 A quorum queue could crash during recovery after an unclean shutdown PR: rabbitmq/ra#629 Stream queue argument validation was improved. GitHub issue: #16285 Enhancements channel_max was renamed to max_channels in rabbitmq.conf . The original name is still supported as an alias. GitHub issue: #16347 connection_max was renamed to max_connections in rabbitmq.conf . The original name is still supported as an alias. GitHub issue: #16347 The per-node max_connections limit is now enforced for AMQP 1.0 connections as well as AMQP 0-9-1 ones. GitHub issue: #16300 When a plain-text client connects to a TLS listener (or vice versa) for AMQP 0-9-1, MQTT, STOMP, and the Stream protocol, target node will log a more useful message. GitHub issues: #16342 , #16344 The permission cache is now traversed less often during AMQP 1.0 management and AMQP 0-9-1 channel checks. GitHub issue: #16274 Stream Plugin Bug Fixes Stream protocol: an open frame with empty properties is now handled correctly. GitHub issue: #16341 Enhancements It is now possible to cap the maximum number of concurrent Stream Protocol client connections using the stream.max_connections configuration key in rabbitmq.conf . GitHub issue: #16341 Management Plugin Bug Fixes HTTP API GET /api/connections could return a 500 response when STOMP connections were present. GitHub issue: #16435 Enhancements It is now possible to cap the maximum number of concurrent HTTP API connections using the management.tcp.max_connections , management.ssl.max_connections configuration keys in rabbitmq.conf . GitHub issue: #16407 The peer (client) certificate serial number is now exposed in the management UI and select CLI commands. GitHub issue: #16463 Prometheus Plugin Enhancements It is now possible to cap the maximum number of concurrent HTTP API connections using the prometheus.tcp.max_connections , prometheus.ssl.max_connections configuration keys in rabbitmq.conf . GitHub issue: #16407 MQTT Plugin Bug Fixes The MQTT connection process no longer fails and logs an exception when keepalive checks encounter socket errors on an already-closed connection. GitHub issue: #16391 Enhancements It is now possible to cap the maximum number

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.3.14

Bun v1.3.14

To install Bun v1.3.14 curl -fsSL https://bun.sh/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.sh/install.ps1|iex " To upgrade to Bun v1.3.14: bun upgrade Read Bun v1.3.14's release notes on Bun's blog Thanks to 11 contributors! @190n @alii @carlsmedstad @cirospaciari @coleleavitt @djs5008 @dylan-conway @ig-ant @Jarred-Sumner @robobun @sosukesuzuki

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETCVE-2026-31431

Linux Kernel Vulnerability copy.fail - CVE-2026-31431

CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. Revised on 2026-05-13 00:00:00

Published 13 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
OPENSEARCHOPENSEARCH-2.19.5

2.19.5

Version 2.19.5 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 2.19.5 Bug Fixes Add case sensitivity as an argument to XContentMapValues.filter ( #19976 ) Fix segment replication failure during rolling restart ( #20498 ) Infrastructure Update wrapper github workflow version ( #20748 ) Maintenance Bulk update of HDFS test fixture dependencies ( #20768 ) Bump shadow-gradle-plugin from 8.3.9 to 9.3.1 ( #20569 ) Bump netty from 4.1.125.Final to 4.1.131.Final ( #20744 ) Bump log4j from 2.21.0 to 2.25.3 ( #20308 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CADDYCADDY-2.11.3

v2.11.3

This release improves several aspects of Caddy with minor features, bug fixes, and security patches. Thank you to everyone and their bots who contributed to help make this release the best one yet! Security patches: fastcgi: Carrying over a patch from FrankenPHP for a bug that could allow non-PHP files to be executed; collaborated on by @dunglas , @KC1zs4 , and @chenjj . vars: A more thorough fix for GHSA-m2w3-8f23-hxxf , collaborated by @everping and @vnxme . admin: Array index normalization to prevent remote admin socket auth bypass, by @Amemoyoi and bot. admin: More rigorous path prefix matching to prevent remote admin socket auth bypass, by @Amemoyoi and bot. We've also merged a couple PRs that fix upstream security bugs in other projects like quic-go and CertMagic. Thank you to @marten-seemann for maintaining quic-go so diligently! What's Changed caddyhttp: Sync placeholder expansion in vars and vars_regexp by @vnxme in #7573 caddytls: Avoid ACME fallback for implicit Tailscale *.ts.net policies by @steadytao in #7577 chore: Resolve recent CI failures by @mholt in #7593 caddytls: Consolidate empty APs more smartly by @mholt in #7567 rewrite: skip query rename when source key is absent by @steadytao in #7599 root: introduce down-propagating Helper.BlockState for other directives/plugins to use by @henderkes in #7594 http: make zstd checksum configurable by @ottenhoff in #7586 notify: Always send "READY=1" even after an error by @francislavoie in #7597 reverseproxy: Fix check for header_up Host {upstream_hostport} redundancy by @yubiuser in #7564 caddytls: Expand placeholders in dns_challenge override_domain tls parameter by @pberkel in #7609 tls: add system and combined CA pool modules by @HarshPatel5940 in #7406 vars: Don't expand placeholders in values by @vnxme in #7629 build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from 1.42.0 to 1.43.0 by @dependabot [bot] in #7637 build(deps): bump the all-updates group across 1 directory with 11 updates by @dependabot [bot] in #7641 reverseproxy: make stream copy buffer size configurable by @steadytao in #7627 vars: Add matcher placeholder handling tests by @steadytao in #7640 build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 by @dependabot [bot] in #7621 logging: Add journald encoder wrapper by @steadytao in #7623 caddyfile: Improve import/global options UX for imports before global options by @steadytao in #7642 chore: replace interface{} with any for modernization by @tsinglua in #7571 chore: bump timberjack to v1.4.1 by @DeRuina in #7618 logging: Preserve ts for journald-wrapped JSON logs by @steadytao in #7644 fileserver: show symlink targets verbatim ( #7476 ) by @maxtruxa in #7579 fix(caddyfile): {block} in snippet by @prettysunflower in #7558 caddyhttp: Document missing placeholders for escaped URI and prefixed query by @steffenbusch in #7659 chore: add AGENTS.md by @mohammed90 in #7652 build(deps): bump github.com/jackc/pgx/v5 from 5.8.0 to 5.9.0 by @dependabot [bot] in #7655 admin: Redact sensitive request headers in API logs by @steadytao in #7578 reverseproxy: add lb_retry_match condition on response status by @seroperson in #7569 caddyhttp: prefer port 443 in auto-HTTPS and add tests by @mholt in #7666 fix: Propagate ECH keys to the QUIC listener by @steadytao in #7670 chore: Use atomics where appropriate by @francislavoie in #7648 metrics: Implement pushing via OLTP by @dunglas in #7664 logging: Add regression coverage for rotated file mode by @steadytao in #7620 httpcaddyfile: Inherit global ACME issuer settings in tls shortcuts by @steadytao in #7617 build(deps): bump github.com/jackc/pgx/v5 from 5.9.0 to 5.9.2 by @dependabot [bot] in #7668 admin: require path segment boundary in remote access control by @Amemoyoi in #7673 reverseproxy: Add ability to clear dynamic upstreams cache during retries by @mholt in #7662 listeners: clean up stale Unix socket files on Windows by @mfrischknecht in #7676 admin: reject non-

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-07F7F11F61A68D5E

Improper access control on API endpoints

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-1484AA2015450471

OS command injection in CLI

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-44E83E7C32D8ED03

Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-51E28132BCBC0625

Incorrect global authorization

CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-532B91C042CFCD9C

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-99DB29317DD5A9B4

Out-of-bounds access in CAPWAP daemon

CVSSv3 Score: 8.3 An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-A1186039008D4FE9

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

Published 12 May 2026 · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.0

RabbitMQ 4.3.0

RabbitMQ 4.3.0 is a new feature release. Breaking Changes and Compatibility Notes Mnesia and Parition Handling Strategies are Removed Since only 4.2.x clusters can upgrade to 4.3.0 in place , this won't be a breaking change for nearly all instalations but it will affect community plugins that use Mnesia. All partition handling-related keys in rabbitmq.conf will be accepted by 4.3.0 nodes but won't have any effect: cluster_partition_handling cluster_partition_handling.pause_if_all_down.recover cluster_partition_handling.pause_if_all_down.nodes.$name Team RabbitMQ recommends removing the above keys from rabbitmq.conf before or shortly after upgrading. Deprecated Features are Now Disabled by Default A number of deprecated features are now disabled by default and require the user to opt-in in order to use them. This includes non-durable (transient) non-exclusive queues: attempts to declare a queue with such property combination will be rejected by default. Use durable queues, transient exclusive queues, or durable queues with a queue TTL instead. To explicitly allow transient non-exclusive queues, make sure that all nodes in the cluster include the following rabbitmq.conf key and were restarted so that all nodes have a consistent view of the deprecated feature settings: # Enables deprecated non-durable (transient) non-exclusive queues # (disabled by default as of RabbitMQ `4.3.0`, will be removed in a later version). # # Must be effective on all cluster nodes BEFORE # the cluster is upgraded to `4.3.0`. # If only some nodes have the setting configured, it will not have the desired effect. deprecated_features.permit.transient_nonexcl_queues = true If only some nodes have setting configured, it will not have the desired effect. Classic Queues v1 Storage (CQv1) is Removed This release removes the original classic queue storage implementation these days known as CQv1. A 2nd generation implementation called CQv2 has been adopted as the default starting with 4.2.0 . This means that attempts to declare a queue using the following optional queue arguments will fail: x-queue-mode set to any value x-queue-version set to 1 Existing classic queues upgraded to CQv2 during an earlier upgrade to 4.2.x will continue operating as usual. Consumer Timeouts are No Longer Evaluated for Classic Queues and Streams This release moves consumer timeout handling responsibility into the queues themselves. Also, all protocols (except for the stream protocol) now evaluate consumer timeout for queue types that support them. Classic queues and streams never evaluate consumer timeouts as their use cases largely avoid the need for such as feature. Release Highlights Khepri is Now The Only Metadata Store As of this release, Khepri is the only metadata store supported by RabbitMQ: Mnesia was removed completely. In practical operational terms, this means that For a cluster to be available, a majority of nodes must be online at all times Failure and partition recovery in a RabbitMQ cluster is now significantly simpler and uniform: all components that have replicated state (Khepri, quorum queues, streams) recover per Raft recovery semantics Quorum Queues Enhancements This release upgrades the Ra dependency to 3.x and introduces a new (8th) version of the quorum queue state machine with several new features and optimisations: Strict priority queues with per-priority message counts, correct redelivery ordering, and priority-aware message expiration Delayed retry for quorum queues: configurable increasing backoff when messages are returned Consumer timeout for quorum queues: configurable timeout for unacknowledged messages, with protocol-specific handling for AMQP 1.0 and MQTT Recovery snapshots and snapshot throttling to reduce recovery time and improve snapshotting decisions Memory optimisations including compact message references, optimised tuple storage for delayed keys, and removal of rabbit_fifo_index usage Upgrading to 4.3.0 Documentation Guides on Upgrades See th

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSALERTMANAGER-0.32.1

0.32.1 / 2026-04-29

[BUGFIX] dispatcher: Fix issue with dispatching to a contended route. #5179 [BUGFIX] ui: Provide prebuilt ui assets in release. #5191 [ENHANCEMENT] ui: Support building artifacts in containers with Docker or Podman. #5102

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSALERTMANAGER-0.32.1-RC.0

0.32.1-rc.0 / 2026-04-27

[BUGFIX] dispatcher: Fix issue with dispatching to a contended route. #5179 [BUGFIX] ui: Provide prebuilt ui assets in release. #5191 [ENHANCEMENT] ui: Support building artifacts in containers with Docker or Podman. #5102

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-7.0.7

v7.0.7

⭐ New Features Improve SpringValidatorAdapter and MethodValidationAdapter performance #36621 Support JSON array decoding to Flux in KotlinSerializationJsonDecoder #36597 Deprecate methodIdentification() in CacheAspectSupport for removal #36575 Add MockRestServiceServer#createServer variant for RestClient #36572 Create RestClientXhrTransport variant replacing RestTemplateXhrTransport #36566 Improve error handling in multipart codecs #36563 Make ApplicationListenerMethodAdapter#getTargetMethod() public #36558 ApiVersionConfigurer.setSupportedVersionPredicate() returns void instead of ApiVersionConfigurer #36551 LazyConnectionDataSourceProxy does not work well with Hibernate's multi-tenancy by schema strategy #36527 Add registerManagedResource variant with bean key argument to MBeanExporter #36520 Handle blank Accept-Language header in AcceptHeaderLocaleResolver #36513 Make AbstractStreamingClientHttpRequest and AbstractBufferingClientHttpRequest public #36501 MySQL Error 149 (Galera/WSREP conflict) not translated to ConcurrencyFailureException in Spring JDBC/ORM #36499 Add PreFlightRequestFilter #36482 Support configuration of extension context scope for SpringExtension via Spring or JUnit properties #36460 Lower log level of "Cache miss for REQUEST dispatch" in HandlerMappingIntrospector #36309 🐞 Bug Fixes WebDataBinder unnecessarily instantiates collections when using the "!" and "_" prefixes #36625 Cache pollution from high-cardinality FieldError default messages in MessageSourceSupport #36609 MergedAnnotation does not use ClassLoader for method or field #36606 @Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36611 AnnotatedTypeMetadata no longer retains source declaration order on Java 24+ #36598 MergedAnnotation.asMap() fails when an attribute references a non-existent class #36586 FileSystemResource does not strictly follow the Resource#isReadable() contract #36584 Converter overrides in HttpMessageConverters only apply when defaults are registered #36579 Invalid method return type metadata for ClassFile variant on JDK 24+ #36577 Fix Writer lifecycle for AbstractJsonHttpMessageConverter.writeInternal(Object, Type, Writer) #36565 Flushing-related regression in SseServerResponse #36537 LazyConnectionDataSourceProxy does not pass on holdability to target Connection #36528 AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36524 Perserve default API version in RestClientAdapter #36514 Inconsistent codings resolution in resource resolvers #36507 DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36506 Query not hidden in DefaultClientResponse checkpoint #36502 RestClient closes stream for ResponseEntity responses #36492 IllegalStateException when using websocket handshake headers with Tomcat #36486 Invalid nullness information for ParameterizedTypeReference #36477 WebTestClient cannot assert null list elements #36476 Handle Kotlin nullable value class param correctly in CoroutineUtils #36449 Remove RFC 2047 encoding from Content-Disposition filename #36328 📔 Documentation Clarify semantics of HttpMethod.valueOf() #36652 Document whitespace semantics in SpEL expressions #36628 Document that spring.profiles.active is ignored by @ActiveProfiles #36600 MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36567 Fix incorrect Javadoc in HandlerMethodReturnValueHandlerComposite regarding caching #36555 Fix incorrect method name in TypeDescriptor.array() Javadoc #36549 Introduce Kotlin examples for Bean Overrides ( @MockitoBean , etc.) #36541 Fix incorrect cross-reference links in AbstractEnvironment Javadoc #36516 Document RetryTemplate#invoke variants in reference manual #36452 Link observability section to Micrometer Observation Handler docs #34994 🔨 Dependency Upgrades Upgrade to Micrometer 1.16.5 #36659 Upgrade to Reactor 2025.0.5 #36658 ❤️ Contributors Thank you to all the contributors who worked on th

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPPACKER-1.15.3

v1.15.3

1.15.3 (April 27, 2026) BUG FIXES: hcp: skip bucket update requests when description and labels already match, avoiding unnecessary updates for existing buckets. GH-13624

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GITEAGITEA-1.26.1

v1.26.1

BUGFIXES Add event.schedule context for schedule actions task ( #37320 ) ( #37348 ) Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. ( #37324 ) ( #37344 ) Use modern "git update-index --cacheinfo" syntax to support more file names ( #37338 ) ( #37343 ) Fix URL related escaping for oauth2 ( #37334 ) ( #37340 ) When the requested arch rpm is missing fall back to noarch ( #37236 ) ( #37339 ) Fix actions concurrency groups cross-branch leak ( #37311 ) ( #37331 ) Fix bug when accessing user badges ( #37321 ) ( #37329 ) Fix AppFullLink ( #37325 ) ( #37328 ) Fix container auth for public instance ( #37290 ) ( #37294 ) Enhance GetActionWorkflow to support fallback references ( #37189 ) ( #37283 ) Fix vite manifest update masking build errors ( #37279 ) ( #37310 ) Fix Mermaid diagrams failing when node labels contain line breaks ( #37296 ) ( #37299 ) Use TriggerEvent instead of Event in workflow runs API response for scheduled runs ( #37288 ) #37360 Add URL to Learn more about blocking a user. ( #37355 ) #37367 Fix button layout shift when collapsing file tree in editor ( #37363 ) #37375 Fix org team assignee/reviewer lookups for team member permissions ( #37365 ) #37391 Fix repo init README EOL ( #37388 ) #37399 Fix: dump with default zip type produces uncompressed zip ( #37401 ) #37402 Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPPACKER-1.15.2

v1.15.2

1.15.2 (April 21, 2026) FEATURES: provisioner: added support for the enforced provisioner. GH-13591 SECURITY: deps: bump github.com/go-jose/go-jose/v4 GH-13594 deps: bump go.opentelemetry.io/otel/sdk GH-13606 deps: update cloud.google.com/go and aws-sdk-go-v2 related dependencies GH-13610 INTERNAL: build: bump Go to 1.25.9 and refresh dependencies GH-13614 GH-13615

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.0.6

v4.0.6

🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50188 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50187 ApplicationPidFileWriter does not handle symlinks correctly #50185 RandomValuePropertySource is not suitable for secrets #50183 Cassandra auto-configuration misconfigures CqlSessionBuilder #50180 ApplicationTemp does not handle symlinks correctly #50178 Remote DevTools performs comparison incorrectly #50176 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50174 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50077 Classic starters are missing several modules #50071 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50069 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50064 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50039 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50017 Imports on a containing test class are ignored when a nested class has imports #50012 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49951 500 response from env endpoint when supplied pattern is invalid #49946 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49945 HTTP method is lost when configuring excludes in EndpointRequest #49943 Honor HttpMethod for reactive additional endpoint paths #49880 Docker Compose support doesn't work with apache/artemis image #49869 Docker Compose support doesn't work with apache/activemq image #49866 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49854 API versioning path strategy should be applied path last as it is not meant to yield #49800 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50146 HTTP Service Interface Clients still document that API versioning can be configured via properties #50126 Link to the observability section of the Lettuce documentation is broken #50097 Javadoc for StaticResourceLocation.FAVICON doesn't describe icons location #50085 MySamlRelyingPartyConfiguration is missing a Kotlin sample #50024 Incorrect default value for management.httpexchanges.recording.include in configuration metadata #50019 Link to the Kubernetes documentation when discussing startup probes #50015 Typo in JdbcSessionAutoConfiguration Javadoc #49873 Clarify that configuration property default values are not available through the Environment #49851 Document the need for Liquibase and Flyway starters #49839 Kafka documentation refers to deprecated JSON serializer and deserializer classes #49826 🔨 Dependency Upgrades Upgrade to Elasticsearch Client 9.2.8 #50027 Upgrade to Groovy 5.0.5 #49911 Upgrade to Hibernate 7.2.12.Final #50134 Upgrade to Jackson Bom 3.1.2 #50051 Upgrade to Jaxen 2.0.1 #50104 Upgrade to Jaybird 6.0.5 #49914 Upgrade to Jetty 12.1.8 #49915 Upgrade to jOOQ 3.19.32 #50105 Upgrade to Log4j2 2.25.4 #49916 Upgrade to Lombok 1.18.46 #50150 Upgrade to MariaDB 3.5.8 #49917 Upgrade to Micrometer 1.16.5 #49972 Upgrade to Micrometer Tracing 1.6.5 #49973 Upgrade to MongoDB 5.6.5 #50028 Upgrade to MySQL 9.7.0 #50159 Upgrade to Neo4j Java Driver 6.0.5 #50075 Upgrade to Reactor Bom 2025.0.5 #49974 Upgrade to Spring AMQP 4.0.3 #49975 Upgrade to Spring Data Bom 2025.1.5 #49976 Upgrade to Spring Framework 7.0.7 #49977 Upgrade to Spring GraphQL 2.0.3 #49978 Upgrade to Spring Kafka 4.0.5 #49979 Upgrade to Spring LDAP 4.0.3 #49980 Upgrade to Spring Pulsar 2.0.5 #49981 Upgrade to Spring Security 7.0.5 #49982 Upgrade to Spring Session 4.0.3 #49983 Upgrade to Testcontainers 2.0.5 #50135 Upgrade to Thymeleaf 3

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.1.0-RC1

v4.1.0-RC1

⭐ New Features Add support for docker.elastic.co/elasticsearch/elasticsearch #50119 Narrow the scope of icons pattern to /icons/icon-* #50084 Add configuration options for KafkaTemplate's allowNonTransactional and closeTimeout #49954 Align ReactorHttpClientBuilder defaults with Spring Framework and provide an opt-out #49950 Add support for providing a custom SessionTimeout bean #49883 Add support for Redis Annotation driven listeners #49858 Support spring.webflux.default-html-escape property for application-wide HTML escaping configuration #49791 Add fallback support for '/opt/homebrew/bin' on macOS #49721 Support InetAddress filtering for HTTP Clients #49687 Monitor certificates from truststore in SslMeterBinder #49641 Enable ansi support by default on Windows 11+ #49571 Add ' @GrpcAdvice ' exception handling support #49053 Add support for OpenTelemetry SDK environment variables #48799 Add ability to read custom layers.xml from classpath #32466 Support LazyConnectionDataSourceProxy #15480 🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50190 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50189 ApplicationPidFileWriter does not handle symlinks correctly #50186 RandomValuePropertySource is not suitable for secrets #50184 Cassandra auto-configuration misconfigures CqlSessionBuilder #50182 ApplicationTemp does not handle symlinks correctly #50179 Remote DevTools performs comparison incorrectly #50177 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50175 GrpcDisableCsrfHttpConfigurer incorrectly uses inverse of 'spring.grpc.server.security.csrf.enabled' property #50145 API versioning path strategy should be applied path last as it is not meant to yield #50127 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50078 Classic starters are missing several modules #50072 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50070 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50065 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50040 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50018 Imports on a containing test class are ignored when a nested class has imports #50013 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49988 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49958 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49957 500 response from env endpoint when supplied pattern is invalid #49947 HTTP method is lost when configuring excludes in EndpointRequest #49944 Honor HttpMethod for reactive additional endpoint paths #49881 Docker Compose support doesn't work with apache/artemis image #49870 Docker Compose support doesn't work with apache/activemq image #49867 ReactiveOAuth2ResourceServerAutoConfiguration should trigger only on real Reactive Applications #49807 Test starters 'spring-boot-starter-grpc-client-test' and 'spring-boot-starter-grpc-server-test' are missing #49690 Properties in ' @ConfigurationProperties ' annotated type shouldn't be able to define the same ' @Name ' #49565 Distribution's SLO, minimum expected value, and maximum expected value are not applied to long task timer meters #49190 WebConversionService breaks embedded value resolving #8923 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50147 HTTP Service Interface Clients still document that API versioning can be configured via properties #50128 Link to the observability section of the Lettuce documentation is broken #50098 Javadoc for StaticResour

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.3.13

Bun v1.3.13

To install Bun v1.3.13 curl -fsSL https://bun.sh/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.sh/install.ps1|iex " To upgrade to Bun v1.3.13: bun upgrade Read Bun v1.3.13's release notes on Bun's blog Thanks to 8 contributors! @alii @ant-kurt @chrislloyd @cirospaciari @dylan-conway @jarred-sumner @robobun @sosukesuzuki

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-6.2.18

v6.2.18

⭐ New Features Improve SpringValidatorAdapter and MethodValidationAdapter performance #36624 Add missing @Deprecated (forRemoval = true) for deleted in 7.0 #36591 Deprecate methodIdentification() in CacheAspectSupport for removal #36576 Improve error handling in multipart codecs #36564 LazyConnectionDataSourceProxy does not work well with Hibernate's multi-tenancy by schema strategy #36529 MySQL Error 149 (Galera/WSREP conflict) not translated to ConcurrencyFailureException in Spring JDBC/ORM #36510 🐞 Bug Fixes Handle Kotlin nullable value class param correctly in CoroutineUtils #36643 NullPointerException in ServerSentEvent when trying to set id or event properties #36634 @Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36630 WebDataBinder unnecessarily instantiates collections when using the "!" and "_" prefixes #36627 Cache pollution from high-cardinality FieldError default messages in MessageSourceSupport #36623 ContentCachingRequestWrapper does not allow unlimited content caching #36620 MergedAnnotation does not use ClassLoader for method or field #36614 AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36588 FileSystemResource does not strictly follow the Resource#isReadable() contract #36585 Query not hidden in DefaultClientResponse checkpoint #36571 LazyConnectionDataSourceProxy does not pass on holdability to target Connection #36530 DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36511 Inconsistent codings resolution in resource resolvers #36508 📔 Documentation Clarify semantics of HttpMethod.valueOf() #36653 Document that spring.profiles.active is ignored by @ActiveProfiles #36636 Document whitespace semantics in SpEL expressions #36629 MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36568 Introduce Kotlin examples for Bean Overrides ( @MockitoBean , etc.) #36542 Fix incorrect cross-reference links in AbstractEnvironment Javadoc #36517 🔨 Dependency Upgrades Upgrade to Micrometer 1.15.11 #36661 Upgrade to Reactor 2024.0.17 #36660

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RUST FOUNDATIONRUST-1.95.0

Rust 1.95.0

Language Stabilize if let guards on match arms irrefutable_let_patterns lint no longer lints on let chains Support importing path-segment keywords with renaming Stabilize inline assembly for PowerPC and PowerPC64 const-eval: be more consistent in the behavior of padding during typed copies Const blocks are no longer evaluated to determine if expressions involving fallible operations can implicitly be constant-promoted. . Expressions whose ability to implicitly be promoted would depend on the result of a const block are no longer implicitly promoted. Make operational semantics of pattern matching independent of crate and module Compiler Stabilize --remap-path-scope for controlling the scoping of how paths get remapped in the resulting binary Apply patches for CVE-2026-6042 and CVE-2026-40200 to vendored musl Platform Support Promote powerpc64-unknown-linux-musl to Tier 2 with host tools Promote aarch64-apple-tvos to Tier 2 Promote aarch64-apple-tvos-sim to Tier 2 Promote aarch64-apple-watchos to Tier 2 Promote aarch64-apple-watchos-sim to Tier 2 Promote aarch64-apple-visionos to Tier 2 Promote aarch64-apple-visionos-sim to Tier 2 Refer to Rust's platform support page for more information on Rust's tiered platform support. Libraries thread::scope : document how join interacts with TLS destructors Speed up str::contains on aarch64 targets with neon target feature enabled by default Stabilized APIs MaybeUninit<[T; N]>: From<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>]> MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>]> [MaybeUninit<T>; N]: From<MaybeUninit<[T; N]>> Cell<[T; N]>: AsRef<[Cell<T>; N]> Cell<[T; N]>: AsRef<[Cell<T>]> Cell<[T]>: AsRef<[Cell<T>]> bool: TryFrom<{integer}> AtomicPtr::update AtomicPtr::try_update AtomicBool::update AtomicBool::try_update AtomicIn::update AtomicIn::try_update AtomicUn::update AtomicUn::try_update cfg_select! mod core::range core::range::RangeInclusive core::range::RangeInclusiveIter core::hint::cold_path <*const T>::as_ref_unchecked <*mut T>::as_ref_unchecked <*mut T>::as_mut_unchecked Vec::push_mut Vec::insert_mut VecDeque::push_front_mut VecDeque::push_back_mut VecDeque::insert_mut LinkedList::push_front_mut LinkedList::push_back_mut Layout::dangling_ptr Layout::repeat Layout::repeat_packed Layout::extend_packed These previously stable APIs are now stable in const contexts: fmt::from_fn ControlFlow::is_break ControlFlow::is_continue Rustdoc In search results, rank unstable items lower Add new "hide deprecated items" setting in rustdoc Compatibility Notes Array coercions may now result in less inference constraints than before Importing $crate without renaming, i.e. use $crate::{self}; , is now no longer permitted due to stricter error checking for self imports. const-eval: be more consistent in the behavior of padding during typed copies. In very rare cases, this may cause compilation errors due to bytes from parts of a pointer ending up in the padding bytes of a const or static . A future-incompatibility warning lint ambiguous_glob_imported_traits is now reported when using an ambiguously glob imported trait Check lifetime bounds of types mentioning only type parameters Report more visibility-related ambiguous import errors Deprecate Eq::assert_receiver_is_total_eq and emit future compatibility warnings on manual impls powerpc64: Use the ELF ABI version set in target spec instead of guessing (fixes the ELF ABI used by the OpenBSD target) Matching on a #[non_exhaustive] enum now reads the discriminant, even if the enum has only one variant . This can cause closures to capture values that they previously wouldn't. mut ref and mut ref mut patterns, part of the unstable Match Ergonomics 2024 RFC , were accidentally allowed on stable within struct pattern field shorthand. These patterns are now correctly feature-gated as unstable in this position. Add future-compatibility warning for d

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.1.3

v5.1.3

What's Changed 🐛 Fixes fix: provider output handling and watch rebuild re-invocation by @glours in #13732 🔧 Internal Add Docker Desktop Logs view hints and navigation shortcut by @glours in #13721 Build and push Docker Desktop module image on release by @glours in #13726 Fix typo in SECURITY.md by @glours in #13730 Make hook hint deep links clickable using OSC 8 terminal hyperlinks by @glours in #13734 Remove 'provenance' attribute' by @glours in #13738 ⚙️ Dependencies build(deps): bump github.com/containerd/containerd/v2 from 2.2.2 to 2.2.3 by @dependabot [bot] in #13737 Full Changelog : v5.1.2...v5.1.3

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.0.0

v2.0.0

BREAKING CHANGES: sdk/helpers/docker: Migrate docker helpers from github.com/docker/docker to github.com/moby/moby. This was necessary as github.com/docker/docker is no longer maintained. Resolves GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 . SECURITY: Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229 Upgrade filippo.io/edwards25519 to v1.1.1 to resolve GO-2026-4503 api/auth/gcp: Update go.opentelemetry.io/otel/sdk to fix CVE-2026-39883 . api/auth: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . auth/aws: fix an issue where a user may be able to bypass authentication to Vault due to incorrect caching of the AWS client auth/cert: ensure that the certificate being renewed matches the certificate attached to the session. core: Correctly remove any Vault tokens from the Authorization header when this header is forwarded to plugin backends. The header will only be forwarded if "Authorization" is explicitly included in the list of passthrough request headers. core: Resolve GO-2026-4518 and GHSA-jqcq-xjh3-6g23 by upgrading to github.com/jackc/pgx/v5 core: Update github.com/aws/aws-sdk-go-v2/ to fix security vulnerability GHSA-xmrv-pmrh-hhx2 . core: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . core: Update github.com/hashicorp/go-getter to fix security vulnerability GHSA-92mm-2pjq-r785 . core: Update go.opentelemetry.io/otel/sdk to fix CVE-2026-39883 . core: reject URL-encoded paths that do not specify a canonical path http: Added configurable max_token_header_size listener option (default 8 KB) to bound the size of authentication token headers ( X-Vault-Token and Authorization: Bearer ), preventing a potential denial-of-service attack via oversized header contents. The stdlib-level MaxHeaderBytes backstop is also now set on the HTTP server. Set max_token_header_size = -1 to disable the limit. sdk: Resolve GO-2026-4518 and GHSA-jqcq-xjh3-6g23 by upgrading to github.com/jackc/pgx/v5 sdk: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . ui: disable scarf analytics for ui builds vault/sdk: Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229 vault/sdk: Upgrade go.opentelemetry.io/otel/sdk to v1.40.0 to resolve GO-2026-4394 Update github.com/dvsekhvalnov/jose2go to fix security vulnerability CVE-2025-63811 . go: update to golang/x/crypto to v0.45.0 to resolve GHSA-f6x5-jh6r-wrfv , GHSA-j5w8-q4qc-rx2x , GO-2025-4134 and GO-2025-4135. CHANGES: secrets/ldap (enterprise): Static roles will be migrated from a plugin-managed queue to the Vault Enterprise Rotation Manager system. Static role migration progress can be checked and managed through a new static-migration endpoint. See the LDAP documentation for more details on this process. audit: A new top-level key called supplemental_audit_data can now appear within audit entries of type "response" within the request and response data structures. These new fields can contain data that further describe the request/response data and are mainly used for non-JSON based requests and responses to help auditing. The audit-non-hmac-request-keys and audit-non-hmac-response-keys apply to keys within supplemental_audit_data to remove the HMAC of the field values if so desired. auth/alicloud: Update plugin to v0.23.1 auth/azure: Update plugin to v0.24.0 auth/cf: Update plugin to v0.23.0 auth/gcp: Update plugin to v0.23.1 auth/jwt: Update plugin to v0.26.1 auth/kerberos: Update plugin to v0.17.1 auth/kubernetes: Update plugin to v0.24.1 auth/oci: Update plugin to v0.21.1 auth/saml: Update plugin to v0.8.1 core/managed-keys (enterprise): The response to API endpoint GET sys/managed-keys/:type/:name now returns an array of string values for key usages, rather than an array of integer values. The strings used are 'encrypt' (1), 'decrypt' (2), 'sign' (3), 'verify' (4), 'wrap' (5), 'unwrap' (6), 'generate_random' (7), and 'mac'

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.1.2

v5.1.2

What's Changed 🐛 Fixes Fix TTY timer rendering when duration length changes by @MaybeSam05 in #13634 Fix up attach filtering by @false200 in #13664 Preserve ssh:// URL scheme when resolving Dockerfile path by @ssam18 in #13669 Initialize and pass envFiles map in processExtends by @Mohamed-Moumni in #13678 Fix TestRunHook_ConsoleSize on macOS by @thaJeztah in #13686 Restore post-connect fallback for multi-network stacks on API < 1.44 by @jotka in #13629 Publish: return api.ErrCanceled when user declines interactive prompts by @ishwar170695 in #13674 Return error on non-ErrNotExist stat failures in Tar.Sync() by @Lidang-Jiang in #13684 🔧 Internal Refactor: thread context through publish sensitive data check by @ishwar170695 in #13653 Add AI-powered PR review workflow via docker/cagent-action by @glours in #13659 Update cagent-action to latest (with better permissions) by @derekmisler in #13665 Pin GitHub Actions to commit SHA, remove pr-review workflow by @glours in #13662 Exclude hook_test.go from Windows builds and propagate ExecStart error in runWaitExec by @pawannn in #13683 Skip PR review workflow for Dependabot PRs by @glours in #13679 Use negotiated API version for network setup by @glours in #13690 Fix mixed assertion libraries in tests by @thaJeztah in #13689 Test: use random host port for dind TLS build test by @ricardobranco777 in #13630 Remove direct dependency on docker/docker by @glours in #13706 ⚙️ Dependencies Bump github.com/containerd/platforms from 1.0.0-rc.2 to 1.0.0-rc.3 by @dependabot [bot] in #13657 Bump golangci-lint to v2.11.3 and configure CLAUDE to use it on change by @ndeloof in #13656 Bump google.golang.org/grpc from 1.78.0 to 1.79.3 by @dependabot [bot] in #13642 Bump github.com/moby/patternmatcher from 0.6.0 to 0.6.1 by @dependabot [bot] in #13667 Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.42.0 by @glours in #13663 Bump github.com/docker/cli from 29.2.1+incompatible to 29.3.1+incompatible by @dependabot [bot] in #13670 Bump github.com/hashicorp/go-version from 1.8.0 to 1.9.0 by @dependabot [bot] in #13692 Bump github.com/docker/buildx v0.33.0 , buildkit v0.29.0 by @thaJeztah in #13693 Bump google.golang.org/grpc from 1.79.3 to 1.80.0 by @dependabot [bot] in #13697 Bump github.com/containerd/platforms from 1.0.0-rc.3 to 1.0.0-rc.4 by @dependabot [bot] in #13696 Bump github.com/moby/moby/client v0.4.0 , moby/api v1.54.1 by @thaJeztah in #13708 Bump github.com/docker/cli v29.4.0 by @thaJeztah in #13707 Bump compose-go to version v2.10.2 by @glours in #13705 Bump to Go 1.25.9 by @thaJeztah in #13720 New Contributors @MaybeSam05 made their first contribution in #13634 @ishwar170695 made their first contribution in #13653 @derekmisler made their first contribution in #13665 @false200 made their first contribution in #13664 @ssam18 made their first contribution in #13669 @Mohamed-Moumni made their first contribution in #13678 @pawannn made their first contribution in #13683 @jotka made their first contribution in #13629 @Lidang-Jiang made their first contribution in #13684 Full Changelog : v5.1.1...v5.1.2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSALERTMANAGER-0.32.0

0.32.0 / 2026-04-08

[CHANGE] go get github.com/prometheus/alertmanager/ui will now fail as compiled UI assets are no longer checked into the repository. Downstream builds that rely on these assets being present in the source tree must now build the UI from source. #5113 [CHANGE] The '--enable-feature=auto-gomaxprocs' option is deprecated and will be removed in v0.33. This flag currently has no effect and can be safely removed from any startup scripts. #5090 [CHANGE] Update internal function signatures across multiple packages. This affects any project that integrates Alertmanager code. [ENHANCEMENT] Add static asset caching. #5113 [ENHANCEMENT] Reduce memory allocations through pre-sizing collections and batch allocation. #5020 [ENHANCEMENT] Replace help with documentation in navigation bar. #4943 [ENHANCEMENT] docs(ha): Update high availability documentation. #5136 [ENHANCEMENT] docs: Add auth_secret_file for smtp in document. #5036 [ENHANCEMENT] docs: Add description for global telegram_bot_token . #5114 [ENHANCEMENT] docs: Add note about notifier timeouts. #5077 [ENHANCEMENT] docs: Fix force_implicit_tls config field name. #5030 [ENHANCEMENT] docs: Link community supported integrations. #4978 [ENHANCEMENT] docs: Remove duplicate header. #5034 [ENHANCEMENT] docs: Update mutual tls reference in high availability documentation. #5120 [ENHANCEMENT] tracing: Use noop spans when tracing disabled. #5118 [ENHANCEMENT] ui: Serve pre-compressed assets. #5133 [FEATURE] Add silence annotations. #4965 [FEATURE] Add silence logging option. #4163 [FEATURE] Add support for multiple matcher set silences. #4957 [FEATURE] Add the reason for notifying in dedup stage. #4971 [FEATURE] mattermost: Flatten attachments into top-level config. #5009 [FEATURE] mattermost: Support global webhook url. #4998 [FEATURE] slack: Add default color from template. #5014 [FEATURE] slack: Allow receiver to edit existing messages. #5007 [FEATURE] template: Add dict, map and append functions. #5093 [FEATURE] webhook: Add full payload templating support for notifier. #5011 [BUGFIX] config: Check for empty cluster tls client config. #5126 [BUGFIX] config: Don't crash upon reading empty config for notifier. #4979 [BUGFIX] config: Fix ipv6 address handling in hostport.string(). #5040 [BUGFIX] mattermost: Omit empty text field in notifications. #4985 [BUGFIX] telegram: Send fallback message when notification exceeds character limit. #5074 [BUGFIX] tracing: Properly shutdown tracer provider. #5131 [BUGFIX] ui: Fix escaping for matcher values with quotes. #4862 [BUGFIX] ui: Handle special chars in silence regex-matchers. #4942 [BUGFIX] ui: Support utf-8 label names in matchers. #5089

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENSEARCHOPENSEARCH-3.6.0

3.6.0

Version 3.6.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.6.0 Features Add bitmap64 query support ( #20606 ) Add warmup phase for pull-based ingestion to prevent serving stale data before catching up with the streaming source ( #20526 ) Implement field_mapping ingestion message mapper for pull-based ingestion ( #20729 ) Add mapper_settings support and field_mapping mapper type for pull-based ingestion ( #20722 ) Remove experimental tag for pull-based ingestion, marking it as public API ( #20704 ) Enhancements Add index warmer support for replica shards using segment replication ( #20650 ) Add indices to search request slow log for easier request identification ( #20588 ) Add node-level JVM and CPU runtime metrics following OpenTelemetry semantic conventions ( #20844 ) Add new Sensitive setting property for tiering dynamic settings authorization ( #20901 ) Add adaptive shard selection for bulk writes on append-only indices ( #20065 ) Add support for expected remote cluster name validation in CCS sniff mode ( #20532 ) Add search_settings support to WLM workload groups with initial timeout setting ( #20536 ) Add scroll API support for workload management rule-based autotagging ( #20151 ) Add stream request flag to SearchRequestContext for plugin consumption ( #20530 ) Support Docker distribution builds for ppc64le, arm64, and s390x architectures ( #20678 ) Fallback to Netty HTTP client when AWS CRT client is unavailable on the target platform ( #20698 ) Add intra-segment support for single-value metric aggregations (sum, min, max, avg, stats, cardinality, value_count) ( #20503 ) Expose wrapped scorer in ProfileScorer for plugin access to custom scorer methods ( #20549 ) Fix ProfileScorer.getChildren() to expose wrapped scorer in the scorer tree hierarchy ( #20607 ) Remove X-Request-Id format restrictions and make maximum length configurable ( #21048 ) Make telemetry Tags immutable with allocation-efficient factories and content-based equality ( #20788 ) Add ref_path support for package-based Hunspell dictionary loading with multi-tenant isolation ( #20840 ) Prevent criteria field updates for context-aware indices to simplify version management ( #20250 ) Add indexer interface to decouple IndexShard from Engine for pluggable engine architectures ( #20675 ) Use ReadAdviseByContext for MMapDirectory instead of Lucene default read advise ( #21062 ) Bug Fixes Fix copy_to functionality for geo_point fields with object and array values ( #20542 ) Fix field_caps returning empty results for disable_objects mappings and field name corruption ( #20814 ) Fix terms lookup subquery to use cluster max_clause_count setting instead of hardcoded fallback ( #20823 ) Fix terms aggregation performance regression on high-cardinality fields by adding a max cardinality setting ( #20623 ) Fix terms aggregation performance regression using segment-to-global ordinals mapping ( #20683 ) Fix array_index_out_of_bounds_exception with wildcard and aggregations under concurrent access ( #20842 ) Add range validations in query builder and field mapper ( #20518 ) Fix synonym_graph filter failure with word_delimiter_graph by handling analyzer dependency ordering ( #19248 ) Fix index template pattern collision false positives for multi-wildcard patterns ( #20702 ) Fix SecurityException when using opensearch.cgroups.hierarchy.override setting ( #20565 ) Fix SLF4J component error caused by slf4j-api version mismatch with log4j binding ( #20587 ) Fix JSON escaping in task details log metadata ( #20802 ) Fix listBlobsByPrefixInSortedOrder in EncryptedBlobContainer to respect limit and prevent JVM exhaustion ( #20514 ) Fix batched deletion of stale cluster metadata manifests to prevent remote storage pile-up ( #20566 ) Fix segment replication infinite retry caused by stale metadata checkpoint ( #20551 ) Fix ExitableTerms to delegate getMin / getMax methods avoiding slow path in field sort ( #20775 ) Lazily initialize stored field reader i

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPPACKER-1.15.1

v1.15.1

1.15.1 (March 26, 2026) FEATURES: hcp: native sbom generation for hcp. Refer to the guide here for more information. GH-13566 BUG FIXES: core: Scrub multiline sensitive values from build output (including OS-specific multiline sensitive-value fixtures) GH-13582 SECURITY: deps: bump syft to v1.42.3 (fixes GO-2026-4809) GH-13581 deps: bump github.com/hashicorp/packer-plugin-sdk to v0.6.7 GH-13581 deps: bump github.com/hashicorp/hcp-sdk-go from 0.136.0 to 0.167.0 GH-13560 deps: Updates OpenTelemetry dependencies to v1.41.0 GH-13572 deps: Upgrade go-git to v5.17.0 and grpc to 1.79.3 GH-13570 deps: Updates circl dependency to v1.6.3 GH-13564 INTERNAL: ci: Adds grouped and scheduled updates for GitHub Actions (monthly, grouped PRs, ignore major bumps) GH-13575 docs: remove docs validation from packer (docs changes move to web-unified-docs) GH-13577 legal: Update LICENSE GH-13563

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RUST FOUNDATIONRUST-1.94.1

Rust 1.94.1

Fix std::thread::spawn on wasm32-wasip1-threads Remove new methods added to std::os::windows::fs::OpenOptionsExt The new methods were unstable, but the trait itself is not sealed and so cannot be extended with non-default methods. Clippy: fix ICE in match_same_arms Cargo: update tar to 0.4.45 This resolves CVE-2026-33055 and CVE-2026-33056 . Users of crates.io are not affected. See blog for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.1.1

v5.1.1

What's Changed 🐛 Fixes Only pass ConsoleSize to ExecAttach when TTY is enabled by @mikesir87 in #13616 Fix deadlock in ttyWriter.Done() by @maks2134 in #13640 ⚙️ Dependencies update to go1.25.8 by @thaJeztah in #13622 bump github.com/moby/moby/api from 1.53.0 to 1.54.0 by @dependabot [bot] in #13619 bump golang.org/x/sys from 0.41.0 to 0.42.0 by @dependabot [bot] in #13626 bump github.com/containerd/containerd/v2 from 2.2.1 to 2.2.2 by @dependabot [bot] in #13631 bump golang.org/x/sync from 0.19.0 to 0.20.0 by @dependabot [bot] in #13627 bump github.com/moby/moby/client from 0.2.2 to 0.3.0 by @dependabot [bot] in #13621 New Contributors @maks2134 made their first contribution in #13640 Full Changelog : v5.1.0...v5.1.1

Published Never · Source checked 29 Sep 2026

Release notes and known issues →