FORTINETFORTINET-PRODUCTS-51E28132BCBC0625
CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-532B91C042CFCD9C
CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-783B453E74F51AD1
CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-99DB29317DD5A9B4
CVSSv3 Score: 8.3 An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-A1186039008D4FE9
CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-E1CDEA8EEE07D522
CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00
Published 12 May 2026 · Source checked 29 Sep 2026
Release notes and known issues →RABBITMQRABBITMQ-4.3.0
RabbitMQ 4.3.0 is a new feature release. Breaking Changes and Compatibility Notes Mnesia and Parition Handling Strategies are Removed Since only 4.2.x clusters can upgrade to 4.3.0 in place , this won't be a breaking change for nearly all instalations but it will affect community plugins that use Mnesia. All partition handling-related keys in rabbitmq.conf will be accepted by 4.3.0 nodes but won't have any effect: cluster_partition_handling cluster_partition_handling.pause_if_all_down.recover cluster_partition_handling.pause_if_all_down.nodes.$name Team RabbitMQ recommends removing the above keys from rabbitmq.conf before or shortly after upgrading. Deprecated Features are Now Disabled by Default A number of deprecated features are now disabled by default and require the user to opt-in in order to use them. This includes non-durable (transient) non-exclusive queues: attempts to declare a queue with such property combination will be rejected by default. Use durable queues, transient exclusive queues, or durable queues with a queue TTL instead. To explicitly allow transient non-exclusive queues, make sure that all nodes in the cluster include the following rabbitmq.conf key and were restarted so that all nodes have a consistent view of the deprecated feature settings: # Enables deprecated non-durable (transient) non-exclusive queues # (disabled by default as of RabbitMQ `4.3.0`, will be removed in a later version). # # Must be effective on all cluster nodes BEFORE # the cluster is upgraded to `4.3.0`. # If only some nodes have the setting configured, it will not have the desired effect. deprecated_features.permit.transient_nonexcl_queues = true If only some nodes have setting configured, it will not have the desired effect. Classic Queues v1 Storage (CQv1) is Removed This release removes the original classic queue storage implementation these days known as CQv1. A 2nd generation implementation called CQv2 has been adopted as the default starting with 4.2.0 . This means that attempts to declare a queue using the following optional queue arguments will fail: x-queue-mode set to any value x-queue-version set to 1 Existing classic queues upgraded to CQv2 during an earlier upgrade to 4.2.x will continue operating as usual. Consumer Timeouts are No Longer Evaluated for Classic Queues and Streams This release moves consumer timeout handling responsibility into the queues themselves. Also, all protocols (except for the stream protocol) now evaluate consumer timeout for queue types that support them. Classic queues and streams never evaluate consumer timeouts as their use cases largely avoid the need for such as feature. Release Highlights Khepri is Now The Only Metadata Store As of this release, Khepri is the only metadata store supported by RabbitMQ: Mnesia was removed completely. In practical operational terms, this means that For a cluster to be available, a majority of nodes must be online at all times Failure and partition recovery in a RabbitMQ cluster is now significantly simpler and uniform: all components that have replicated state (Khepri, quorum queues, streams) recover per Raft recovery semantics Quorum Queues Enhancements This release upgrades the Ra dependency to 3.x and introduces a new (8th) version of the quorum queue state machine with several new features and optimisations: Strict priority queues with per-priority message counts, correct redelivery ordering, and priority-aware message expiration Delayed retry for quorum queues: configurable increasing backoff when messages are returned Consumer timeout for quorum queues: configurable timeout for unacknowledged messages, with protocol-specific handling for AMQP 1.0 and MQTT Recovery snapshots and snapshot throttling to reduce recovery time and improve snapshotting decisions Memory optimisations including compact message references, optimised tuple storage for delayed keys, and removal of rabbit_fifo_index usage Upgrading to 4.3.0 Documentation Guides on Upgrades See th
Published Never · Source checked 29 Sep 2026
Release notes and known issues →POSTGRESQLPOSTGRESQL-18.4
Stamp 18.4.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.0.6
React Server Components Type hardening and performance improvements ( #36425 by @eps1lon and @unstubbable )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.1.7
React Server Components Type hardening and performance improvements ( #36425 by @eps1lon and @unstubbable )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.2.6
React Server Components Type hardening and performance improvements ( #36425 by @eps1lon and @unstubbable )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.67
2.4.67
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.32.1
[BUGFIX] dispatcher: Fix issue with dispatching to a contended route. #5179 [BUGFIX] ui: Provide prebuilt ui assets in release. #5191 [ENHANCEMENT] ui: Support building artifacts in containers with Docker or Podman. #5102
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.32.1-RC.0
[BUGFIX] dispatcher: Fix issue with dispatching to a contended route. #5179 [BUGFIX] ui: Provide prebuilt ui assets in release. #5191 [ENHANCEMENT] ui: Support building artifacts in containers with Docker or Podman. #5102
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.67-RC2-CANDIDATE
2.4.67-rc2-candidate
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-FRAMEWORK-7.0.7
⭐ New Features Improve SpringValidatorAdapter and MethodValidationAdapter performance #36621 Support JSON array decoding to Flux in KotlinSerializationJsonDecoder #36597 Deprecate methodIdentification() in CacheAspectSupport for removal #36575 Add MockRestServiceServer#createServer variant for RestClient #36572 Create RestClientXhrTransport variant replacing RestTemplateXhrTransport #36566 Improve error handling in multipart codecs #36563 Make ApplicationListenerMethodAdapter#getTargetMethod() public #36558 ApiVersionConfigurer.setSupportedVersionPredicate() returns void instead of ApiVersionConfigurer #36551 LazyConnectionDataSourceProxy does not work well with Hibernate's multi-tenancy by schema strategy #36527 Add registerManagedResource variant with bean key argument to MBeanExporter #36520 Handle blank Accept-Language header in AcceptHeaderLocaleResolver #36513 Make AbstractStreamingClientHttpRequest and AbstractBufferingClientHttpRequest public #36501 MySQL Error 149 (Galera/WSREP conflict) not translated to ConcurrencyFailureException in Spring JDBC/ORM #36499 Add PreFlightRequestFilter #36482 Support configuration of extension context scope for SpringExtension via Spring or JUnit properties #36460 Lower log level of "Cache miss for REQUEST dispatch" in HandlerMappingIntrospector #36309 🐞 Bug Fixes WebDataBinder unnecessarily instantiates collections when using the "!" and "_" prefixes #36625 Cache pollution from high-cardinality FieldError default messages in MessageSourceSupport #36609 MergedAnnotation does not use ClassLoader for method or field #36606 @Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36611 AnnotatedTypeMetadata no longer retains source declaration order on Java 24+ #36598 MergedAnnotation.asMap() fails when an attribute references a non-existent class #36586 FileSystemResource does not strictly follow the Resource#isReadable() contract #36584 Converter overrides in HttpMessageConverters only apply when defaults are registered #36579 Invalid method return type metadata for ClassFile variant on JDK 24+ #36577 Fix Writer lifecycle for AbstractJsonHttpMessageConverter.writeInternal(Object, Type, Writer) #36565 Flushing-related regression in SseServerResponse #36537 LazyConnectionDataSourceProxy does not pass on holdability to target Connection #36528 AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36524 Perserve default API version in RestClientAdapter #36514 Inconsistent codings resolution in resource resolvers #36507 DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36506 Query not hidden in DefaultClientResponse checkpoint #36502 RestClient closes stream for ResponseEntity responses #36492 IllegalStateException when using websocket handshake headers with Tomcat #36486 Invalid nullness information for ParameterizedTypeReference #36477 WebTestClient cannot assert null list elements #36476 Handle Kotlin nullable value class param correctly in CoroutineUtils #36449 Remove RFC 2047 encoding from Content-Disposition filename #36328 📔 Documentation Clarify semantics of HttpMethod.valueOf() #36652 Document whitespace semantics in SpEL expressions #36628 Document that spring.profiles.active is ignored by @ActiveProfiles #36600 MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36567 Fix incorrect Javadoc in HandlerMethodReturnValueHandlerComposite regarding caching #36555 Fix incorrect method name in TypeDescriptor.array() Javadoc #36549 Introduce Kotlin examples for Bean Overrides ( @MockitoBean , etc.) #36541 Fix incorrect cross-reference links in AbstractEnvironment Javadoc #36516 Document RetryTemplate#invoke variants in reference manual #36452 Link observability section to Micrometer Observation Handler docs #34994 🔨 Dependency Upgrades Upgrade to Micrometer 1.16.5 #36659 Upgrade to Reactor 2025.0.5 #36658 ❤️ Contributors Thank you to all the contributors who worked on th
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.15.3
1.15.3 (April 27, 2026) BUG FIXES: hcp: skip bucket update requests when description and labels already match, avoiding unnecessary updates for existing buckets. GH-13624
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.67-RC1-CANDIDATE
2.4.67-rc1-candidate
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.26.1
BUGFIXES Add event.schedule context for schedule actions task ( #37320 ) ( #37348 ) Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. ( #37324 ) ( #37344 ) Use modern "git update-index --cacheinfo" syntax to support more file names ( #37338 ) ( #37343 ) Fix URL related escaping for oauth2 ( #37334 ) ( #37340 ) When the requested arch rpm is missing fall back to noarch ( #37236 ) ( #37339 ) Fix actions concurrency groups cross-branch leak ( #37311 ) ( #37331 ) Fix bug when accessing user badges ( #37321 ) ( #37329 ) Fix AppFullLink ( #37325 ) ( #37328 ) Fix container auth for public instance ( #37290 ) ( #37294 ) Enhance GetActionWorkflow to support fallback references ( #37189 ) ( #37283 ) Fix vite manifest update masking build errors ( #37279 ) ( #37310 ) Fix Mermaid diagrams failing when node labels contain line breaks ( #37296 ) ( #37299 ) Use TriggerEvent instead of Event in workflow runs API response for scheduled runs ( #37288 ) #37360 Add URL to Learn more about blocking a user. ( #37355 ) #37367 Fix button layout shift when collapsing file tree in editor ( #37363 ) #37375 Fix org team assignee/reviewer lookups for team member permissions ( #37365 ) #37391 Fix repo init README EOL ( #37388 ) #37399 Fix: dump with default zip type produces uncompressed zip ( #37401 ) #37402 Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.15.2
1.15.2 (April 21, 2026) FEATURES: provisioner: added support for the enforced provisioner. GH-13591 SECURITY: deps: bump github.com/go-jose/go-jose/v4 GH-13594 deps: bump go.opentelemetry.io/otel/sdk GH-13606 deps: update cloud.google.com/go and aws-sdk-go-v2 related dependencies GH-13610 INTERNAL: build: bump Go to 1.25.9 and refresh dependencies GH-13614 GH-13615
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-BOOT-4.0.6
🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50188 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50187 ApplicationPidFileWriter does not handle symlinks correctly #50185 RandomValuePropertySource is not suitable for secrets #50183 Cassandra auto-configuration misconfigures CqlSessionBuilder #50180 ApplicationTemp does not handle symlinks correctly #50178 Remote DevTools performs comparison incorrectly #50176 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50174 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50077 Classic starters are missing several modules #50071 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50069 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50064 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50039 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50017 Imports on a containing test class are ignored when a nested class has imports #50012 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49951 500 response from env endpoint when supplied pattern is invalid #49946 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49945 HTTP method is lost when configuring excludes in EndpointRequest #49943 Honor HttpMethod for reactive additional endpoint paths #49880 Docker Compose support doesn't work with apache/artemis image #49869 Docker Compose support doesn't work with apache/activemq image #49866 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49854 API versioning path strategy should be applied path last as it is not meant to yield #49800 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50146 HTTP Service Interface Clients still document that API versioning can be configured via properties #50126 Link to the observability section of the Lettuce documentation is broken #50097 Javadoc for StaticResourceLocation.FAVICON doesn't describe icons location #50085 MySamlRelyingPartyConfiguration is missing a Kotlin sample #50024 Incorrect default value for management.httpexchanges.recording.include in configuration metadata #50019 Link to the Kubernetes documentation when discussing startup probes #50015 Typo in JdbcSessionAutoConfiguration Javadoc #49873 Clarify that configuration property default values are not available through the Environment #49851 Document the need for Liquibase and Flyway starters #49839 Kafka documentation refers to deprecated JSON serializer and deserializer classes #49826 🔨 Dependency Upgrades Upgrade to Elasticsearch Client 9.2.8 #50027 Upgrade to Groovy 5.0.5 #49911 Upgrade to Hibernate 7.2.12.Final #50134 Upgrade to Jackson Bom 3.1.2 #50051 Upgrade to Jaxen 2.0.1 #50104 Upgrade to Jaybird 6.0.5 #49914 Upgrade to Jetty 12.1.8 #49915 Upgrade to jOOQ 3.19.32 #50105 Upgrade to Log4j2 2.25.4 #49916 Upgrade to Lombok 1.18.46 #50150 Upgrade to MariaDB 3.5.8 #49917 Upgrade to Micrometer 1.16.5 #49972 Upgrade to Micrometer Tracing 1.6.5 #49973 Upgrade to MongoDB 5.6.5 #50028 Upgrade to MySQL 9.7.0 #50159 Upgrade to Neo4j Java Driver 6.0.5 #50075 Upgrade to Reactor Bom 2025.0.5 #49974 Upgrade to Spring AMQP 4.0.3 #49975 Upgrade to Spring Data Bom 2025.1.5 #49976 Upgrade to Spring Framework 7.0.7 #49977 Upgrade to Spring GraphQL 2.0.3 #49978 Upgrade to Spring Kafka 4.0.5 #49979 Upgrade to Spring LDAP 4.0.3 #49980 Upgrade to Spring Pulsar 2.0.5 #49981 Upgrade to Spring Security 7.0.5 #49982 Upgrade to Spring Session 4.0.3 #49983 Upgrade to Testcontainers 2.0.5 #50135 Upgrade to Thymeleaf 3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-BOOT-4.1.0-RC1
⭐ New Features Add support for docker.elastic.co/elasticsearch/elasticsearch #50119 Narrow the scope of icons pattern to /icons/icon-* #50084 Add configuration options for KafkaTemplate's allowNonTransactional and closeTimeout #49954 Align ReactorHttpClientBuilder defaults with Spring Framework and provide an opt-out #49950 Add support for providing a custom SessionTimeout bean #49883 Add support for Redis Annotation driven listeners #49858 Support spring.webflux.default-html-escape property for application-wide HTML escaping configuration #49791 Add fallback support for '/opt/homebrew/bin' on macOS #49721 Support InetAddress filtering for HTTP Clients #49687 Monitor certificates from truststore in SslMeterBinder #49641 Enable ansi support by default on Windows 11+ #49571 Add ' @GrpcAdvice ' exception handling support #49053 Add support for OpenTelemetry SDK environment variables #48799 Add ability to read custom layers.xml from classpath #32466 Support LazyConnectionDataSourceProxy #15480 🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50190 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50189 ApplicationPidFileWriter does not handle symlinks correctly #50186 RandomValuePropertySource is not suitable for secrets #50184 Cassandra auto-configuration misconfigures CqlSessionBuilder #50182 ApplicationTemp does not handle symlinks correctly #50179 Remote DevTools performs comparison incorrectly #50177 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50175 GrpcDisableCsrfHttpConfigurer incorrectly uses inverse of 'spring.grpc.server.security.csrf.enabled' property #50145 API versioning path strategy should be applied path last as it is not meant to yield #50127 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50078 Classic starters are missing several modules #50072 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50070 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50065 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50040 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50018 Imports on a containing test class are ignored when a nested class has imports #50013 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49988 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49958 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49957 500 response from env endpoint when supplied pattern is invalid #49947 HTTP method is lost when configuring excludes in EndpointRequest #49944 Honor HttpMethod for reactive additional endpoint paths #49881 Docker Compose support doesn't work with apache/artemis image #49870 Docker Compose support doesn't work with apache/activemq image #49867 ReactiveOAuth2ResourceServerAutoConfiguration should trigger only on real Reactive Applications #49807 Test starters 'spring-boot-starter-grpc-client-test' and 'spring-boot-starter-grpc-server-test' are missing #49690 Properties in ' @ConfigurationProperties ' annotated type shouldn't be able to define the same ' @Name ' #49565 Distribution's SLO, minimum expected value, and maximum expected value are not applied to long task timer meters #49190 WebConversionService breaks embedded value resolving #8923 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50147 HTTP Service Interface Clients still document that API versioning can be configured via properties #50128 Link to the observability section of the Lettuce documentation is broken #50098 Javadoc for StaticResour
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-1.3.13
To install Bun v1.3.13 curl -fsSL https://bun.sh/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.sh/install.ps1|iex " To upgrade to Bun v1.3.13: bun upgrade Read Bun v1.3.13's release notes on Bun's blog Thanks to 8 contributors! @alii @ant-kurt @chrislloyd @cirospaciari @dylan-conway @jarred-sumner @robobun @sosukesuzuki
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-FRAMEWORK-6.2.18
⭐ New Features Improve SpringValidatorAdapter and MethodValidationAdapter performance #36624 Add missing @Deprecated (forRemoval = true) for deleted in 7.0 #36591 Deprecate methodIdentification() in CacheAspectSupport for removal #36576 Improve error handling in multipart codecs #36564 LazyConnectionDataSourceProxy does not work well with Hibernate's multi-tenancy by schema strategy #36529 MySQL Error 149 (Galera/WSREP conflict) not translated to ConcurrencyFailureException in Spring JDBC/ORM #36510 🐞 Bug Fixes Handle Kotlin nullable value class param correctly in CoroutineUtils #36643 NullPointerException in ServerSentEvent when trying to set id or event properties #36634 @Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36630 WebDataBinder unnecessarily instantiates collections when using the "!" and "_" prefixes #36627 Cache pollution from high-cardinality FieldError default messages in MessageSourceSupport #36623 ContentCachingRequestWrapper does not allow unlimited content caching #36620 MergedAnnotation does not use ClassLoader for method or field #36614 AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36588 FileSystemResource does not strictly follow the Resource#isReadable() contract #36585 Query not hidden in DefaultClientResponse checkpoint #36571 LazyConnectionDataSourceProxy does not pass on holdability to target Connection #36530 DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36511 Inconsistent codings resolution in resource resolvers #36508 📔 Documentation Clarify semantics of HttpMethod.valueOf() #36653 Document that spring.profiles.active is ignored by @ActiveProfiles #36636 Document whitespace semantics in SpEL expressions #36629 MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36568 Introduce Kotlin examples for Bean Overrides ( @MockitoBean , etc.) #36542 Fix incorrect cross-reference links in AbstractEnvironment Javadoc #36517 🔨 Dependency Upgrades Upgrade to Micrometer 1.15.11 #36661 Upgrade to Reactor 2024.0.17 #36660
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.95.0
Language Stabilize if let guards on match arms irrefutable_let_patterns lint no longer lints on let chains Support importing path-segment keywords with renaming Stabilize inline assembly for PowerPC and PowerPC64 const-eval: be more consistent in the behavior of padding during typed copies Const blocks are no longer evaluated to determine if expressions involving fallible operations can implicitly be constant-promoted. . Expressions whose ability to implicitly be promoted would depend on the result of a const block are no longer implicitly promoted. Make operational semantics of pattern matching independent of crate and module Compiler Stabilize --remap-path-scope for controlling the scoping of how paths get remapped in the resulting binary Apply patches for CVE-2026-6042 and CVE-2026-40200 to vendored musl Platform Support Promote powerpc64-unknown-linux-musl to Tier 2 with host tools Promote aarch64-apple-tvos to Tier 2 Promote aarch64-apple-tvos-sim to Tier 2 Promote aarch64-apple-watchos to Tier 2 Promote aarch64-apple-watchos-sim to Tier 2 Promote aarch64-apple-visionos to Tier 2 Promote aarch64-apple-visionos-sim to Tier 2 Refer to Rust's platform support page for more information on Rust's tiered platform support. Libraries thread::scope : document how join interacts with TLS destructors Speed up str::contains on aarch64 targets with neon target feature enabled by default Stabilized APIs MaybeUninit<[T; N]>: From<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>]> MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>; N]> MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>]> [MaybeUninit<T>; N]: From<MaybeUninit<[T; N]>> Cell<[T; N]>: AsRef<[Cell<T>; N]> Cell<[T; N]>: AsRef<[Cell<T>]> Cell<[T]>: AsRef<[Cell<T>]> bool: TryFrom<{integer}> AtomicPtr::update AtomicPtr::try_update AtomicBool::update AtomicBool::try_update AtomicIn::update AtomicIn::try_update AtomicUn::update AtomicUn::try_update cfg_select! mod core::range core::range::RangeInclusive core::range::RangeInclusiveIter core::hint::cold_path <*const T>::as_ref_unchecked <*mut T>::as_ref_unchecked <*mut T>::as_mut_unchecked Vec::push_mut Vec::insert_mut VecDeque::push_front_mut VecDeque::push_back_mut VecDeque::insert_mut LinkedList::push_front_mut LinkedList::push_back_mut Layout::dangling_ptr Layout::repeat Layout::repeat_packed Layout::extend_packed These previously stable APIs are now stable in const contexts: fmt::from_fn ControlFlow::is_break ControlFlow::is_continue Rustdoc In search results, rank unstable items lower Add new "hide deprecated items" setting in rustdoc Compatibility Notes Array coercions may now result in less inference constraints than before Importing $crate without renaming, i.e. use $crate::{self}; , is now no longer permitted due to stricter error checking for self imports. const-eval: be more consistent in the behavior of padding during typed copies. In very rare cases, this may cause compilation errors due to bytes from parts of a pointer ending up in the padding bytes of a const or static . A future-incompatibility warning lint ambiguous_glob_imported_traits is now reported when using an ambiguously glob imported trait Check lifetime bounds of types mentioning only type parameters Report more visibility-related ambiguous import errors Deprecate Eq::assert_receiver_is_total_eq and emit future compatibility warnings on manual impls powerpc64: Use the ELF ABI version set in target spec instead of guessing (fixes the ELF ABI used by the OpenBSD target) Matching on a #[non_exhaustive] enum now reads the discriminant, even if the enum has only one variant . This can cause closures to capture values that they previously wouldn't. mut ref and mut ref mut patterns, part of the unstable Match Ergonomics 2024 RFC , were accidentally allowed on stable within struct pattern field shorthand. These patterns are now correctly feature-gated as unstable in this position. Add future-compatibility warning for d
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.1.3
What's Changed 🐛 Fixes fix: provider output handling and watch rebuild re-invocation by @glours in #13732 🔧 Internal Add Docker Desktop Logs view hints and navigation shortcut by @glours in #13721 Build and push Docker Desktop module image on release by @glours in #13726 Fix typo in SECURITY.md by @glours in #13730 Make hook hint deep links clickable using OSC 8 terminal hyperlinks by @glours in #13734 Remove 'provenance' attribute' by @glours in #13738 ⚙️ Dependencies build(deps): bump github.com/containerd/containerd/v2 from 2.2.2 to 2.2.3 by @dependabot [bot] in #13737 Full Changelog : v5.1.2...v5.1.3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPVAULT-2.0.0
BREAKING CHANGES: sdk/helpers/docker: Migrate docker helpers from github.com/docker/docker to github.com/moby/moby. This was necessary as github.com/docker/docker is no longer maintained. Resolves GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 . SECURITY: Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229 Upgrade filippo.io/edwards25519 to v1.1.1 to resolve GO-2026-4503 api/auth/gcp: Update go.opentelemetry.io/otel/sdk to fix CVE-2026-39883 . api/auth: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . auth/aws: fix an issue where a user may be able to bypass authentication to Vault due to incorrect caching of the AWS client auth/cert: ensure that the certificate being renewed matches the certificate attached to the session. core: Correctly remove any Vault tokens from the Authorization header when this header is forwarded to plugin backends. The header will only be forwarded if "Authorization" is explicitly included in the list of passthrough request headers. core: Resolve GO-2026-4518 and GHSA-jqcq-xjh3-6g23 by upgrading to github.com/jackc/pgx/v5 core: Update github.com/aws/aws-sdk-go-v2/ to fix security vulnerability GHSA-xmrv-pmrh-hhx2 . core: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . core: Update github.com/hashicorp/go-getter to fix security vulnerability GHSA-92mm-2pjq-r785 . core: Update go.opentelemetry.io/otel/sdk to fix CVE-2026-39883 . core: reject URL-encoded paths that do not specify a canonical path http: Added configurable max_token_header_size listener option (default 8 KB) to bound the size of authentication token headers ( X-Vault-Token and Authorization: Bearer ), preventing a potential denial-of-service attack via oversized header contents. The stdlib-level MaxHeaderBytes backstop is also now set on the HTTP server. Set max_token_header_size = -1 to disable the limit. sdk: Resolve GO-2026-4518 and GHSA-jqcq-xjh3-6g23 by upgrading to github.com/jackc/pgx/v5 sdk: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8 . ui: disable scarf analytics for ui builds vault/sdk: Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229 vault/sdk: Upgrade go.opentelemetry.io/otel/sdk to v1.40.0 to resolve GO-2026-4394 Update github.com/dvsekhvalnov/jose2go to fix security vulnerability CVE-2025-63811 . go: update to golang/x/crypto to v0.45.0 to resolve GHSA-f6x5-jh6r-wrfv , GHSA-j5w8-q4qc-rx2x , GO-2025-4134 and GO-2025-4135. CHANGES: secrets/ldap (enterprise): Static roles will be migrated from a plugin-managed queue to the Vault Enterprise Rotation Manager system. Static role migration progress can be checked and managed through a new static-migration endpoint. See the LDAP documentation for more details on this process. audit: A new top-level key called supplemental_audit_data can now appear within audit entries of type "response" within the request and response data structures. These new fields can contain data that further describe the request/response data and are mainly used for non-JSON based requests and responses to help auditing. The audit-non-hmac-request-keys and audit-non-hmac-response-keys apply to keys within supplemental_audit_data to remove the HMAC of the field values if so desired. auth/alicloud: Update plugin to v0.23.1 auth/azure: Update plugin to v0.24.0 auth/cf: Update plugin to v0.23.0 auth/gcp: Update plugin to v0.23.1 auth/jwt: Update plugin to v0.26.1 auth/kerberos: Update plugin to v0.17.1 auth/kubernetes: Update plugin to v0.24.1 auth/oci: Update plugin to v0.21.1 auth/saml: Update plugin to v0.8.1 core/managed-keys (enterprise): The response to API endpoint GET sys/managed-keys/:type/:name now returns an array of string values for key usages, rather than an array of integer values. The strings used are 'encrypt' (1), 'decrypt' (2), 'sign' (3), 'verify' (4), 'wrap' (5), 'unwrap' (6), 'generate_random' (7), and 'mac'
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.1.2
What's Changed 🐛 Fixes Fix TTY timer rendering when duration length changes by @MaybeSam05 in #13634 Fix up attach filtering by @false200 in #13664 Preserve ssh:// URL scheme when resolving Dockerfile path by @ssam18 in #13669 Initialize and pass envFiles map in processExtends by @Mohamed-Moumni in #13678 Fix TestRunHook_ConsoleSize on macOS by @thaJeztah in #13686 Restore post-connect fallback for multi-network stacks on API < 1.44 by @jotka in #13629 Publish: return api.ErrCanceled when user declines interactive prompts by @ishwar170695 in #13674 Return error on non-ErrNotExist stat failures in Tar.Sync() by @Lidang-Jiang in #13684 🔧 Internal Refactor: thread context through publish sensitive data check by @ishwar170695 in #13653 Add AI-powered PR review workflow via docker/cagent-action by @glours in #13659 Update cagent-action to latest (with better permissions) by @derekmisler in #13665 Pin GitHub Actions to commit SHA, remove pr-review workflow by @glours in #13662 Exclude hook_test.go from Windows builds and propagate ExecStart error in runWaitExec by @pawannn in #13683 Skip PR review workflow for Dependabot PRs by @glours in #13679 Use negotiated API version for network setup by @glours in #13690 Fix mixed assertion libraries in tests by @thaJeztah in #13689 Test: use random host port for dind TLS build test by @ricardobranco777 in #13630 Remove direct dependency on docker/docker by @glours in #13706 ⚙️ Dependencies Bump github.com/containerd/platforms from 1.0.0-rc.2 to 1.0.0-rc.3 by @dependabot [bot] in #13657 Bump golangci-lint to v2.11.3 and configure CLAUDE to use it on change by @ndeloof in #13656 Bump google.golang.org/grpc from 1.78.0 to 1.79.3 by @dependabot [bot] in #13642 Bump github.com/moby/patternmatcher from 0.6.0 to 0.6.1 by @dependabot [bot] in #13667 Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.42.0 by @glours in #13663 Bump github.com/docker/cli from 29.2.1+incompatible to 29.3.1+incompatible by @dependabot [bot] in #13670 Bump github.com/hashicorp/go-version from 1.8.0 to 1.9.0 by @dependabot [bot] in #13692 Bump github.com/docker/buildx v0.33.0 , buildkit v0.29.0 by @thaJeztah in #13693 Bump google.golang.org/grpc from 1.79.3 to 1.80.0 by @dependabot [bot] in #13697 Bump github.com/containerd/platforms from 1.0.0-rc.3 to 1.0.0-rc.4 by @dependabot [bot] in #13696 Bump github.com/moby/moby/client v0.4.0 , moby/api v1.54.1 by @thaJeztah in #13708 Bump github.com/docker/cli v29.4.0 by @thaJeztah in #13707 Bump compose-go to version v2.10.2 by @glours in #13705 Bump to Go 1.25.9 by @thaJeztah in #13720 New Contributors @MaybeSam05 made their first contribution in #13634 @ishwar170695 made their first contribution in #13653 @derekmisler made their first contribution in #13665 @false200 made their first contribution in #13664 @ssam18 made their first contribution in #13669 @Mohamed-Moumni made their first contribution in #13678 @pawannn made their first contribution in #13683 @jotka made their first contribution in #13629 @Lidang-Jiang made their first contribution in #13684 Full Changelog : v5.1.1...v5.1.2
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.32.0
[CHANGE] go get github.com/prometheus/alertmanager/ui will now fail as compiled UI assets are no longer checked into the repository. Downstream builds that rely on these assets being present in the source tree must now build the UI from source. #5113 [CHANGE] The '--enable-feature=auto-gomaxprocs' option is deprecated and will be removed in v0.33. This flag currently has no effect and can be safely removed from any startup scripts. #5090 [CHANGE] Update internal function signatures across multiple packages. This affects any project that integrates Alertmanager code. [ENHANCEMENT] Add static asset caching. #5113 [ENHANCEMENT] Reduce memory allocations through pre-sizing collections and batch allocation. #5020 [ENHANCEMENT] Replace help with documentation in navigation bar. #4943 [ENHANCEMENT] docs(ha): Update high availability documentation. #5136 [ENHANCEMENT] docs: Add auth_secret_file for smtp in document. #5036 [ENHANCEMENT] docs: Add description for global telegram_bot_token . #5114 [ENHANCEMENT] docs: Add note about notifier timeouts. #5077 [ENHANCEMENT] docs: Fix force_implicit_tls config field name. #5030 [ENHANCEMENT] docs: Link community supported integrations. #4978 [ENHANCEMENT] docs: Remove duplicate header. #5034 [ENHANCEMENT] docs: Update mutual tls reference in high availability documentation. #5120 [ENHANCEMENT] tracing: Use noop spans when tracing disabled. #5118 [ENHANCEMENT] ui: Serve pre-compressed assets. #5133 [FEATURE] Add silence annotations. #4965 [FEATURE] Add silence logging option. #4163 [FEATURE] Add support for multiple matcher set silences. #4957 [FEATURE] Add the reason for notifying in dedup stage. #4971 [FEATURE] mattermost: Flatten attachments into top-level config. #5009 [FEATURE] mattermost: Support global webhook url. #4998 [FEATURE] slack: Add default color from template. #5014 [FEATURE] slack: Allow receiver to edit existing messages. #5007 [FEATURE] template: Add dict, map and append functions. #5093 [FEATURE] webhook: Add full payload templating support for notifier. #5011 [BUGFIX] config: Check for empty cluster tls client config. #5126 [BUGFIX] config: Don't crash upon reading empty config for notifier. #4979 [BUGFIX] config: Fix ipv6 address handling in hostport.string(). #5040 [BUGFIX] mattermost: Omit empty text field in notifications. #4985 [BUGFIX] telegram: Send fallback message when notification exceeds character limit. #5074 [BUGFIX] tracing: Properly shutdown tracer provider. #5131 [BUGFIX] ui: Fix escaping for matcher values with quotes. #4862 [BUGFIX] ui: Handle special chars in silence regex-matchers. #4942 [BUGFIX] ui: Support utf-8 label names in matchers. #5089
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-3.6.0
Version 3.6.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.6.0 Features Add bitmap64 query support ( #20606 ) Add warmup phase for pull-based ingestion to prevent serving stale data before catching up with the streaming source ( #20526 ) Implement field_mapping ingestion message mapper for pull-based ingestion ( #20729 ) Add mapper_settings support and field_mapping mapper type for pull-based ingestion ( #20722 ) Remove experimental tag for pull-based ingestion, marking it as public API ( #20704 ) Enhancements Add index warmer support for replica shards using segment replication ( #20650 ) Add indices to search request slow log for easier request identification ( #20588 ) Add node-level JVM and CPU runtime metrics following OpenTelemetry semantic conventions ( #20844 ) Add new Sensitive setting property for tiering dynamic settings authorization ( #20901 ) Add adaptive shard selection for bulk writes on append-only indices ( #20065 ) Add support for expected remote cluster name validation in CCS sniff mode ( #20532 ) Add search_settings support to WLM workload groups with initial timeout setting ( #20536 ) Add scroll API support for workload management rule-based autotagging ( #20151 ) Add stream request flag to SearchRequestContext for plugin consumption ( #20530 ) Support Docker distribution builds for ppc64le, arm64, and s390x architectures ( #20678 ) Fallback to Netty HTTP client when AWS CRT client is unavailable on the target platform ( #20698 ) Add intra-segment support for single-value metric aggregations (sum, min, max, avg, stats, cardinality, value_count) ( #20503 ) Expose wrapped scorer in ProfileScorer for plugin access to custom scorer methods ( #20549 ) Fix ProfileScorer.getChildren() to expose wrapped scorer in the scorer tree hierarchy ( #20607 ) Remove X-Request-Id format restrictions and make maximum length configurable ( #21048 ) Make telemetry Tags immutable with allocation-efficient factories and content-based equality ( #20788 ) Add ref_path support for package-based Hunspell dictionary loading with multi-tenant isolation ( #20840 ) Prevent criteria field updates for context-aware indices to simplify version management ( #20250 ) Add indexer interface to decouple IndexShard from Engine for pluggable engine architectures ( #20675 ) Use ReadAdviseByContext for MMapDirectory instead of Lucene default read advise ( #21062 ) Bug Fixes Fix copy_to functionality for geo_point fields with object and array values ( #20542 ) Fix field_caps returning empty results for disable_objects mappings and field name corruption ( #20814 ) Fix terms lookup subquery to use cluster max_clause_count setting instead of hardcoded fallback ( #20823 ) Fix terms aggregation performance regression on high-cardinality fields by adding a max cardinality setting ( #20623 ) Fix terms aggregation performance regression using segment-to-global ordinals mapping ( #20683 ) Fix array_index_out_of_bounds_exception with wildcard and aggregations under concurrent access ( #20842 ) Add range validations in query builder and field mapper ( #20518 ) Fix synonym_graph filter failure with word_delimiter_graph by handling analyzer dependency ordering ( #19248 ) Fix index template pattern collision false positives for multi-wildcard patterns ( #20702 ) Fix SecurityException when using opensearch.cgroups.hierarchy.override setting ( #20565 ) Fix SLF4J component error caused by slf4j-api version mismatch with log4j binding ( #20587 ) Fix JSON escaping in task details log metadata ( #20802 ) Fix listBlobsByPrefixInSortedOrder in EncryptedBlobContainer to respect limit and prevent JVM exhaustion ( #20514 ) Fix batched deletion of stale cluster metadata manifests to prevent remote storage pile-up ( #20566 ) Fix segment replication infinite retry caused by stale metadata checkpoint ( #20551 ) Fix ExitableTerms to delegate getMin / getMax methods avoiding slow path in field sort ( #20775 ) Lazily initialize stored field reader i
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPVAULT-0.25.1
Backport [VAULT-43813] go: resolve CVE-2026-34986 and GHSA-78h2-9frx-…
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPVAULT-2.0.0-RC1
This is an automated pull request to build all artifacts for a release ( #31878 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.15.1
1.15.1 (March 26, 2026) FEATURES: hcp: native sbom generation for hcp. Refer to the guide here for more information. GH-13566 BUG FIXES: core: Scrub multiline sensitive values from build output (including OS-specific multiline sensitive-value fixtures) GH-13582 SECURITY: deps: bump syft to v1.42.3 (fixes GO-2026-4809) GH-13581 deps: bump github.com/hashicorp/packer-plugin-sdk to v0.6.7 GH-13581 deps: bump github.com/hashicorp/hcp-sdk-go from 0.136.0 to 0.167.0 GH-13560 deps: Updates OpenTelemetry dependencies to v1.41.0 GH-13572 deps: Upgrade go-git to v5.17.0 and grpc to 1.79.3 GH-13570 deps: Updates circl dependency to v1.6.3 GH-13564 INTERNAL: ci: Adds grouped and scheduled updates for GitHub Actions (monthly, grouped PRs, ignore major bumps) GH-13575 docs: remove docs validation from packer (docs changes move to web-unified-docs) GH-13577 legal: Update LICENSE GH-13563
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.94.1
Fix std::thread::spawn on wasm32-wasip1-threads Remove new methods added to std::os::windows::fs::OpenOptionsExt The new methods were unstable, but the trait itself is not sealed and so cannot be extended with non-default methods. Clippy: fix ICE in match_same_arms Cargo: update tar to 0.4.45 This resolves CVE-2026-33055 and CVE-2026-33056 . Users of crates.io are not affected. See blog for more details.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.1.1
What's Changed 🐛 Fixes Only pass ConsoleSize to ExecAttach when TTY is enabled by @mikesir87 in #13616 Fix deadlock in ttyWriter.Done() by @maks2134 in #13640 ⚙️ Dependencies update to go1.25.8 by @thaJeztah in #13622 bump github.com/moby/moby/api from 1.53.0 to 1.54.0 by @dependabot [bot] in #13619 bump golang.org/x/sys from 0.41.0 to 0.42.0 by @dependabot [bot] in #13626 bump github.com/containerd/containerd/v2 from 2.2.1 to 2.2.2 by @dependabot [bot] in #13631 bump golang.org/x/sync from 0.19.0 to 0.20.0 by @dependabot [bot] in #13627 bump github.com/moby/moby/client from 0.2.2 to 0.3.0 by @dependabot [bot] in #13621 New Contributors @maks2134 made their first contribution in #13640 Full Changelog : v5.1.0...v5.1.1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-FRAMEWORK-6.2.17
⭐ New Features Leverage ResourceHandlerUtils in ScriptTemplateView #36459 Restore ScriptTemplateViewTests #36457 Fix log message in ConfigurationClassBeanDefinitionReader #36454 Resolve context initializers only once in AbstractTestContextBootstrapper #36431 Exclude legacy @javax.validation.Constraint from convention-based annotation attribute override check #36412 Optimize MediaType(MediaType, Charset) constructor #36351 Optimize the addition of a charset to the MediaType in AbstractHttpMessageConverter #36350 Consistent adaptation of HTTP headers on Servlet responses #36345 Improve performance of validation groups determination in WebFlux #36337 Detect all common size exceptions from Tomcat and Commons FileUpload 2.x #36324 🐞 Bug Fixes Guard against invalid id/event values in Server Sent Events #36442 Incomplete debug message in ConfigurationClassBeanDefinitionReader #36411 Inconsistent ApplicationEventMulticaster state after removing ApplicationListener implemented by FactoryBean #36405 Graceful shutdown of SimpleAsyncTaskExecutor #36384 HttpMediaTypeException thrown when calculating compatible media types #36363 ResolvableType#getGenerics() breaks serialization #36347 Multipart upload leak on client abort (ByteBuf.release() not called) #36327 📔 Documentation Document @Fallback alongside Primary in the reference manual and @Bean Javadoc #36441 Document registration recommendations for BeanPostProcessor and BeanFactoryPostProcessor #36436 Fix links to UriComponentsBuilder and polish examples #36406 Emphasize @Configuration classes over XML and Groovy in testing chapter #36394 Polish SpEL operator examples in reference docs #36375 🔨 Dependency Upgrades Upgrade to JUnit 5.14.3 #36388 Upgrade to Micrometer 1.15.10 #36446 Upgrade to Reactor 2024.0.16 #36445
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-FRAMEWORK-7.0.6
⚠️ Attention Required Log warning when default context configuration is ignored within test class hierarchies #36390 Ignore flush calls on ServletServerHttpResponse body outputstream #36385 ⭐ New Features Leverage ResourceHandlerUtils in ScriptTemplateView #36458 Restore ScriptTemplateViewTests #36456 Fix log message in ConfigurationClassBeanDefinitionReader #36453 DefaultResponseErrorHandler - setMessageConverters() not called via RestClient #36434 Resolve context initializers only once in AbstractTestContextBootstrapper #36430 Invoke resolveContextLoader() only once in AbstractTestContextBootstrapper #36425 Further align synthesized annotation toString() with modern JDKs #36417 Introduce setDefaultCharset() in AbstractResourceBasedMessageSource #36413 Support for JPA 4.0 flush mode "explicit" #36401 Support application-wide defaultHtmlEscape setting in WebFlux RequestContext #36400 Support Predicate<RequestPath>> in path API version resolver #36398 Avoid duplicate flushes in HttpMessageConverter implementations #36383 Add support for non-flushing OutputStream to StreamUtils #36382 Make it easier to get InputStream from RestClient #36380 RuntimeHintsWriter should comply with reachability-metadata-schema-v1.2.0.json #36379 Make it easier to create custom HttpExchangeAdapter #36374 Improve ResourceHttpMessageConverter target type support #36368 org.springframework.test.web.servlet.assertj.AbstractHttpServletResponseAssert#headers case sensitivity #36349 Allow registering serialized lambda metadata through RuntimeHints #36339 Refactor calculateHashCode in RequestMappingInfo #36325 🐞 Bug Fixes MetadataReader misses enclosing class name for Kotlin nested classes with Java 24+ #36451 Guard against invalid id/event values in Server Sent Events #36440 Component scanning fails against non-loadable annotation type with enum array on Java 25 #36432 Duplicate ServletServerHttpRequest headers #36418 Incomplete debug message in ConfigurationClassBeanDefinitionReader #36410 Inconsistent ApplicationEventMulticaster state after removing ApplicationListener implemented by FactoryBean #36404 Propagate max frame length to WebSocket session #36370 Graceful shutdown of SimpleAsyncTaskExecutor #36362 Duplicate response headers with ResponseEntity<Mono<T>> (or Kotlin suspend function) controller method #36357 HttpServiceProxyFactory returns LinkedHashMap instead of target type for method with generic return type #36326 HttpMediaTypeException thrown when calculating compatible media types #36300 📔 Documentation Document FullyQualifiedConfigurationBeanNameGenerator in Javadoc and reference docs #36455 Document @Fallback alongside Primary in the reference manual and @Bean Javadoc #36439 Fix links to UriComponentsBuilder and polish examples #36403 Emphasize @Configuration classes over XML and Groovy in testing chapter #36393 Document tips to avoid issues with ignored default context configuration in tests #36392 Polish SpEL operator examples in reference docs #36367 Add programmatic configuration tabs in the transactional refdoc #36323 Document registration recommendations for BeanPostProcessor and BeanFactoryPostProcessor #34964 🔨 Dependency Upgrades Upgrade to JUnit 6.0.3 #36389 Upgrade to Micrometer 1.16.4 #36444 Upgrade to Reactor 2025.0.4 #36443 ❤️ Contributors Thank you to all the contributors who worked on this release: @AgilAghamirzayev , @aavoronin93 , @cetf9h , @froggy0m0 , @gbouwen , @husseinvr97 , @jisub-dev , @ngocnhan-tran1996 , @siom79 , and @xxxxxxjun
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.11.2
Caddy 2.11.2 contains numerous bug fixes and enhancements! I know that's a lame summary but it's really all over the place. Highlights Reverse proxy got a lot of love with certain edge cases related to PROXY protocol, health check port, and closing body on retries. Dynamic upstreams are now tracked which enables passive health checking. Performance improvements for metrics. New tls_resolvers global option to control DNS resolvers for all sites when using the ACME DNS challenge. Log rolling now supports zstd compression; deprecated roll_gzip , which will be removed in the future. Use roll_compression instead. Refined logging and some error messages. Fixed a bug in rewrite handler that could cause some URIs to not be rewritten when URI path is an escaped form of target path. Thanks to @MaherAzzouzi for the report. Security fixes This release fixes two CVEs. @NucleiAv reported a bug in the forward_auth directive that could permit identity injection and potential privilege escalation. @sammiee5311 reported that vars_regexp double-expanded placeholders, allowing some unusual configs to reveal secrets. In addition: Built on Go 1.26.1 (also released today) which patches several CVEs. Our documentation has been updated to note that file system case sensitivity may affect the behavior of the hide option of the file_server handler. Thank you to everyone who contributed, and for our ongoing sponsorships that make this development possible! Changelog 88616e8 api: Add all in-flight requests /reverse_proxy/upstreams (Fixes #7277 ) ( #7517 ) d935a69 autohttps: Ensure CertMagic config is recreated after autohttps runs ( #7510 ) 5d20adc build(deps): bump github.com/smallstep/certificates ( #7535 ) 9371ee6 build(deps): bump the actions-deps group across 1 directory with 12 updates ( #7536 ) 9798f69 caddyhttp: Avoid nil pointer dereference in proxyWrapper ( #7521 ) dc36082 caddyhttp: Collect metrics once per route instead of per handler ( #7492 ) 174fa2d caddyhttp: Evaluate tls.client placeholders more accurately (fix #7530 ) ( #7534 ) eac02ee caddyhttp: Limit empty Host check to HTTP/1.1 f283062 cmd: Custom binary names through CustomBinaryName and CustomLongDescription ( #7513 ) cd9e166 cmd: Pass configFile, not configFlag, for reload command ( #7532 ) 7b34e31 core: Check whether @id is unique ( #7002 ) 566e710 fileserver: document hide case-sensitivity (F-CADDY-FILESERVER-HIDE-CASE-001) ( #7548 ) 2dd3852 fix(caddyfile): Prevent parser to panic when no token were added by empty {block} ( #7543 ) 2dbcdef forward_auth: copy_headers does not strip client-supplied identity headers (Fixes GHSA-7r4p-vjf4-gxv4 ) ( #7545 ) ce203aa go.mod: Upgrade x/net 76b198f http: Sort auto-HTTPS redirect routes by host specificity (fixes #7390 ) ( #7502 ) 7ffb640 httpcaddyfile: Fix missing TLS connection policies when auto_https is default ( #7325 ) ( #7507 ) 45cf61b logging: Ensure slog error level logs don't print stack traces ( #7512 ) 9873752 logging: Support zstd roll compression ( #7515 ) 294dfff logging: add DirMode options and propagate FileMode to rotations ( #7335 ) a6acb39 proxyproto: Generated test coverage ( #7540 ) 11b56c6 reverseproxy: Fix health_port being ignored in health checks ( #7533 ) db29860 reverseproxy: Track dynamic upstreams, enable passive healthchecking ( #7539 ) d7b21c6 reverseproxy: fix tls dialing w/ proxy protocol ( #7508 ) a5e7c6e reverseproxy: prevent body close on dial-error retries ( #7547 ) 2ab043b reverseproxy: query escape request urls when proxy protocol is enabled ( #7537 ) fbfb8fc rewrite: Force recomputing path when escaped path matches rewrite target f145bce tls: Add tls_resolvers global option for DNS challenge configuration ( #7297 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.94.0
Language Impls and impl items inherit dead_code lint level of the corresponding traits and trait items Stabilize additional 29 RISC-V target features including large portions of the RVA22U64 / RVA23U64 profiles Add warn-by-default unused_visibilities lint for visibility on const _ declarations Update to Unicode 17 Avoid incorrect lifetime errors for closures Platform Support Add riscv64im-unknown-none-elf as a tier 3 target Refer to Rust's platform support page for more information on Rust's tiered platform support. Libraries Relax T: Ord bound for some BinaryHeap<T> methods. Stabilized APIs <[T]>::array_windows <[T]>::element_offset LazyCell::get LazyCell::get_mut LazyCell::force_mut LazyLock::get LazyLock::get_mut LazyLock::force_mut impl TryFrom<char> for usize std::iter::Peekable::next_if_map std::iter::Peekable::next_if_map_mut x86 avx512fp16 intrinsics (excluding those that depend directly on the unstable f16 type) AArch64 NEON fp16 intrinsics (excluding those that depend directly on the unstable f16 type) f32::consts::EULER_GAMMA f64::consts::EULER_GAMMA f32::consts::GOLDEN_RATIO f64::consts::GOLDEN_RATIO These previously stable APIs are now stable in const contexts: f32::mul_add f64::mul_add Cargo Stabilize the config include key. The top-level include config key allows loading additional config files, enabling better organization, sharing, and management of Cargo configurations across projects and environments. docs #16284 Stabilize the pubtime field in registry index. This records when a crate version was published and enables time-based dependency resolution in the future. Note that crates.io will gradually backfill existing packages when a new version is published. Not all crates have pubtime yet. #16369 #16372 Cargo now parses TOML v1.1 for manifests and configuration files. Note that using these features in Cargo.toml will raise your development MSRV, but the published manifest remains compatible with older parsers. #16415 Make CARGO_BIN_EXE_<crate> available at runtime Compatibility Notes Forbid freely casting lifetime bounds of dyn -types Make closure capturing have consistent and correct behaviour around patterns Some finer details of how precise closure captures get affected by pattern matching have been changed. In some cases, this can cause a non-move closure that was previously capturing an entire variable by move, to now capture only part of that variable by move, and other parts by borrow. This can cause the borrow checker to complain where it previously didn't, or cause Drop to run at a different point in time. Standard library macros are now imported via prelude, not via injected #[macro_use] This will raise an error if macros of the same name are glob imported. For example if a crate defines their own matches macro and then glob imports that, it's now ambiguous whether the custom or standard library matches is meant and an explicit import of the name is required to resolve the ambiguity. One exception is core::panic and std::panic , if their import is ambiguous a new warning ( ambiguous_panic_imports ) is raised. This may raise a new warning ( ambiguous_panic_imports ) on #![no_std] code glob importing the std crate. Both core::panic! and std::panic! are then in scope and which is used is ambiguous. Don't strip shebang in expression-context include!(…) s This can cause previously working includes to no longer compile if they included files which started with a shebang. Ambiguous glob reexports are now also visible cross-crate This unifies behavior between local and cross-crate errors on these exports, which may introduce new ambiguity errors. Don't normalize where-clauses before checking well-formedness Introduce a future compatibility warning on codegen attributes on body-free trait methods These attributes currently have no effect in this position. On Windows std::time::SystemTime::checked_sub_duration will return None for times before the Windows epoch (1/1/1601) Lifetime identifiers such as 'a are
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.11.1
Our community is pleased to announce Caddy 2.11! Of note are new features, numerous bug fixes including several security patches, and various QoL ("quality-of-life") enhancements. There are no code changes from v2.11.0 other than to a CI job. Due to a recent external change that broke our release process, the first release of 2.11 is v2.11.1. Special Sponsor Shoutout Extra big thanks to our major sponsors: ZeroSSL Stripe Railway They, along with dozens of smaller sponsors, make this project and new releases possible, together with our maintainer team. Thank you all! Notable changes Encrypted ClientHello (ECH) keys are rotated automatically. Time-rolling options for logs. SIGUSR1 can now reload configuration if it was initially loaded from a file on the command line and did not get changed via the API. Reverse proxy now automatically rewrites the Host header to the address of the upstream when the upstream is HTTPS ( #7454 ) log_append can now log request and response bodies, useful for debugging. Our project now implements and requires Assistance Disclosures (for AI/LLMs) on issues, PRs, comments, replies, reviews, etc. Many, many other minor improvements and bug fixes. Thank you to everyone who was involved this release! ⚠️ Security patches fastcgi: CVE-2026-27590 by @dunglas and @AbdrrahimDahmani - Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport. admin: CVE-2026-27589 by @1seal - Cross-origin requests attempted with no-cors mode could cause some API requests to succeed; such requests are now blocked. (In order for this to be practically exploitable, a web browser executing a malicious web page must be running locally to a production Caddy process.) caddyhttp: CVE-2026-27588 by Asim Viladi Oglu Manizada - The Host matcher becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass. caddyhttp: CVE-2026-27587 by Asim Viladi Oglu Manizada - The Path matcher skips case normalization for escape sequences, enabling path-based route/auth bypass. caddytls: CVE-2026-27586 by @moscowchill - TLS client authentication silently fails open when CA certificate file is missing or malformed. caddyhttp: CVE-2026-27585 by @parrot409 - Improper sanitization of glob characters in file matcher may lead to bypassing security protections. 🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. (Then, turn Dependabot off .) What's Changed caddyhttp: add replacer placeholders for escaped values by @Qusic in #7181 AI assistance disclosure by @mholt in #7212 caddyfile: Prevent trailing space on line before env variable - Fixes #6881 by @arpansaha13 in #7215 add: encode header Content-Type graphql-response by @aro-lew in #7214 caddyhttp: Removing redundant middleware next copy by @maxcelant in #7217 build(deps): bump the all-updates group with 17 updates by @dependabot [bot] in #7236 build(deps): bump the actions-deps group with 5 updates by @dependabot [bot] in #7237 encode: fix response corruption when handle_errors is used by @Siomachkin in #7235 Fix PKI creation when auto_https is disabled ( #7211 ) by @Siomachkin in #7238 logging: Buffer the logs before config is loaded by @francislavoie in #7245 fileserver: set Content-Length for precompressed files by @WeidiDeng in #7251 refactor: use WaitGroup.Go to simplify code by @mickychang9 in #7253 caddyfile: Allow block to do nothing if nothing passed to import by @BeeJay28 in #7206 logging: Adjustments to BufferedLog to keep logs in the correct order by @francislavoie in #7257 caddyhttp: Prevent commas in header values from being split in CLI commands by @gilbsgilbs in #7268 update quic-go to v0.54.1 by @marten-seemann in #7273 chore: ugh, lint fix... by @mohammed90 in #7275 caddypki: check intermediate lif
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.11.0
Release v2.11.0
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-FRAMEWORK-7.0.5
⚠️ Attention Required Optimize request and response header handling in Spring MVC #36334 ⭐ New Features Consistent adaptation of HTTP headers on Servlet responses #36343 Copy methodAnnotations in MethodParameter copy constructor #36342 Improve performance of validation groups determination in WebFlux #36336 Reuse AnnotatedMethod annotation cache in derived instances #36322 Optimize the addition of a charset to the MediaType in AbstractHttpMessageConverter #36320 Optimize MediaType(MediaType, Charset) constructor #36318 Detect all common size exceptions from Tomcat and Commons FileUpload 2.x #36317 Consistently support @Autowired as a meta-annotation #36315 Avoid duplicate required attribute lookup for @Autowired annotations #36314 Cache @ResponseBody presence per controller class in RequestResponseBodyMethodProcessor #36311 🐞 Bug Fixes ResolvableType#getGenerics() breaks serialization #36346 DefaultHttpMessageConverters not adding provided configurer #36332 Restore early MessageConsumer creation for temporary queue #36321 Multipart upload leak on client abort (ByteBuf.release() not called) #36262 📔 Documentation Document that SpEL expressions using Optional with null-safe and Elvis operators are not compilable #36331 Improve documentation of baseline API version to emphasize version must be supported #36316 Stop referring to obsolete ListenableFuture in documentation #36313 Stop referring to standard Java features as "Java 8" features in documentation #36310 ❤️ Contributors Thank you to all the contributors who worked on this release: @Niravil and @TAKETODAY
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-3.5.0
Version 3.5.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.5.0 Added Add support for fields containing dots in their name as literals ( #19958 ) Add support for forward translog reading ( #20163 ) Added public getter method in SourceFieldMapper to return excluded field ( #20205 ) Add integ test for simulating node join left event when data node cluster state publication lag because the cluster applier thread being busy ( #19907 ). Relax jar hell check when extended plugins share transitive dependencies ( #20103 ) Added public getter method in SourceFieldMapper to return included field ( #20290 ) Support for HTTP/3 (server side) ( #20017 ) Add circuit breaker support for gRPC transport to prevent out-of-memory errors ( #20203 ) Add index-level-encryption support for snapshots and remote-store ( #20095 ) Adding BackWardCompatibility test for remote publication enabled cluster ( #20221 ) Support for hll field mapper to support cardinality rollups ( #20129 ) Add tracing support for StreamingRestChannel ( #20361 ) Introduce new libs/netty4 module to share common implementation between netty-based plugins and modules (transport-netty4, transport-reactor-netty4) ( #20447 ) Add validation to make crypto store settings immutable ( #20123 ) Introduce concurrent translog recovery to accelerate segment replication primary promotion ( #20251 ) Update to almalinux:10 ( #20482 ) Add X-Request-Id to uniquely identify a search request ( #19798 ) Added TopN selection logic for streaming terms aggregations ( #20481 ) Added support for Intra Segment Search ( #19704 ) Introduce AdditionalCodecs and EnginePlugin::getAdditionalCodecs hook to allow additional Codec registration ( #20411 ) Changed Handle custom metadata files in subdirectory-store ( #20157 ) Add support for missing proto fields in GRPC FunctionScore and Highlight ( #20169 ) Ensure all modules are included in INTEG_TEST testcluster distribution ( #20241 ) Cleanup HttpServerTransport.Dispatcher in Netty tests ( #20160 ) Use compact object headers with JDK25+ ( #20392 ) Add cluster.initial_cluster_manager_nodes to testClusters OVERRIDABLE_SETTINGS ( #20348 ) Add BigInteger support for unsigned_long fields in gRPC transport ( #20346 ) Install demo security information when running ./gradlew run -PinstalledPlugins="['opensearch-security']" ( #20372 ) Add Alt-Svc header support to advertise HTTP/3 availability ( #20434 ) Refactor streaming agg query phase planning ( #20471 ) Fixed Fix Snapshot rename replacement unbounded length rename ( #20464 ) Fix segment replication failure during rolling restart ( #19234 ) Fix bug of warm index: FullFileCachedIndexInput was closed error ( #20055 ) Fix flaky test ClusterMaxMergesAtOnceIT.testClusterLevelDefaultUpdatesMergePolicy ( #18056 ) Fix bug in Assertion framework(Yaml Rest test): numeric comparison fails when comparing Integer vs Long (or Float vs Double) ( #19376 ) Fix Netty deprecation warnings in transport-netty4 module ( #20233 ) Fix snapshot restore when an index sort is present ( #20284 ) Fix SearchPhaseExecutionException to properly initCause ( #20320 ) [repository-s3] remove endpointOverride and let AWS SDK V2 S3 determine the s3 url based on bucket name or arn provided ( #20345 ) Fix cluster.remote.<cluster_alias>.server_name setting no populating SNI ( #20321 ) Fix X-Opaque-Id header propagation (along with other response headers) for streaming Reactor Netty 4 transport ( #20371 ) Allow removing plugin that's optionally extended ( #20417 ) Fix indexing regression and bug fixes for grouping criteria. ( 20145 ) LeafReader should not remove SubReaderWrappers incase IndexWriter encounters a non aborting Exception ( #20193 ) Fix Netty deprecation warnings in transport-reactor-netty4 module ( 20429 ) Fix stats aggregation returning zero results with size:0 . ( 20427 ) Fix the node local term and version being truncated in logs when host providers return very long IP or host strings ( 20432 ) Remove child level
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.93.1
Don't try to recover keyword as non-keyword identifier , fixing an ICE that especially affected rustfmt . Fix clippy::panicking_unwrap false-positive on field access with implicit deref . Revert "Update wasm-related dependencies in CI" , fixing file descriptor leaks on the wasm32-wasip2 target.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.31.1
[BUGFIX] docs: Fix email TLS configuration example. #4976 [BUGFIX] docs: Add telegram bot token options to global config docs. #4999
Published Never · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-1FA2FCF071F5C9CB
CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-07-04 00:00:00
Published 10 Feb 2026 · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.15.0
1.15.0 (February 4, 2026) IMPROVEMENTS: core/hcp: add support for updating HCP Packer registry channels and bucket log UI metadata. GH-13532 build: update Go to 1.24.12. GH-13553 docker: remove vmware and vsphere from the packer full image. GH-13442 docs: add comments to packer docs. GH-13534 compliance: update copyright and license headers. GH-13540 GH-13543 GH-13545 GH-13544 BUG FIXES: datasource/http: update acceptance test URL to avoid rate limiting. GH-13480 provisioner/powershell: ensure LASTEXITCODE is set before checking its value in tests. GH-13539 SECURITY: Bump golang.org/x/crypto to 0.46.0 GH-13546
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.11.0-BETA.2
Welcome to the second beta version of 2.11. We are closer to a final release. This includes some minor new features and enhancements, and a fix for the ZeroSSL API issuer. Thank you to everyone who contributed! Changelog 8a87bb3 build(deps): bump github.com/smallstep/certificates ( #7381 ) 7b031e1 build(deps): bump the all-updates group across 1 directory with 12 updates ( #7421 ) be5f49f caddyhttp: Fix logging on wildcard sites when SkipUnmappedHosts is true ( #7372 ) 6e0cbd0 caddyhttp: create a placeholder for and log ech status ( #7328 ) 4037d05 caddyhttp: {http.request.body_base64} placeholder ( #7367 ) 7ebe72b caddypki: Add support for multiple intermediates in signing chain ( #7057 ) 3c9c67e caddytls: ECH key rotation ( #7356 ) 374b7a6 caddytls: fix preferred chains options by appending values instead of replacing ( #7387 ) 6a4296b caddytls: panic when using tls.ca_pool.source.http -> tls.ca ( #7393 ) 9eabd44 cmd: Add --json flag to list-modules command ( #7409 ) b2d21f6 go.mod: Upgrade CertMagic and ZeroSSL deps 34fd2df go.mod: update tscert package to latest (aea342f6) ( #7397 ) decc8a4 logging: log_append Early option, Supports {http.response.body} ( #7368 ) 409a072 notify: implement windows service status and error notifications ( #7389 ) 1f1be3f tracing: Add span attributes to tracing module ( #7269 ) What's Changed build(deps): bump github.com/smallstep/certificates from 0.28.4 to 0.29.0 by @dependabot [bot] in #7381 caddypki: Add support for multiple intermediates in signing chain by @hslatman in #7057 caddyhttp: Fix logging on wildcard sites when SkipUnmappedHosts is true by @francislavoie in #7372 multiplexing: Introduce packet conn wrappers by @vnxme in #7180 docs: add maybe template function documentation by @steffenbusch in #7388 caddyhttp: create a placeholder for and log ech status by @WeidiDeng in #7328 caddytls: fix preferred chains options by appending values instead of replacing by @okrc in #7387 feat: mark Assert* functions as test helpers by @dunglas in #7380 caddytls: ECH key rotation by @mholt in #7356 caddytls: panic when using tls.ca_pool.source.http -> tls.ca by @Zenexer in #7393 notify: implement windows service status and error notifications by @FreyreCorona in #7389 caddyhttp: {http.request.body_base64} placeholder by @francislavoie in #7367 chore: update tscert package to latest (aea342f6) by @willnorris in #7397 logging: log_append Early option, Supports {http.response.body} by @francislavoie in #7368 update quic-go to v0.58.0 by @marten-seemann in #7404 cmd: add --json flag to list-modules by @pauloappbr in #7409 Add span attributes to tracing module by @felix-hilden in #7269 readme: fix fence by @mohammed90 in #7416 build(deps): bump the all-updates group across 1 directory with 12 updates by @dependabot [bot] in #7421 New Contributors @okrc made their first contribution in #7387 @Zenexer made their first contribution in #7393 @FreyreCorona made their first contribution in #7389 @pauloappbr made their first contribution in #7409 @felix-hilden made their first contribution in #7269 Full Changelog : v2.11.0-beta.1...v2.11.0-beta.2
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-3.4.0
Version 3.4.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.4.0 Added Allow setting index.creation_date on index creation and restore for plugin compatibility and migrations ( #19931 ) Add support for a ForkJoinPool type ( #19008 ) Add seperate shard limit validation for local and remote indices ( #19532 ) Use Lucene pack method for half_float and unsigned_long when using ApproximatePointRangeQuery ( #19553 ) New cluster setting search.query.max_query_string_length_monitor_only ( #19539 ) Add a mapper for context aware segments grouping criteria ( #19233 ) Return full error for GRPC error response ( #19568 ) Add support for repository with Server side encryption enabled and client side encryption as well based on a flag ( #19630 ) Add pluggable gRPC interceptors with explicit ordering( #19005 ) Add BindableServices extension point to transport-grpc-spi ( #19304 ) Add metrics for the merged segment warmer feature ( #18929 ) Handle deleted documents for filter rewrite sub-aggregation optimization ( #19643 ) Add bulk collect API for filter rewrite sub-aggregation optimization ( #19933 ) Allow collectors take advantage of preaggregated data using collectRange API ( #20009 ) Bulk collection logic for metrics and cardinality aggregations ( #20067 ) Add pointer based lag metric in pull-based ingestion ( #19635 ) Introduced internal API for retrieving metadata about requested indices from transport actions ( #18523 ) Add cluster defaults for merge autoThrottle, maxMergeThreads, and maxMergeCount; Add segment size filter to the merged segment warmer ( #19629 ) Add build-tooling to run in FIPS environment ( #18921 ) Add SMILE/CBOR/YAML document format support to Bulk GRPC endpoint ( #19744 ) Make test-suite runnable under FIPS compliance support ( #18491 ) Implement GRPC Search params Highlight and Sort ( #19868 ) Implement GRPC ConstantScoreQuery, FuzzyQuery, MatchBoolPrefixQuery, MatchPhrasePrefix, PrefixQuery, MatchQuery ( #19854 ) Add async periodic flush task support for pull-based ingestion ( #19878 ) Add support for context aware segments ( #19098 ) Implement GRPC FunctionScoreQuery ( #19888 ) Implement error_trace parameter for bulk requests ( #19985 ) Allow the truncate filter in normalizers ( #19778 ) Support pull-based ingestion message mappers and raw payload support ( #19765 ) Add search API tracker ( #18601 ) Support dynamic consumer configuration update in pull-based ingestion ( #19963 ) Cache the StoredFieldsReader for scroll query optimization ( #20112 ) Add Hybrid Cardinality collector to prioritize Ordinals Collector ( #19524 ) Changed Combining filter rewrite and skip list to optimize sub aggregation( #19573 ) Faster terms query creation for keyword field with index and docValues enabled ( #19350 ) Refactor to move prepareIndex and prepareDelete methods to Engine class ( #19551 ) Omit maxScoreCollector in SimpleTopDocsCollectorContext when concurrent segment search enabled ( #19584 ) Onboarding new maven snapshots publishing to s3 ( #19619 ) Remove MultiCollectorWrapper and use MultiCollector in Lucene instead ( #19595 ) Change implementation for percentiles aggregation for latency improvement ( #19648 ) Wrap checked exceptions in painless.DefBootstrap to support JDK-25 ( #19706 ) Refactor the ThreadPoolStats.Stats class to use the Builder pattern instead of constructors ( #19317 ) Refactor the IndexingStats.Stats class to use the Builder pattern instead of constructors ( #19306 ) Remove FeatureFlag.MERGED_SEGMENT_WARMER_EXPERIMENTAL_FLAG. ( #19715 ) Replace java.security.AccessController with org.opensearch.secure_sm.AccessController in sub projects with SocketAccess class ( #19803 ) Replace java.security.AccessController with org.opensearch.secure_sm.AccessController in discovery plugins ( #19802 ) Change the default value of doc_values in WildcardFieldMapper to true. ( #19796 ) Make Engine#loadHistoryUUID() protected and Origin#isFromTranslog() public ( #19753 ) Bump opensearch-proto
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.66
2.4.66
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.11.0-BETA.1
Welcome to the beta version of 2.11. This is the first release made by our new, automated release process developed by @mohammed90 that was carried out and approved entirely by our maintainer team (together with @francislavoie ) without intervention from @mholt , the original Caddy author. This represents a significant step forward in project autonomy and growth , ensuring that the project's stability and longevity is not reliant upon a single person. This first beta release was primarily to test our new workflow, so there's still a couple things left to do before the stable release. Featured here are numerous, mostly minor, bug fixes and enhancements, mostly affecting edge cases or niche corners of the software; for example, proxying H2C or HTTP/3, obscure Caddyfile scenarios, and named socket activation. Some notable changes: SIGUSR1 can be used to reload configuration only if it was loaded from a file using the CLI, and not changed by the API since then. We replaced "lumberjack", our logging library, with a fork "timberjack" that supports the oft-requested time-rolling ability. Caddy can now bind listeners with named socket activation. Before the final release, we expect ECH key rotation to be enabled as well as a few other patches/features Thank you to our sponsors and contributors for all that you do! Changelog 5473eb9 encode: fix response corruption when handle_errors is used ( #7235 ) 13a4ec7 basicauth: Implement argon2id ( #7186 ) 6d90c77 build(deps): bump github.com/slackhq/nebula from 1.9.5 to 1.9.7 ( #7315 ) eead249 build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 ( #7355 ) 2d0f3f8 build(deps): bump the actions-deps group with 5 updates ( #7237 ) afbdcec build(deps): bump the actions-deps group with 8 updates ( #7284 ) cd1c203 build(deps): bump the all-updates group across 1 directory with 2 updates ( #7307 ) 39357d3 build(deps): bump the all-updates group with 17 updates ( #7236 ) 786d537 build(deps): bump the all-updates group with 3 updates ( #7376 ) 07d2aaf build(deps): bump the all-updates group with 4 updates ( #7333 ) 0ba8786 caddyfile: Allow block to do nothing if nothing passed to import ( #7206 ) 92c8bc7 caddyfile: fix nested quotes formatted incorrectly by fmt ( #7045 ) 6d73d85 caddyfile: prevent adding trailing space on line before env variable ( #7215 ) d7185fd caddyhttp: Add trusted_proxies_unix for trusting unix socket X-Forwarded-* headers ( #7265 ) de6b780 caddyhttp: Add server options keepalive_idle and keepalive_count ( #7298 ) e0a8f95 caddyhttp: Normalize (lowercase) {label.N} placeholders 5e29536 caddyhttp: add replacer placeholders for escaped values ( #7181 ) 8285eba caddyhttp: allow customizing the Server header ( #7338 ) bc0e184 caddyhttp: omit unnecessary reassignment ( #7276 ) 3553cfb caddyhttp: remove redundant middleware next copy ( #7217 ) 1ce2a13 caddyhttp: wrap accepted connection to suppress tls.ConnectionState ( #7247 ) d9cc24f caddypki: Disable internal auto-CA when auto_https is disabled (fix #7211 ) ( #7238 ) 1e82f96 caddypki: check intermediate lifetime to actual root cert lifetime ( #7272 ) 38848f7 caddytls: Allow disabling distributed solving (except http-01) ddec183 caddytls: correct documentation of LeafFolderLoader ( #7327 ) f5c3094 cmd: prevent commas in header values from being split ( #7268 ) 65e0ddc core: Reloading with SIGUSR1 if config never changed via admin ( #7258 ) b3f2db2 core: custom slog handlers for modules (log contextual data) ( #7346 ) b2ab419 core: use reflect.TypeFor to check for encoding/json.RawMessage ( #7274 ) 806fef8 encode: add graphql-response header to list ( #7214 ) 2cb4267 encode: modernize, replace HasSuffix+TrimSuffix with CutSuffix ( #7357 ) b462615 fileserver: set Content-Length for precompressed files ( #7251 ) 0c8798f go.mod: update quic-go to v0.54.1 ( #7273 ) 3c003de httpcaddyfile: Add missing DNS challenge check for acme_dns ( #7270 ) 2f1d270 httpcaddyfile: Map default_bind to BindHost in globalACMEDefaults ( #7278 ) a7885aa
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.66-RC1-CANDIDATE
2.4.66-rc1-candidate
Published Never · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-EF96459F0904C3EF
CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00
Published 18 Nov 2025 · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.14.3
1.14.3 (November 18, 2025) IMPROVEMENTS: core/hcp: added cicd metadata support for BitBucket and Jenkins pipelines. GH-13513 GH-13505 core: bump github.com/hashicorp/packer-plugin-sdk to 0.6.4 GH-13494 docs: fix typos and linguistic errors in documentation. GH-13496 SECURITY: Bump golang.org/x/crypto to 0.43.0 GH-13518
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-2.19.4
Version 2.19.4 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 2.19.4 Added New cluster setting search.query.max_query_string_length ( #19491 ) Dependencies Bump Apache Lucene to 9.12.3 ( #19444 ) Bump org.bouncycastle:bc-fips from 2.0.0 to 2.1.2 ( #19155 ) Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 ( #19155 ) Bump org.bouncycastle:bcprov-jdk18on from 1.78 to 1.79 ( #19155 ) Bump org.bouncycastle:bcmail-jdk18on from 1.78 to 1.79 ( #19155 ) Bump org.bouncycastle:bcpkix-jdk18on from 1.78 to 1.79 ( #19155 ) Bump org.apache.tika from 2.9.2 to 3.2.2 ( #19242 ) Bump org.apache.commons:commons-compress from 1.26.1 to 1.28.0 ( #19125 ) Bump org.apache.commons:commonscodec from 1.16.1 to 1.18.0 ( #19125 ) Replace commons-lang:commons-lang with org.apache.commons:commons-lang3 ( #19229 ) Bump netty from 4.1.121.Final to 4.1.125.Final ( #19270 ) Bump bouncycastle from 1.79 to 1.82 ( #19552 ) Bump org.ajoberstar.grgit:grgit-core from 5.2.1 to 5.3.2 ( #19606 ) Bump reactor-netty from 1.1.23 to 1.2.9 ( #19603 ) Bump reactor from 3.5.20 to 3.7.5 ( #19603 ) Bump org.apache.hadoop:hadoop-minicluster from 3.4.1 to 3.4.2 ( #19605 ) Bump io.grpc deps from 1.68.2 to 1.75.0 ( #19495 ) Bump com.nimbusds:nimbus-jose-jwt from 10.0.2 to 10.3 ( #19604 ) Exclude commons-lang and org.jsonschema2pojo from hadoop-miniclusters ( #19538 ) Fixed Add task cancellation checks in aggregators ( #18426 ) Fix OOM due to large number of shard result buffering ( #19066 ) Fix QueryPhaseResultConsumer incomplete callback loops ( #19231 ) Use ScoreDoc instead of FieldDoc when creating TopScoreDocCollectorManager to avoid unnecessary conversion ( #18802 ) Fix IndexOutOfBoundsException when running include/exclude on non-existent prefix in terms aggregations ( #19637 ) Changed Replace centos:8 with almalinux:8 since centos docker images are deprecated ( #19154 ) Allow plugins to copy folders into their config dir during installation ( #19343 ) Onboarding new maven snapshots publishing to s3 ( #19632 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-3.3.2
Version 3.3.2 Release Notes Compatible with OpenSearch 3.3.2 and OpenSearch Dashboards 3.3.0 Fixed [Star Tree] Fix sub-aggregator casting for search with profile=true ( #19652 ) [Java Agent] Allow JRT protocol URLs in protection domain extraction ( #19683 ) Fix bwc @timestamp upgrade issue by adding a version check on skip_list param ( #19671 ) Fix issue with updating core with a patch number other than 0 ( #19377 ) Fix IndexOutOfBoundsException when running include/exclude on non-existent prefix in terms aggregations ( #19637 ) Add S3Repository.LEGACY_MD5_CHECKSUM_CALCULATION to list of repository-s3 settings ( #19789 ) Dependencies Bump ch.qos.logback modules from 1.5.18 to 1.5.20 in HDFS test fixture ( #19764 ) Bump org.bouncycastle:bc-fips from 2.1.1 to 2.1.2 ( #19817 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-3.3.1
Version 3.3.1 Release Notes OpenSearch 3.3.1 Only. Fixed Fix issue with updating core with a patch number other than 0 ( #19377 ) [Star Tree] Fix sub-aggregator casting for search with profile=true ( #19652 ) Fix bwc @timestamp upgrade issue by adding a version check on skip_list param ( #19671 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-019E0DB0868B09EA
CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00
Published 14 Oct 2025 · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.14.2
1.14.2 (September 9, 2025) ✨ Features HCP Certificate Authentication Support – by @JenGoldstrich ( #13435 ) Adds support for the HCP_CRED_FILE environment variable and removes restrictions on HCP_CLIENT_ID and HCP_CLIENT_SECRET when connecting builds to an HCP Packer registry. Upgrade Node.js to v22 – by @LeahMarieBush ( #13450 ) Updates the Node.js version used for Packer website builds. 🐛 Bug Fixes fix(winrm): catch cmd err from winrm – by @anurag5sh in ( #298 ) Improved reliability by catching WinRM remote shell failures during provisioning PowerShell wrapper cleanup – by @kp2099 ( #13451 ) Removed the unused $result variable from the wrapper string. fix tests for shell and shell-local – by @kp2099 in ( #300 ) Acceptance test fixes for shell and shell-local 🛠 Improvements Added workflow-dispatch and set PACKER_ACC_BUILDERS for acceptance tests – by @kp2099 ( #13444 ) Improved spacing in hcl2template error messages – by @sbraz ( #13453 ) Added callouts for HashiCorp-maintained plugins moving to releases.hashicorp.com – by @BrianMMcClain ( #13438 ) 📦 Dependencies Bump github.com/ulikunitz/xz from 0.5.10 → 0.5.14 – by @dependabot ( #13459 ) Bump golang.org/x/oauth2 from 0.13.0 → 0.27.0 – by @dependabot ( #13460 ) Bump github.com/ulikunitz/xz from 0.5.10 → 0.5.15 – by @kp2099 ( #13461 ) Bump github.com/hashicorp/packer-plugin-sdk from 0.6.2 → 0.6.3 – by @kp2099 ( #13462 ) 👩💻 New Contributors @LeahMarieBush made their first contribution in #13450 🎉
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.10.2
This is a hotfix release to fix a couple critical issues from v2.10.1 What's Changed http: Make logger first, before TLS provisioning by @francislavoie in #7198 httpcaddyfile: Fix acme_dns regression by @francislavoie in #7199 caddyfile: Fix importing nested tokens for {block} by @BeeJay28 in #7189 Changelog 551f793 caddyfile: Fix importing nested tokens for {block} ( #7189 ) 16fe83c http: Make logger first, before TLS provisioning ( #7198 ) 4564261 httpcaddyfile: Fix acme_dns regression ( #7199 ) New Contributors @BeeJay28 made their first contribution in #7189 Full Changelog : v2.10.1...v2.10.2
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.10.1
This is probably our biggest patch release ever -- not that lots of things were broken, but there's lots of refinement happening thanks to broader adoption and contributions from many more people. Just look at the New Contributors below! Anyway, this release does contain some bug fixes and dependency upgrades which we hope will serve you well. Let us know if there's any issues! And thank you to all who contributed, especially our reliable maintainer team! This version of Caddy requires Go v1.25.0 or newer . What's Changed update quic-go to v0.51.0 by @marten-seemann in #6972 forwardproxy: reference correct field name in LoadModule by @mohammed90 in #6978 fix: Remove nil arg from zapslog.NewHandler call by @IndraGunawan in #6984 fileserver: Add support for .avif image format by @steffenbusch in #6988 reverseproxy: use DialTLSContext for TLS if servername has placeholder by @WeidiDeng in #6955 admin: Make sure that any admin routers are provisioned when local/re… by @Compy in #6997 log: default logger should respect {in,ex}clude by @mohammed90 in #6995 Move local admin server replacement logic below data structure initia… by @Compy in #7004 acme_server: fix policy parsing in caddyfile by @mohammed90 in #7006 implement Unwrap for interceptedResponseHandler by @WeidiDeng in #7016 fileserver: map invalid path errors to fs.ErrInvalid, and return 400 … by @Compy in #7017 caddyhttp: fix route sort by comparing paths without wildcard if they don't shar… by @WeidiDeng in #7015 refactor: use maps.Copy for cleaner map handling by @eveneast in #7009 refactor: use slices.Contains to simplify code by @tongjicoder in #7039 chore: upgrade .golangci.yml and workflow to v2 by @mohammed90 in #6924 build(deps): bump golangci/golangci-lint-action from 6 to 8 by @dependabot [bot] in #7044 fix: crash - null check on event origin by @suxatcode in #7047 fix: prevent error handler from overriding sub handler matchers by @Hellio404 in #6999 client_auth: wire up leaf verifier Caddyfile by @mohammed90 in #6772 caddyfile: reject blocks in log_skip directive by @IwatsukaYura in #7056 build(deps): bump github.com/cloudflare/circl from 1.6.0 to 1.6.1 by @dependabot [bot] in #7058 cmd: fix Commands function not returning all registered commands by @hslatman in #7059 ci: add dep review, OSSF scorecard actions by @mohammed90 in #7063 ci: add {base,head}-ref to dep review check by @mohammed90 in #7064 core: clean up new config if it failed to run by @WeidiDeng in #7068 chore: apply security best practices for CI by @mohammed90 in #7066 refactor: use the built-in max/min to simplify the code by @xiaoxiangirl in #7081 [ADD] sort buttons in grid mode by @filipRatajczak in #7089 update quic-go to v0.53.0 by @marten-seemann in #7094 refactor: replace HasPrefix+TrimPrefix with CutPrefix by @gopherorg in #7095 docs: fix some minor issues in the comments by @mountdisk in #7101 httpcaddyfile: Validates TLS DNS challenge options by @francislavoie in #7099 chore: fix struct name in comment by @bytetigers in #7114 reverse proxy: validate versions in http transport by @WeidiDeng in #7112 chore: fix function in comment by @bytesingsong in #7121 Fix: Support placeholders in header replacement search patterns by @zongzewu23 in #7117 fileserver: specify license for embedded JavaScript by @infertux in #7127 fix dead link by @eeemmmmmm in #7136 update quic-go to v0.54.0 by @marten-seemann in #7138 chore: fix minor issue in comment by @pingshuijie in #7140 refactor: use slices.Equal to simplify code by @minxinyi in #7141 ci: reduce dependabot spam by @mohammed90 in #7078 fix(provisioning): Context.App or Context.AppIfConfigured will return (val, nil) even if the app failed to provision or validate the first time by @alexandre-daubois in #7070 build(deps): bump the actions-deps group with 6 updates by @dependabot [bot] in #7142 Use KeepAliveConfig to pass keepalive_interval to listener's accepted sockets by @joshuamcbeth in #7151 build(deps): bump the all-updates group across 1 direct
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.65
2.4.65
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.65-RC2-CANDIDATE
2.4.65-rc2-candidate
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-HTTP-SERVER-2.4.65-RC3-CANDIDATE
2.4.65-rc3-candidate
Published Never · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-56B549B86F685129
CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL. Revised on 2026-06-15 00:00:00
Published 10 Jun 2025 · Source checked 29 Sep 2026
Release notes and known issues →CADDYCADDY-2.10.0
Caddy 2.10 is here! Aside from bug fixes, this release features: Encrypted ClientHello (ECH): This new technology encrypts the last plaintext portion of a TLS connection: the ClientHello, which includes the domain name being connected to. The draft spec for ECH is almost finalized, so we can now support this privacy feature for TLS. This is a powerful but nuanced capability; we highly recommend reading the ECH documentation on our website. Post-quantum (PQC) key exchange: Caddy now supports the standardized x25519mlkem768 cryptographic group by default. ACME profiles: ACME profiles are an experimental draft that allow you to choose properties of your certificates with more flexibility than traditional CSR methods. For example, Let's Encrypt will issue 6-day certificates under a certain profile. Caddy may eventually use that profile by default. Via header: The reverse proxy now sets a Via header instead of a duplicate Server header. Global DNS provider: You can now specify a default "global" DNS module to use instead of having to configure it locally in every part of your config that requires a DNS provider (for example, ACME DNS challenges, and ECH). This is the dns global option in the Caddyfile, or in JSON config, it's the dns parameter in the tls app configuration. Wildcards used by default: Previously, Caddy would obtain individual certificates for every domain in your config literally; now wildcards, if present, will be utilized for subdomains, rather than obtaining individual certificates. This change was motivated by the novel possibility for subdomain privacy afforded by ECH. It can be overridden with tls force_automate in the Caddyfile. The experimental auto_https prefer_wildcard option has been removed. libdns 1.0 APIs: Many of you use DNS provider modules to solve ACME DNS challenges or to enable dynamic DNS. They implement interfaces defined by libdns to get, set, append, and delete DNS records. After 5 years of production experience, including lessons learned with ECH, libdns APIs have been updated and 1.0 beta has been tagged. DNS provider packages will need to update their code to be compatible, which will help ensure stability and well-defined semantics for the future. Several packages have already updated or are in the process of updating (cloudflare, rfc2136, and desec to name a few). Global dns config: Now that several components of Caddy configuration may affect DNS records (ACME challenges, ECH publication, etc.), there is a new dns global option that can be used to specify your DNS provider config in a single place. This prevents repetition of credentials for servers where all the domains are managed by a single DNS provider. Thank you to the many contributors who have helped to make this possible! 🎉 🥳 🍾 ⚠️ While have traditionally supported the last 2 minor Go versions to accommodate some distribution / package manager policies, we now only support the latest minor Go version. The privacy and security benefits added in new Go versions (such as post-quantum cryptography) are worth making available to everyone as soon as possible, rather than holding back the entire user base or maintaining multiple code compilation configurations. Encrypted ClientHello (ECH) details (This is a brief overview. We recommend reading the full documentation .) Typically, server names (domain names, or "SNI") are sent in the plaintext ClientHello when establishing TLS connections. With ECH, the true server name is encrypted (and wrapped) by an "outer" ClientHello which has a generic SNI of your choosing. With many sites on the same server sharing the same outer SNI, both clients and the server have more privacy related to domain names. Caddy implements fully automated ECH, meaning that it generates (and soon , rotates), publishes, and serves ECH configurations simply by specifying a DNS provider, and the outer/public domain name to use. Fully automated ECH requires a DNS module built into your Caddy binary. In order for a clien
Published Never · Source checked 29 Sep 2026
Release notes and known issues →FORTINETCVE-2025-26466
CVSSv3 Score: 5.9 CVE-2025-26466A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack. Revised on 2026-05-25 00:00:00
Published 11 Mar 2025 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-D5DB43C5852EC433
CVSSv3 Score: 7.5 A security advisory was released affecting the version of OpenSSL library used in some Fortinet products:CVE-2022-0778:The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters.Thus vulnerable situations include:TLS clients consuming server certificatesTLS servers consuming client certificatesHosting providers taking certificates or private keys from customersCertificate authorities parsing certification requests from subscribersAnything else which parses ASN.1 elliptic curve parametersAlso any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue.In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature.This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022.Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc). Revised on 2026-08-27 00:00:00
Published 1 Apr 2022 · Source checked 29 Sep 2026
Release notes and known issues →