2.39.4
Release 2.39.4 LTS
Added 1
- Add an API endpoint to refresh Team/Group membership for a user
Changed 1
- Replace docker binary with libstack
Fixed 6
- Fix an issue where users with no environment access are able to enumerate Kubernetes resources
- Fix ecr token pre-validation error with warning log
- Fix the way a standard user could not redeploy team stack or delete registry image
- Fix the restore endpoint allowing admin takeover for uninitialised Portainer instances
- Fix link on timed out page
- Fix the volume label dropdown becoming blank
Security 2
- Bump go-git to 5.19.1 to address CVE-2026-45570, CVE-2026-45571, and GHSA-w5pp-99ch-qj29
- Bump go stdlib to 1.25.11 to remediate multiple stdlib CVEs including CVE-2026-42504, CVE-2026-27145, CVE-2026-42499, CVE-2026-39836, CVE-2026-39820, CVE-2026-33814, CVE-2026-33811, CVE-2026-39826, CVE-2026-39823, CVE-2026-39825, and CVE-2026-42507
Known issues
- On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
- kubectl port-forward fails with Portainer kubeconfig in some configurations
Known issues with Podman support
- Podman environments aren't supported by auto-onboarding script
- It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
- Support for only CentOS 9, Podman 5 rootful
Changes
- Added an API endpoint to refresh Team/Group membership for a user
- Fixed an issue where users with no environment access are able to enumerate Kubernetes resources
- Fixed ecr token pre-validation error with warning log
- Fixed the way a standard user could not redeploy team stack or delete registry image
- Fixed the restore endpoint allowing admin takeover for uninitialised Portainer instances
- Fixed link on timed out page
- Replaced docker binary with libstack
- Fixed the volume label dropdown becoming blank
- Bump go-git to 5.19.1 to address the following CVEs:
- CVE-2026-45570
- CVE-2026-45571
- GHSA-w5pp-99ch-qj29
- Bumped go stdlib to 1.25.11 to remediate the following stdlib CVEs:
- CVE-2026-42504
- CVE-2026-27145
- CVE-2026-42499
- CVE-2026-39836
- CVE-2026-39820
- CVE-2026-33814
- CVE-2026-33811
- CVE-2026-39826
- CVE-2026-39823
- CVE-2026-39825
- CVE-2026-42504
- CVE-2026-27145
- CVE-2026-42507
Deprecated and removed features
Deprecated features
None
Removed features
None