Portainer 2.39.4

2.39.4

Release 2.39.4 LTS

Added 1
  • Add an API endpoint to refresh Team/Group membership for a user
Changed 1
  • Replace docker binary with libstack
Fixed 6
  • Fix an issue where users with no environment access are able to enumerate Kubernetes resources
  • Fix ecr token pre-validation error with warning log
  • Fix the way a standard user could not redeploy team stack or delete registry image
  • Fix the restore endpoint allowing admin takeover for uninitialised Portainer instances
  • Fix link on timed out page
  • Fix the volume label dropdown becoming blank
Security 2
  • Bump go-git to 5.19.1 to address CVE-2026-45570, CVE-2026-45571, and GHSA-w5pp-99ch-qj29
  • Bump go stdlib to 1.25.11 to remediate multiple stdlib CVEs including CVE-2026-42504, CVE-2026-27145, CVE-2026-42499, CVE-2026-39836, CVE-2026-39820, CVE-2026-33814, CVE-2026-33811, CVE-2026-39826, CVE-2026-39823, CVE-2026-39825, and CVE-2026-42507
Known issues
  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations
Known issues with Podman support
  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful
Changes
  • Added an API endpoint to refresh Team/Group membership for a user
  • Fixed an issue where users with no environment access are able to enumerate Kubernetes resources
  • Fixed ecr token pre-validation error with warning log
  • Fixed the way a standard user could not redeploy team stack or delete registry image
  • Fixed the restore endpoint allowing admin takeover for uninitialised Portainer instances
  • Fixed link on timed out page
  • Replaced docker binary with libstack
  • Fixed the volume label dropdown becoming blank
  • Bump go-git to 5.19.1 to address the following CVEs:
    • CVE-2026-45570
    • CVE-2026-45571
    • GHSA-w5pp-99ch-qj29
  • Bumped go stdlib to 1.25.11 to remediate the following stdlib CVEs:
    • CVE-2026-42504
    • CVE-2026-27145
    • CVE-2026-42499
    • CVE-2026-39836
    • CVE-2026-39820
    • CVE-2026-33814
    • CVE-2026-33811
    • CVE-2026-39826
    • CVE-2026-39823
    • CVE-2026-39825
    • CVE-2026-42504
    • CVE-2026-27145
    • CVE-2026-42507
Deprecated and removed features
Deprecated features

None

Removed features

None

View original

Upgraded? How did it go?

Discussion