# Portainer 2.45.0 — Release 2.45.0 LTS - Product: Portainer (https://whatsnew.fyi/product/portainer) - Vendor: Portainer - Date: 2026-08-27 - Version: 2.45.0 - Original notes: https://github.com/portainer/portainer/releases/tag/2.45.0 - Permalink: https://whatsnew.fyi/product/portainer/releases/2.45.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Advanced Kubernetes node drain options with agent failover - **added** — Native Portainer APIs for writing Kubernetes secrets, configmaps, deployments and persistent volume claims, replacing direct kube-apiserver proxy calls - **added** — Generic Kubernetes manifest dry-run API - **added** — Edge Compute settings can be configured during initial setup and via cli flags - **changed** — Authentication events now record the real client IP from X-Forwarded-For when the request comes through a trusted proxy - **changed** — The namespace YAML tab now shows every resource quota in the namespace - **added** — GetCharts() support to the async Edge agent, so chart data syncs on agent startup - **changed** — Edge agent connectivity checks now report progress while probing, and wait longer before failing - **changed** — Creating a git source now skips the source type selection step - **changed** — The source form now explains git polling versus webhook triggers, and exposes the polling interval setting that was missing from the UI - **removed** — The redundant single-tab handle from the workflow details view - **changed** — Registry creation tooltip reworded to make the default behaviour obvious - **changed** — Clarified that Portainer supports Podman through its Docker-compatible API only - **security** — Fixed a critical Docker proxy authorization bypass where unrecognised API version prefixes like /v1.47.0/ or /v01.47/ skipped access control entirely - **security** — Closed a remaining gap in the CVE-2026-44849 fix and broadened bind-mount restrictions for non-admin users, now including Compose and Swarm stack deployments - **security** — Single-namespace Kubernetes endpoints now check the caller's namespace authorization instead of running as admin - **security** — Read-only and Helpdesk users can no longer view Kubernetes secret data - **security** — Standard users can no longer manage registry access ##### Known issues - On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot ###### Known issues with Podman support - Podman environments aren't supported by auto-onboarding script - It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa) - Support for only CentOS 9, Podman 5 rootful ##### Changes ###### New and improved features - Added advanced Kubernetes node drain options with agent failover - Added native Portainer APIs for writing Kubernetes secrets, configmaps, deployments and persistent volume claims, replacing direct kube-apiserver proxy calls - Added a generic Kubernetes manifest dry-run API - Edge Compute settings can now be configured during initial setup and via cli flags - Authentication events now record the real client IP from X-Forwarded-For when the request comes through a trusted proxy - The namespace YAML tab now shows every resource quota in the namespace - Added GetCharts() support to the async Edge agent, so chart data syncs on agent startup - Edge agent connectivity checks now report progress while probing, and wait longer before failing - Creating a git source now skips the source type selection step - The source form now explains git polling versus webhook triggers, and exposes the polling interval setting that was missing from the UI - Removed the redundant single-tab handle from the workflow details view - Reworded the registry creation tooltip to make the default behaviour obvious - Clarified that Portainer supports Podman through its Docker-compatible API only ###### Security improvements - Fixed a critical Docker proxy authorization bypass. Unrecognised API version prefixes like /v1.47.0/ or /v01.47/ skipped access control entirely, letting non-admin users reach the Docker API directly - Closed a remaining gap in the CVE-2026-44849 (GHSA-5fxq-qcf3-244w) fix and broadened bind-mount restrictions for non-admin users, now including Compose and Swarm stack deployments - Single-namespace Kubernetes endpoints now check the caller’s namespace authorization instead of running as admin - Read-only and Helpdesk users can no longer view Kubernetes secret data - Standard users can no longer manage registry access - Kubernetes authorization denials now return HTTP 403 instead of 500 - Fixed a Kubernetes shell authorization flaw. Caller-supplied query parameters could override the server's pod target, letting a standard user run commands in any pod on Agent-managed Kubernetes environments - Updated the Go toolchain to 1.26.6, fixing CVE-2026-39821 (Critical, 9.6), an IDNA validation bypass of hostname-based access controls, along with CVE-2026-42505, CVE-2026-39822, CVE-2026-56862, CVE-2026-56860, CVE-2026-56859, CVE-2026-56858, CVE-2026-56853, CVE-2026-46600 and CVE-2026-33818 - Updated oras.land/oras-go/v2 to 2.6.2, fixing CVE-2026-50163 - Updated github.com/go-git/go-git/v5 to 5.19.2, fixing CVE-2026-71556 and CVE-2026-71557 - Updated go.opentelemetry.io/otel to 1.44.0, fixing CVE-2026-41178 - Updated github.com/klauspost/compress to 1.18.7, fixing GHSA-259r-337f-4rfw - Upgraded libcurl to 8.21.0-r0 in the kubectl-shell image to address the following CVEs: CVE-2026-11856, CVE-2026-10536, CVE-2026-11564, CVE-2026-12064, CVE-2026-11586, CVE-2026-11352, CVE-2026-9547, CVE-2026-9546, CVE-2026-9545, CVE-2026-9080, CVE-2026-9079, CVE-2026-8932, CVE-2026-8927, CVE-2026-8926, CVE-2026-8925, CVE-2026-8924, CVE-2026-8458, and CVE-2026-8286. - Upgraded c-ares to 1.34.8-r0 in the kubectl-shell image to address CVE-2026-33630 ###### Bug fixes - Removing a stack now uninstalls the underlying Helm release, which used to be left running - Fixed Edge stack workloads staying up after deletion on Kubernetes. The entry file and namespace are now sent on removal - Fixed collisions during Edge stack removal and reassignment. The old stack is now removed before the n _[Truncated at 4000 characters — full notes: https://github.com/portainer/portainer/releases/tag/2.45.0]_