Security updates

The newest releases whose notes mention a security fix, as tagged by our normalization of each vendor’s changelog. Follow along in your reader with the RSS feed.

Latest security updates

Gumroad

Gumroad · Productivity

Stop 500ing Stripe Connect callback when OAuth referer is missing; Stop 500ing product review pages past the last page; Clamp buffered Gumhead maxtokens to the timeout-window…

ChangedFixedSecurity

node-hdb

node-hdb · Frameworks & Libraries

Keep extra space for potential client info updates; Override diff to 8.0.4 to address GHSA-73rr-hh4g-fpgx; Fix GHSA-3jxr-9vmj-r5cp and GHSA-52cp-r559-cp3m

FixedSecurity

Turborepo

Vercel · Developer Tools

Support nub.lock files; Walk the repository once when pruning; Upgrade js-yaml to 4.3.1 (GHSA-5p4m-2wfm-xmqj); Add Eve operator dashboard; Rotate Eve example maintenance daily…

AddedChangedFixedSecurity

pi

pi · AI

Add fullscreen transcript search with Ctrl+Shift+F, incremental match highlighting, configurable search match theme colors, and next/previous navigation with Enter/Ctrl+G and…

AddedChangedFixedSecurity

gstack

gstack · Developer Tools

Enforcement guards /freeze, /careful, and team-init required mode now block requests; /careful now parses tool payload with real JSON parser and handles quoted arguments; /careful…

AddedChangedFixedSecurity
SourceAI extracted

1Password CLI

AgileBits · Security & Privacy

Debug output now includes per-request timing; Debug output now reports more information when a vault cannot be read; Reporting item usage for cached items no longer delays reading…

AddedChangedFixedSecurity
SourceAI extracted

uv

uv · Developer Tools

Prefer post-quantum key exchange and enable opt-in TLS diagnostics; Accept whitespace before versions in noncompliant wildcard comparisons such as Requires-Python: = 3.5.; Report…

AddedChangedFixedSecurity

Podman

Red Hat · Infrastructure & DevOps

Fixed CVE-2026-19730 where the podman quadlet install --replace command did not truncate the file being replaced, causing content from the original file to be incorrectly retained…

Security

Gitea

Gitea · Developer Tools

Fix collaborator access mode and httpsign; Refactor external render; Resolve pullrequesttarget reusable workflows at the base commit; Refactor markup render; Set WebAuthn user…

AddedFixedSecurity

Redpanda

Redpanda Data · Databases & Data

Fixed a crash that could occur when removing a partition with a very large number of log segments, for example during partition rebalancing; Fixed a crash where a snapshot write…

FixedSecurity

Redpanda

Redpanda Data · Databases & Data

Changes to cloudstoragethroughputlimitpercent cluster config now take effect at runtime instead of being ignored until restart; Fix consumer group lag metrics inflated after…

FixedSecurity

Helm

Helm · Infrastructure & DevOps

Improve error reporting for helm template --debug with --show-only; Fetch logs from all containers in test pods; Check error return in Digest and encodeRelease; Fix panic on…

FixedSecurity

Docker Engine

Docker · Infrastructure & DevOps

Fix CVE-2026-41568: symlink escape in mount destination creation; Decompress archives before entering container filesystem, fixing CVE-2026-41567; Fix CVE-2026-42306: bind mount…

Security

1Password CLI

AgileBits · Security & Privacy

Debug output now includes per-request timing; 1Password Environments commands are now significantly faster on Apple silicon Macs; Debug output now reports more information when a…

AddedChangedFixedSecurity
SourceAI extracted

Portainer

Portainer · Infrastructure & DevOps

Implemented an SSRF protection mechanism with a configurable allow-list in settings (off / audit / enforce modes); Changed a default setting to enforce server-side EdgeID on first…

FixedSecurity

Wireshark

Wireshark Foundation · Security & Privacy

Fix sharkd crash (wnpa-sec-2026-64); Fix sharkd crash (wnpa-sec-2026-65); Fix UMTS FP protocol dissector crash (wnpa-sec-2026-66); Fix RDP protocol dissector crash…

Security

Wireshark

Wireshark Foundation · Security & Privacy

Fix sharkd crash; Fix UMTS FP protocol dissector crash; Fix RDP protocol dissector crash; Fix TTX Logger file parser crash; Fix dissection engine reassembly crash; Fix BUSMASTER…

Security

Argo CD

Argo Project · Infrastructure & DevOps

Reuse server-side diff result when masking Secret data in controller; Prevent SSD CLI secret mask spoofing in server; Hide secret in last-applied-configuration annotation in SSD…

FixedSecurity

Strapi

Strapi · Developer Tools

Record MCP actions in audit logs; Add locale codes for Corsican in i18n; Enhance Koa app configuration with proxy settings; Fix typescript pipeline issue; Dedupe react-dnd in the…

AddedChangedFixedSecurity

ONNX Runtime

Microsoft · AI

WebGL and JSEP execution providers in onnxruntime-web are deprecated in favor of the native WebGPU EP; POSIX telemetry is now available on Linux, macOS, Android, and iOS when ONNX…

AddedChangedRemovedDeprecatedSecurity

Umami

Umami Software · Databases & Data

Two-Factor Authentication (2FA) support with TOTP-based authentication for self-hosted installs; 2FA setup with QR code and manual key entry; Backup codes for account recovery…

AddedChangedFixedSecurity

CrewAI

CrewAI · AI

Report flow outcome, duration, and human-in-the-loop signals; Emit FlowStartedEvent when a boundary hook aborts the flow; Scope span export to our own tracer provider; Bump torch…

AddedChangedFixedSecurity

ERPNext

Frappe · Productivity

Prevent a cancelled Subscription from being reactivated when its status is refreshed, and correct period-end cancellation when End Date is empty or a billing period rolls over…

AddedChangedFixedSecurity

LiteLLM

BerriAI · AI

All LiteLLM Docker images are now signed with cosign for verification purposes; Proxy request-handling maintenance and runtime dependencies refreshed

ChangedSecurity

LiteLLM

BerriAI · AI

All LiteLLM Docker images are now signed with cosign for signature verification; Backport proxy request-handling fixes; Refresh runtime dependencies

ChangedFixedSecurity

gemini-cli

gemini-cli · AI

Implement tool registry discovery; Implement Cloud Run webhook ingestion service for caretaker; Implement egress cloud run service skeleton for caretaker; Add triage worker core…

AddedChangedFixedSecurity

Claude Code

Anthropic · Developer Tools

Fixed interactive sessions that could stop redrawing entirely while the process kept running after a rare internal layout error; Fixed git / Git Bash not being found on Windows…

ChangedFixedRemovedSecurity

Mem0

Mem0 · AI

Add an Oracle AI Vector Search vector store (oracledb) to the OSS SDK with pooled connections, HNSW/IVF indexes, optional indexAccuracy target, JSON payload filtering, and six…

AddedChangedFixedSecurity

Zulip Server

Zulip · Communication

Guest users could receive new messages sent to public channels they were not subscribed to by registering an event queue with appropriate parameters, and existing event queues…

ChangedFixedSecurity

serverless

serverless · Frameworks & Libraries

Host MCP servers on AWS Lambda with a new mcp section in serverless.yml that deploys official MCP TypeScript SDK servers behind API Gateway with response streaming, OAuth…

AddedChangedFixedSecurity

Gumroad

Gumroad · Productivity

Harden Ping posturl SSRF checks, review-video stream auth, and SNS webhook verification

Security

Meilisearch

Meili · Databases & Data

Foreign filter now supports sharding by retrieving documents through the network when evaluating foreign filters and hydrating documents; Increase the limit of documents that a…

AddedChangedSecurity

XanMod Kernel

XanMod · Operating Systems

usb: typec: ucsi: Correct teardown ordering in ucsiinit() error path; drm/amd/display: Exit idle optimizations before programming; drm/amd/display: check GRPHFLIP status before…

AddedChangedFixedSecurity

Docker Desktop

Docker · Infrastructure & DevOps

Update Docker Engine to v29.7.2; Update Docker Buildx to v0.36.0; Update Docker Scout CLI to v1.24.0; Update Docker Agent to v1.119.0; Improve Docker VMM Beta performance with…

AddedChangedFixedSecurity
SourceAI extracted

Calibre-Web

Calibre-Web · Media

MOBI files now support metadata extraction on upload; Reverse proxy login with shared secret header implemented; Cover path is now selected based on the correct setting instead of…

AddedFixedSecurity

openclaw

openclaw · AI

Sandboxed browser routes, trusted DNS targets, custom browser origins, and loopback provider endpoints now reject unsafe access paths; Retained session writes, provider fallbacks…

FixedDeprecatedSecurity

Steam

Valve · Gaming Tools

Support for waking up from the Steam Controller Wireless Adapter (2015); Improved battery indications when the device is charging but using more power than the charger can…

AddedChangedFixedSecurity

Schedule I

TVGS · Games

Fixed a security vulnerability in which users could join a multiplayer game without being friends with the host; Fixed packaging station button text wrapping; Fixed main menu info…

FixedSecurity

CrewAI

CrewAI · AI

Fix preservation of provider on LiteLLM-routed models; Harden brittle LLM event-bus mocks; Fix underreporting of Anthropic cache token usage; Bump h2 to version 4.4.1 to address…

FixedSecurity

Super Productivity

Johannes Millan · Productivity

Added search to global settings and a keyboard shortcut cheat sheet; Added crash-safe local drafts for project notes; Added interval recurrence phrases such as @every 2 weeks and…

AddedChangedFixedSecurity

Dagster

Dagster Labs · Infrastructure & DevOps

An asset whose materialization failures are all pending an automatic retry now reports a WARNING health status instead of DEGRADED, and Slack, Microsoft Teams, and email alerts…

AddedChangedFixedSecurity

Consul

HashiCorp · Infrastructure & DevOps

Update brace-expansion to address DoS via unbounded intermediate arrays; Update fast-uri to address Host Confusion via backslash authority introducer; Update golang.org/x/text to…

AddedFixedSecurity

AionUi

iOfficeAI · AI

The conversation Explorer gains a Changes panel to see modified/added/deleted files for the project's repository, stage and unstage them inline, and get a clear result banner when…

AddedChangedFixedSecurity

Private Internet Access

Private Internet Access · Security & Privacy

Fixed race condition overriding selected location; Addressed security concern; Clear keystore after use; Added permissions blocks; Removed duplicate lookup; Fixed snooze remaining…

AddedChangedFixedSecurity

cherry-studio

cherry-studio · AI

Localize workspace tree errors in agent files; Use preset append mode for agent prompts in claude-code; Address high and critical security advisories; Serve DeepSeek V4 models…

AddedChangedFixedSecurity

strix

usestrix · AI

Align View label spacing in final panel; Fix viewer tool call collisions across agents; Make recoverable guardrail blocks and decouple crash-notify; Scope viewer session cookie to…

AddedChangedFixedSecurity

Linux Kernel

Linux Kernel Organization · Operating Systems
5.15.215longterm

Make Safe-RET robust against interrupt injection

Security

Linux Kernel

Linux Kernel Organization · Operating Systems
6.6.150longterm

Make Safe-RET robust against interrupt injection

Security

Payload

Payload · Developer Tools

Connect to the correct Next.js dev HMR endpoint per version; Bump mongoose to 8.24.1 for GHSA-664h-wqgq-64gw; Bump undici for security vulnerability; Bump @modelcontextprotocol/sdk…

FixedSecurity

lucide

lucide · Frameworks & Libraries

Fix lab build; Remove incorrect spaces clause from copilot instructions; Remove Super and Noodle from showcase; Improve security by adding permissions to CI workflows; Add…

AddedChangedFixedSecurity

OpenVPN

OpenVPN · Security & Privacy

Improve command line validation in openvpnserv on Windows to prevent circumventing admin restrictions on allowed OpenVPN config directories; Make DCO key state desynchronization…

FixedSecurity

Recently mentioned CVEs

CVE ids found verbatim in release notes — extracted from the text itself, not tagged by a model, so short notes count too. Each links to every release that mentions it.