Security updates

The newest releases whose notes mention a security fix, as tagged by our normalization of each vendor’s changelog. Follow along in your reader with the RSS feed.

Latest security updates

AutoGPT

Significant-Gravitas · AI

Expert-scoped sessions and identity context in Copilot backend; Experts marketplace section, team page, and per-expert threads; Compact wallet popover for the new layout; Replace S…

AddedChangedFixedSecurity

alist

alist · Developer Tools

Add an opt-in parallel upload mode for personalnew; Add CSTCloud Capsule (数据胶囊) driver; Make ranged download concurrency and part size configurable for quarkuc; Add optional User-A…

AddedFixedSecurity

Django

Django Software Foundation · Frameworks & Libraries

Disallow dict and non-valid GEOSGeometry str values in spatial lookups to prevent server-side file-write, remote code execution, and request forgery via spatial lookups (CVE-2026-1…

AddedSecurity

Django

Django Software Foundation · Frameworks & Libraries

Disallow dict and non-GEOSGeometry str types in spatial lookups to prevent server-side file-write, remote code execution, and request forgery via spatial lookups (CVE-2026-15307);…

AddedChangedFixedSecurity

Next.js

Vercel · Frameworks & Libraries

Update vendored lodash to 4.17.23 to fix CVE-2025-13465; Fix invalid HTML response for route-level RSC requests in deployment adapter; Normalize encoded dynamic placeholders in app…

AddedChangedFixedSecurity

XanMod Kernel

XanMod · Operating Systems

cifs: fix timelastwrite stamp placement in setattr/truncate paths; KVM: SVM: Bump asidgeneration on CPU online to avoid ASID collision after hotplug; bootconfig: fix NULL-pointer a…

ChangedFixedSecurity

pnpm

pnpm · Developer Tools

Fix package-substitution vulnerability in projects using namedRegistries where packages from different registries could be confused; packages resolved from named registries are now…

AddedChangedFixedSecurity

DBeaver

DBeaver Corp · Developer Tools

AI Chat is now accessible via keyboard with added shortcuts; Add ability to always open AI-generated scripts in a new SQL console; Fixed models that do not support temperature dyna…

AddedChangedFixedSecurity

rtk

rtk · AI

Store history db, tee logs and audit log owner-only; Tighten data dirs that already exist; Quote recovery hint paths with spaces

FixedSecurity

Enhance

Enhance Hosting Automation · Developer Tools

SVG uploads from resellers and end users are now explicitly checked for Javascript content which might be executed if the SVG file were opened directly in the browser; Customer sti…

FixedSecurity
SourceAI extracted

formatjs

formatjs · Developer Tools

apply Date method defaults in @formatjs/intl-datetimeformat; parse module ids with queries in @formatjs/unplugin; repair corrupted patches/typescript@7.0.2.patch; stop enabling JSX…

AddedFixedSecurity

Docker Engine

Docker · Developer Tools

Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process; Mount type image is no longer experimental;…

AddedChangedFixedSecurity

Unturned

Smartly Dressed Games · Games

Prevent loading components with UnityEvents connected to static methods to block exploitation of restricted methods such as Application.OpenURL; Fix an error when a component is mi…

FixedSecurity

cc-switch

cc-switch · AI

Tighten Skill installation from GitHub repository with zip-slip and path traversal protections and archive size limits; Close credential leakage in Gemini universal configuration a…

AddedChangedFixedSecurity

BeamNG.drive

BeamNG · Games

HDR output support on Vulkan and Direct3D 12 for brighter highlights, wider color ranges, and improved display accuracy on HDR-capable monitors; Volumetric clouds in the sky system…

AddedChangedFixedSecurity

Project Zomboid

The Indie Stone · Games

Fixed a vulnerability disclosed responsibly by Jorge Escabias; Many areas across the map received substantial overhauls with new tiles, buildings, and locations; Implemented perfor…

AddedChangedFixedRemovedSecurity

Counter-Strike 2

Valve · Games

Ranked Series stickers are now available for purchase with 50% of royalties shared with players, teams, and the tournament organizer; Fixed a bug where scripts would fail to load i…

AddedChangedFixedSecurity

CLion

JetBrains · Developer Tools

Fix path-traversal vulnerability in project workspace ID handling (CVE-2026-59792)

Security

gemini-cli

gemini-cli · AI

Group cancelled tool responses and coalesce consecutive roles to prevent 400 Bad Request errors; Implement LLM triage orchestrator and container build for caretaker-triage; Align m…

AddedChangedFixedSecurity

uv

uv · Developer Tools

Projects created with uv init now declare a build system using uvbuild and are packaged by default, with source code placed in src/ and a project.scripts entry included; Reject uns…

ChangedRemovedSecurity

DataGrip

JetBrains · Developer Tools

Fixed code execution vulnerability via path traversal in project workspace ID handling (CVE-2026-59792)

Security

prisma

prisma · Developer Tools

Resolved a security advisory in a transitive dependency of Prisma CLI

Security

Vercel

Vercel · Developer Tools

Addressed a high-severity server-side remote code execution vulnerability in Nuxt; Released Nuxt 4.5.1 and 3.21.10 to address eight security advisories; Released @nuxt/devtools 3.3…

Security

OpenWrt

OpenWrt Project · Operating Systems

Fixed stack buffer overflow in odhcpd DHCPv6 IA reply serialization (CVE-2026-53921); Fixed Reconfigure-Accept stack buffer overflow in odhcpd; Fixed use-after-free through danglin…

Security

ONNX Runtime

Microsoft · AI

Upgrade to ONNX 1.22.0 and protobuf 6.33.5; Make cuDNN and cuFFT optional at runtime for the CUDA execution provider; Remove nvrtc linking from CUDA execution provider to reduce re…

AddedChangedRemovedDeprecatedSecurity

spec-kit

github · AI

Update Intake Review Governance preset to v0.1.1; Update Verify Review Ship extension to v0.3.0; Update Architecture Guard extension to v1.13.1; Install commands under .kilo/comman…

AddedChangedFixedSecurity

legado

legado · Developer Tools

Add toggle switch for bookshelf recent reading and quantity statistics, disabled by default; Add persistent scheduled tasks support with five-segment Cron, JavaScript editing and d…

AddedChangedFixedSecurity

Linux Kernel

Linux Kernel Organization · Operating Systems
5.15.212longterm

perf/x86/amd/core: Always use the NMI latency mitigation; ALSA: seq: Fix uninitialised heap leak in sndseqeventdup(); iio: imu: invicm42600: fix timestamp clock period by using low…

FixedSecurity

Redis

Redis · Developer Tools

Fixed crafted RESTORE payloads in RedisBloom and TDigest that may trigger out-of-bounds writes, potentially leading to remote code execution

Security

Redis

Redis · Developer Tools

Fix a crafted stream RESTORE payload that could make two consumers share the same NACK, leading to a use-after-free and potential Remote Code Execution; Fix crafted RESTORE payload…

FixedSecurity

pnpm

pnpm · Developer Tools

Add a new setting update.githubActionsServer for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files; pn…

AddedChangedFixedSecurity

Turborepo

Vercel · Developer Tools

Disable unresolved Cargo artifact caching; Surface create-turbo Git failures; Resolve exact cargo profile outputs; Prune Bun production workspace dev dependencies; Resolve Cargo ta…

AddedFixedSecurity

open-design

open-design · AI

Visual direction now follows the format of the thing you are making with previews suited to each format including documents, posters, images, videos, Web Clones, wireframes, mobile…

AddedChangedFixedSecurity

serverless

serverless · Frameworks & Libraries

Lambda self-managed code storage with provider.deploymentBucket.codeStorageMode: reference to run function and layer code directly from deployment bucket instead of copying to Lamb…

AddedChangedFixedRemovedSecurity