CVE-2026-42505

Releases whose notes mention this CVE, found verbatim in the text — 4 releases so far. The vulnerability itself is described in the National Vulnerability Database. Or browse all security updates.

Releases mentioning CVE-2026-42505

Portainer

Portainer · Infrastructure & DevOps

Implemented an SSRF protection mechanism with a configurable allow-list in settings (off / audit / enforce modes); Changed a default setting to enforce server-side EdgeID on first…

FixedSecurity

Grafana Loki

Grafana Labs · Infrastructure & DevOps

Fix delete request when using Thanos objstore client with filesystem backend; Fix index filename issue with legacy S3 client and chunkdelimiter; Update fluentd to v1.19.3 to…

ChangedFixedSecurity

Grafana Loki

Grafana Labs · Infrastructure & DevOps

Update dependency fluentd to v1.19.3; Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505; Update module google.golang.org/grpc to v1.82.1; Update golang.org/x/net…

FixedSecurity

rclone

rclone · System Utilities

Fix goroutine leak in ResetCounters; Fix goroutine leak in NewStatsGroup for zero-transfer rc jobs; Fix path traversal in archive extract letting archives escape the destination…

ChangedFixedSecurity