This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 version 3.39.16 fixes broken access control on the internal table search API.
Why it matters: The fix resolves a critical (severity 90) security vulnerability affecting the internal table search surface; operators should apply this release immediately.
Summary
AI summary[VULN-80] Fix broken access control on internal table search
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes broken access control on internal table search Fixes broken access control on internal table search Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Dependency | Low |
Updates joi from 17.6.0 to 18.2.1 in /packages/backend-core Updates joi from 17.6.0 to 18.2.1 in /packages/backend-core Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Dependency | Low |
Updates esbuild from 0.18.20 to 0.28.1 across all-non-major-security group Updates esbuild from 0.18.20 to 0.28.1 across all-non-major-security group Source: llm_adapter@2026-06-15 Confidence: high |
— |
Full changelog
What's Changed
- build(deps): bump joi from 17.6.0 to 18.2.1 in /packages/backend-core by @dependabot[bot] in https://github.com/Budibase/budibase/pull/18967
- build(deps-dev): bump esbuild from 0.18.20 to 0.28.1 in the all-non-major-security group across 1 directory by @dependabot[bot] in https://github.com/Budibase/budibase/pull/18974
- [VULN-80] Fix broken access control on internal table search by @jvcalderon in https://github.com/Budibase/budibase/pull/18962
Full Changelog: https://github.com/Budibase/budibase/compare/3.39.15...3.39.16
Security Fixes
- [VULN-80] Fix broken access control on internal table search
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]