This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe release patches a critical SSO takeover vulnerability and blocks DNS rebinding attacks on OpenAPI endpoints.
Why it matters: Security‑critical fixes (severity 95 for SSO, severity 90 for DNS) directly protect authentication flows and API surface; operators must apply the update immediately to mitigate high‑impact threats.
Summary
AI summaryUpdates fix, completed/failed, and feat across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes SSO takeover vulnerability. Fixes SSO takeover vulnerability. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Prevents DNS rebinding attacks on OpenAPI REST endpoints. Prevents DNS rebinding attacks on OpenAPI REST endpoints. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds realtime WebSocket updates for Agent Requests Activity table. Adds realtime WebSocket updates for Agent Requests Activity table. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds status filter dropdown to Activity requests table. Adds status filter dropdown to Activity requests table. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds async SharePoint sync capability. Adds async SharePoint sync capability. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Makes rollout strategy and imagePullPolicy configurable in Helm chart. Makes rollout strategy and imagePullPolicy configurable in Helm chart. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes live‑update pagination and summary counts on Activity page. Fixes live‑update pagination and summary counts on Activity page. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes view handling for external databases when deleting a column. Fixes view handling for external databases when deleting a column. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Partially removes stalled cron jobs to prevent resource buildup. Partially removes stalled cron jobs to prevent resource buildup. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Corrects free plan workspace and plugin quota enforcement. Corrects free plan workspace and plugin quota enforcement. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
What's Changed
- [Added] Realtime WebSocket updates for the Agent Requests Activity table by @jvcalderon in https://github.com/Budibase/budibase/pull/19150
- Fix live-update pagination and summary counts on Activity page by @jvcalderon in https://github.com/Budibase/budibase/pull/19155
- Add status filter dropdown to Activity requests table by @jvcalderon in https://github.com/Budibase/budibase/pull/19157
- Track status changes in the actions timeline by @jvcalderon in https://github.com/Budibase/budibase/pull/19165
- Add actions timeline data model and user interaction tracking by @jvcalderon in https://github.com/Budibase/budibase/pull/19162
- View fix for external dbs on column delete by @deanhannigan in https://github.com/Budibase/budibase/pull/19161
- Secfix/sso takeover by @calexiou in https://github.com/Budibase/budibase/pull/19173
- Make rollout strategy and imagePullPolicy configurable in Helm chart by @calexiou in https://github.com/Budibase/budibase/pull/19183
- Secfix/dns rebinding openapi rest by @calexiou in https://github.com/Budibase/budibase/pull/19178
- fix: partial removal of stalled cron jerbs by @Dakuan in https://github.com/Budibase/budibase/pull/19065
- Track AgentRequest status through the full escalation lifecycle by @jvcalderon in https://github.com/Budibase/budibase/pull/19124
- Unify usage of Helpers.uuid for unsecured browsers by @adrinr in https://github.com/Budibase/budibase/pull/19191
- fix free plan workspace and plugin quotas by @ConorWebb96 in https://github.com/Budibase/budibase/pull/19190
- Bind chat identity link confirmation to the current user by @adrinr in https://github.com/Budibase/budibase/pull/19194
- Judge agent request outcome (completed/failed) via LLM instead of tool-failure counting by @jvcalderon in https://github.com/Budibase/budibase/pull/19185
- Track escalation timeline actions (escalation_raised, escalation_resolved) by @jvcalderon in https://github.com/Budibase/budibase/pull/19192
- Track tool call actions in the AgentRequest timeline by @jvcalderon in https://github.com/Budibase/budibase/pull/19184
- feat: async sharepoint sync by @Dakuan in https://github.com/Budibase/budibase/pull/19189
- fix: can miss sharepoint name on partial falure by @Dakuan in https://github.com/Budibase/budibase/pull/19200
- fix: dont attempt to ingest large sharepoint files by @Dakuan in https://github.com/Budibase/budibase/pull/19201
- Split couchinfo between internal and external by @adrinr in https://github.com/Budibase/budibase/pull/19197
- Fix mysql test docker-compose, updating it to mysql 9 by @adrinr in https://github.com/Budibase/budibase/pull/19199
Full Changelog: https://github.com/Budibase/budibase/compare/3.39.29...3.39.30
Security Fixes
- Secfix/sso takeover
- Secfix/dns rebinding openapi rest
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]