Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalThe release fixes an open redirect vulnerability by unescaping the redirect URI before parsing.
Why it matters: CVE GHSA-8w27-c4vc-88q9 (severityβ―90) resolves an openβredirect flaw; deploy v8.2.3 to mitigate this highβrisk issue.
Summary
AI summaryUpdates π¦ Bundled Resource Types, π Bug Fixes, and bosh-io-release across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes open redirect vulnerability CVE GHSA-8w27-c4vc-88q9 by unescaping the redirect URI before parsing. Fixes open redirect vulnerability CVE GHSA-8w27-c4vc-88q9 by unescaping the redirect URI before parsing. Source: llm_adapter@2026-05-27 Confidence: high |
β |
| Dependency | Low |
Updates bundled resource types to latest versions: bosh-io-release v1.3.4, bosh-io-stemcell v1.5.4, docker-image v1.13.1, git v1.22.3, github-release v1.14.0, hg v1.5.4, mock v0.14.5, pool v1.8.1, registry-image v1.17.0, s3 v2.5.4, semver v2.0.1, time v1.11.3. Updates bundled resource types to latest versions: bosh-io-release v1.3.4, bosh-io-stemcell v1.5.4, docker-image v1.13.1, git v1.22.3, github-release v1.14.0, hg v1.5.4, mock v0.14.5, pool v1.8.1, registry-image v1.17.0, s3 v2.5.4, semver v2.0.1, time v1.11.3. Source: llm_adapter@2026-05-27 Confidence: high |
β |
Full changelog
What's Changed
π Bug Fixes
- unescape the redirect uri before further parsing it by @taylorsilva in https://github.com/concourse/concourse/pull/9587
- Resolves open redirect CVE https://github.com/concourse/concourse/security/advisories/GHSA-8w27-c4vc-88q9
π¦ Bundled Resource Types
- bosh-io-release: v1.3.4
- bosh-io-stemcell: v1.5.4
- docker-image: v1.13.1
- git: v1.22.3
- github-release: v1.14.0
- hg: v1.5.4
- mock: v0.14.5
- pool: v1.8.1
- registry-image: v1.17.0
- s3: v2.5.4
- semver: v2.0.1
- time: v1.11.3
Full Changelog: https://github.com/concourse/concourse/compare/v8.2.2...v8.2.3
Security Fixes
- GHSA-8w27-c4vc-88q9 β open redirect vulnerability fixed by unescaping the redirect URI before parsing.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Concourse
Concourse is a container-based automation system written in Go. It's mostly used for CI/CD.
Related context
Related tools
Beta — feedback welcome: [email protected]