Skip to content

databasus

v3.40.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 14d Backup & Recovery
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

backup database database-backup devops docker go
+10 more
kubernetes mariadb mongodb mysql postgresql s3 self-hosted system-administration tools web-ui

Affected surfaces

deps rce_ssrf

ReleasePort's take

Light signal
editorial:auto 14d

v3.40.0 prevents SMTP header injection via CR/LF/NUL stripping, upgrades Docker SDK to v29 or v28.5.2 to clear high-severity advisories, and adds PostgreSQL 18 compatibility.

Why it matters: SMTP header injection is a security vector; patch immediately if using email notifications. Docker SDK upgrades clear high-severity advisoriesβ€”test in dev before production. PostgreSQL 18 support enables database version upgrades.

Summary

AI summary

Updates πŸ› Bug Fixes, ✨ Features, and 🐳 Docker across a mixed release.

Changes in this release

Security Medium

Migrate Docker SDK to moby/moby/{client,api} v29 to clear high-severity advisories

Migrate Docker SDK to moby/moby/{client,api} v29 to clear high-severity advisories

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

β€”
Security Medium

Bump Docker SDK to v28.5.2 to clear high-severity advisories

Bump Docker SDK to v28.5.2 to clear high-severity advisories

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

β€”
Feature Medium

Allow disabling cloud notice in self-hosted version via env variable IS_DISABLE_CLOUD_NOTICE

Allow disabling cloud notice in self-hosted version via env variable IS_DISABLE_CLOUD_NOTICE

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: high

β€”
Feature Medium

Add backups verification

Add backups verification

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

β€”
Dependency Medium

Databasus Docker image v3.40.0 released for linux/amd64 and linux/arm64 platforms

Databasus Docker image v3.40.0 released for linux/amd64 and linux/arm64 platforms

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

β€”
Bugfix Medium

Resolve binary path via constant map to clear uncontrolled data in path expression findings

Resolve binary path via constant map to clear uncontrolled data in path expression findings

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: high

β€”
Bugfix Medium

Support PostgreSQL 18 PGDATA layout and PG-friendly recovery_target_time format

Support PostgreSQL 18 PGDATA layout and PG-friendly recovery_target_time format

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: high

β€”
Bugfix Medium

Strip CR/LF/NUL from header-bound values to prevent SMTP header injection

Strip CR/LF/NUL from header-bound values to prevent SMTP header injection

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

β€”
Full changelog

Changelog

[3.40.0] - 2026-05-20

✨ Features

  • cloud: Allow to disable cloud notice in self-hosted version via env variable IS_DISABLE_CLOUD_NOTICE (9334895)
  • verifications: Add backups verification (f4ad457)

πŸ› Bug Fixes

  • notifiers/email: strip CR/LF/NUL from header-bound values to prevent SMTP header injection and clear CodeQL "email content injection" finding (00adb9c)
  • system/agent: resolve binary path via constant map to clear CodeQL "uncontrolled data in path expression" findings (f17d130)
  • verification: migrate Docker SDK to moby/moby/{client,api} v29 to clear three high-severity advisories (37f274b)
  • verification: bump docker SDK to v28.5.2 to clear high-severity advisories (1a6bc2f)
  • agent restore: support PostgreSQL 18 PGDATA layout and PG-friendly recovery_target_time format (#599) (d35440c)

🐳 Docker

  • Image: databasus/databasus:v3.40.0
  • Platforms: linux/amd64, linux/arm64

Security Fixes

  • Strip CR/LF/NUL from email header values to prevent SMTP header injection and clear CodeQL "email content injection" finding

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track databasus

Get notified when new releases ship.

Sign up free

About databasus

PostgreSQL backup tool (with MySQL\MariaDB and MongoDB support)

All releases β†’

Related context

Earlier breaking changes

  • v3.38.0 Reject MongoDB versions older than 4.2 at connection test
  • v3.38.0 Drop --db flag and unify MongoDB URI builder

Beta — feedback welcome: [email protected]