This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalVersion v4.9.4 of the release is broken and fails to start containers; use version 4.9.5 instead.
Why it matters: If you attempt to run v4.9.4, container startup will fail; switch immediately to v4.9.5.
Summary
AI summaryBroken release — container fails to start; use version 4.9.5 instead.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Secure unauthenticated db restore endpoint with a setup token Secure unauthenticated db restore endpoint with a setup token Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | High |
Validate OIDC state parameter to prevent CSRF login attack Validate OIDC state parameter to prevent CSRF login attack Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Breaking | High |
Container fails to start in release 4.9.4 Container fails to start in release 4.9.4 Source: granite4.1:30b@2026-06-06-audit Confidence: low |
— |
| Bugfix | Medium |
Restrict migrate.php to CLI and admin session only Restrict migrate.php to CLI and admin session only Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
Breaking Changes
- v4.9.4 is a broken release that fails to start; requires upgrading to v4.9.5
Security Fixes
- Secure unauthenticated db restore endpoint with setup token
- Validate OIDC state parameter to prevent CSRF login attack
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Wallos
Wallos: Open-source, self-hostable personal subscription tracker. Visualize your recurring expenses, manage your budget, and save money.
Beta — feedback welcome: [email protected]