This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
ReleasePort's take
Moderate signalThe release bumps PyJWT to version 2.13.0, which patches CVE‑2026‑48526.
Why it matters: CVE‑2026‑48526 has a severity score of 90; upgrading PyJWT to 2.13.0 eliminates the vulnerability for any application using this library.
Summary
AI summaryUpdates 2.239.0, Dependency Updates, and CI across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bump PyJWT to 2.13.0, fixing CVE-2026-48526. Bump PyJWT to 2.13.0, fixing CVE-2026-48526. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Security | High |
Update pytest to version 9, addressing security issues. Update pytest to version 9, addressing security issues. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Breaking | High |
Make evaluation result variant required and nullable in SDK. Make evaluation result variant required and nullable in SDK. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Add metric search, experiments field and update. Add metric search, experiments field and update. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Allow choosing project administrators during project creation. Allow choosing project administrators during project creation. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Introduce environment‑scoped metrics and experiment results. Introduce environment‑scoped metrics and experiment results. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Add Docker image and release publishing for MCP. Add Docker image and release publishing for MCP. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Emit session and tool call events in MCP. Emit session and tool call events in MCP. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Expose Prometheus metrics for MCP. Expose Prometheus metrics for MCP. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Add OAuth 2.0 support for HTTP transport in MCP. Add OAuth 2.0 support for HTTP transport in MCP. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Run an MCP server from OpenAPI specifications. Run an MCP server from OpenAPI specifications. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Low |
Add per-feature unique key to multivariate options. Add per-feature unique key to multivariate options. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Report variant key on identities flag responses for multivariate. Report variant key on identities flag responses for multivariate. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Thread variant key into the environment document for multivariate. Thread variant key into the environment document for multivariate. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Add variant key to evaluation schemas in SDK. Add variant key to evaluation schemas in SDK. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Dependency | Low |
Bump uv to 0.11.18. Bump uv to 0.11.18. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Dependency | Low |
Update python-dotenv and idna (transitive dependencies). Update python-dotenv and idna (transitive dependencies). Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Dependency | Low |
Update sentry webpack plugin. Update sentry webpack plugin. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Bugfix | Medium |
Fix uv compatibility in local environments. Fix uv compatibility in local environments. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
Full changelog
2.239.0 (2026-06-08)
Features
- add metric search, experiments field and update (#7724) (3d34cbc)
- choose project administrators on project creation (#7580) (1bf8bda)
- experimentation: environment-scoped metrics & experiment results (#7674) (f4b246e)
- MCP: Add Docker image and release publishing (#7694) (19fa405)
- MCP: Emit session and tool call events (#7707) (36ef8dd)
- MCP: Expose Prometheus metrics (#7705) (8ef95e0)
- MCP: OAuth 2.0 support for HTTP transport (#7692) (35664ed)
- MCP: Run an MCP server out of OpenAPI specs (#7670) (4688419)
- MCP: Set up logging and OpenTelemetry export (#7706) (f3c738b)
- multivariate: add per-feature unique key to multivariate options (#7698) (6fcede7)
- multivariate: report variant key on identities flag responses (#7723) (08b9690)
- multivariate: thread variant key into the environment document (#7699) (ed18061)
- sdk: add variant key to evaluation schemas (#7704) (2eae0ff)
- sdk: make evaluation result variant required and nullable (#7726) (9036dbf)
- verify warehouse connection api and events received (#7677) (d0ac9b5)
Bug Fixes
- API: bump PyJWT to 2.13.0 (CVE-2026-48526) and add to dev dependencies (#7714) (09bac40)
- Improve ButterBar text contrast on banners (#7684) (cf0d7b0)
- infra: Drop SECURE_PROXY_SSL_HEADER_NAME override (#7499) (ab37e29)
- Runtime: Fix uv compatibility in local envs (#7720) (4ffbf74)
Dependency Updates
- Bump uv to 0.11.18 (#7708) (cbcac64)
- update dependency pytest to v9 [security] (#7689) (253111c)
- Update python-dotenv and idna (transitive dependencies) (#7682) (08e6853)
- Update sentry webpack plugin (#7683) (de382aa)
- updated track event callsites with new interface (#7666) (0a935c7)
CI
Security Fixes
- CVE-2026-48526 — bump PyJWT to 2.13.0 (API dependency)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Flagsmith
Dashboard, API and SDKs for adding Feature Flags to your applications (alternative to LaunchDarkly).
Beta — feedback welcome: [email protected]