Skip to content

Flagsmith

v2.253.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ci-cd docker feature-flag feature-flaggers feature-flagging feature-flags
+9 more
feature-management feature-toggles flagsmith multivariate-testing python react remote-config remote-control self-hosted

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 11d

Update the django dependency to version 5.2.16 to apply critical security fixes.

Why it matters: The update addresses a high‑severity (severity 90) security vulnerability; operators must upgrade immediately to protect api runtime components.

Summary

AI summary

Updates Bug Fixes, 2.253.0, and Dependency Updates across a mixed release.

Changes in this release

Security Critical

Update django dependency to v5.2.16 for security fixes

Update django dependency to v5.2.16 for security fixes

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Add unique analytics IDs to experiment, metric, and warehouse buttons

Add unique analytics IDs to experiment, metric, and warehouse buttons

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Adopt the `flagsmith` entrypoint for API usage

Adopt the `flagsmith` entrypoint for API usage

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Bundle the Core API OpenAPI schema into distribution

Bundle the Core API OpenAPI schema into distribution

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Improve experiments wizard UX

Improve experiments wizard UX

Source: llm_adapter@2026-07-15

Confidence: high

Dependency Low

Update flagsmith-common dependency to >=3.12.0,<4

Update flagsmith-common dependency to >=3.12.0,<4

Source: llm_adapter@2026-07-15

Confidence: high

Dependency Low

Update flagsmith-private dependency to >=0.11.0,<1

Update flagsmith-private dependency to >=0.11.0,<1

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Add navigation link from segment members list to identity page

Add navigation link from segment members list to identity page

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Make Headway bell icon clickable

Make Headway bell icon clickable

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Prevent project navbar items from clipping off-screen

Prevent project navbar items from clipping off-screen

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fix nested viewsets exposing data across projects and organisations in API

Fix nested viewsets exposing data across projects and organisations in API

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Poll warehouse status for created connections in experimentation module

Poll warehouse status for created connections in experimentation module

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Preserve multivariate bucketing salt across feature state recreation

Preserve multivariate bucketing salt across feature state recreation

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Make LaunchDarkly import processing idempotent for completed requests

Make LaunchDarkly import processing idempotent for completed requests

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Enable segment membership across different organisations in backend and frontend

Enable segment membership across different organisations in backend and frontend

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Adjust dark mode colour utilities to use tokens instead of Bootstrap

Adjust dark mode colour utilities to use tokens instead of Bootstrap

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Resolve .text-secondary in dark mode to token, not Bootstrap

Resolve .text-secondary in dark mode to token, not Bootstrap

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Ensure experiment results page is visible in dark mode

Ensure experiment results page is visible in dark mode

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Return 400 when environment is null in featurestate update endpoint

Return 400 when environment is null in featurestate update endpoint

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Accept any 2xx status codes in webhook test endpoint

Accept any 2xx status codes in webhook test endpoint

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Full changelog

2.253.0 (2026-07-15)

Features

Bug Fixes

  • add navigation to identity page from segment members list (#7927) (f005081)
  • API: Nested viewsets expose data across projects and organisations (#7945) (26a1e29)
  • dark mode: move colour and shadow utilities from Bootstrap to tokens (#7982) (9ecdf6d)
  • dark mode: resolve .text-secondary to the token, not Bootstrap (#7981) (3eeaf38)
  • experimentation: poll warehouse status for created connections (#8001) (038238b)
  • Experiments: Dark mode visibility in results page (#7980) (c92b305)
  • features: preserve multivariate bucketing salt across feature state recreation (#7914) (62a8143)
  • LaunchDarkly: Import processing not idempotent for completed requests (#7954) (5cfb9f4)
  • make Headway bell icon clickable (#7925) (fd438ba)
  • nav: stop project navbar items clipping off-screen (#7968) (2b4473b)
  • return 400 when environment is null in featurestate update (#7957) (686bb9c)
  • Segment Membership: Enabled for different organisations in backend and frontend (#7966) (aa4ad62)
  • webhooks: accept 2xx status codes in webhook test endpoint (#7992) (7a6210c)

Dependency Updates

  • api: update dependency django to v5.2.16 [security] (#7990) (1c73453)
  • api: update dependency flagsmith-common to >=3.12.0,<4 (#8008) (0cb114b)
  • api: update dependency flagsmith-private to >=0.11.0,<1 (#8006) (1042aad)
  • MCP: Bump flagsmith-common to 3.12, pyfakefs to 6 (#8007) (e55b56d)

CI

  • Renovate: Eagerly bump flagsmith-common and flagsmith-private (#8005) (d625997)

Docs

Security Fixes

  • Dependency update: django upgraded to v5.2.16 (security)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Flagsmith

Get notified when new releases ship.

Sign up free

About Flagsmith

Dashboard, API and SDKs for adding Feature Flags to your applications (alternative to LaunchDarkly).

All releases →

Related context

Earlier breaking changes

  • v2.239.0 Make evaluation result variant required and nullable in SDK.

Beta — feedback welcome: [email protected]