Skip to content

Hasura

v2.45.6 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 17d API Development
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

access-control api automatic-api bigquery graphql graphql-server
+8 more
haskell hasura mongodb postgresql rest sql-server subgraph supergraph

Affected surfaces

crypto_tls

ReleasePort's take

Moderate signal
editorial:auto 11d

The Ubuntu base image now includes an upgraded OpenSSL to address CVE‑2026‑45447.

Why it matters: CVE‑2026‑45447 is a critical vulnerability; upgrade the base image immediately if using affected packaging layers.

Summary

AI summary

Fixed OpenSSL CVE-2026-45447 by upgrading openssl in the Ubuntu base image.

Changes in this release

Security Critical

upgrade openssl in ubuntu base image to fix CVE-2026-45447

upgrade openssl in ubuntu base image to fix CVE-2026-45447

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

Changelog

This is a patch release for v2.45.

Bug fixes and improvements

  • packaging: upgrade openssl in ubuntu base image to fix openssl CVE-2026-45447

Security Fixes

  • CVE-2026-45447 — upgraded openssl in the Ubuntu base image to remediate vulnerability

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Hasura

Get notified when new releases ship.

Sign up free

About Hasura

Fast, instant realtime GraphQL APIs on Postgres with fine grained access control, also trigger webhooks on database events.

All releases →

Related context

Related CVEs

Earlier breaking changes

  • v2.45.4 Event trigger log format changed
  • v2.45.4 Remote schema type conflicts now marked as inconsistent_metadata

Featured in

Beta — feedback welcome: [email protected]