This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryUpdates https://docs.kurrent.io/server/v26.1/quick-start/whatsnew.html, https://docs.kurrent.io/server/v26.1/quick-start/installation.html, and https://docs.kurrent.io/server/v26.1/quick-start/upgrade-guide.html across a mixed release.
Full changelog
What's Changed
Important: Security Fix
Fixed https://github.com/kurrent-io/KurrentDB/security/advisories/GHSA-r8vq-5875-cq97: Privileged access to read $all enables arbitrary file read and GET-only SSRF
Fixed
- [DB-2085] Fix three JintProjectionStateHandler correctness bugs by @alexeyzimarev in https://github.com/kurrent-io/KurrentDB/pull/5610
- [v26.1] Fixed secondary-index related stats in the UI by @timothycoleman in https://github.com/kurrent-io/KurrentDB/pull/5651
- [release/v26.1] [DB-2153] Fix projections v2 processing link to scavenged event by @github-actions[bot] in https://github.com/kurrent-io/KurrentDB/pull/5657
- [release/v26.1] [DB-2154] Reject property values with no type set at the API boundary by @github-actions[bot] in https://github.com/kurrent-io/KurrentDB/pull/5659
- [DB-2156] Populate position fields for unresolved link-to events in HTTP API by @timothycoleman in https://github.com/kurrent-io/KurrentDB/pull/5660
Changed
- [DEV-1700] Update Surge and Connectors packages by @w1am in https://github.com/kurrent-io/KurrentDB/pull/5620
- [release/v26.1] [DEV-1719] Upgrade surge for CVE-2026-44788 by @github-actions[bot] in https://github.com/kurrent-io/KurrentDB/pull/5629
- [v26.1][DB-2144] Workaround https://github.com/advisories/GHSA-2m69-gcr7-jv3q (#5646) by @timothycoleman in https://github.com/kurrent-io/KurrentDB/pull/5649
- [DB-2158] Add TruncateParked API for persistent subscriptions by @timothycoleman in https://github.com/kurrent-io/KurrentDB/pull/5665
- [release/v26.1] [DB-2160] Make gRPC response compression level configurable by @github-actions[bot] in https://github.com/kurrent-io/KurrentDB/pull/5670
Full Changelog: https://github.com/kurrent-io/KurrentDB/compare/v26.1.0...v26.1.1
Security Fixes
- GHSA-r8vq-5875-cq97 – Fixed privileged access to read $all enabling arbitrary file read and GET‑only SSRF
- CVE-2026-44788
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About KurrentDB
KurrentDB is a database that's engineered for modern software applications and event-driven architectures. Its event-native design simplifies data modeling and preserves data integrity while the integrated streaming engine solves distributed messaging challenges and ensures data consistency.
Related context
Related tools
Beta — feedback welcome: [email protected]