Skip to content

Manticore Search

vrelease-28.4.4 scope: release Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 16d Search Engines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

api bm25 c++ database full-text-search json
+8 more
mysql search search-api search-engine search-server sphinxsearch sql stream-filtering

Affected surfaces

auth breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 11d

The release patches a critical authentication/authorization bypass in MySQL multi‑statement execution and fixes replication‑cluster restart recovery by persisting the stored replication user.

Why it matters: Severity 80 security fix blocks permission‑check bypass; severity 80 bug prevents cluster outages on restart. Operators must upgrade immediately to avoid unauthorized access or data loss.

Summary

AI summary

Broad release touches Bug Fixes, New Features and Improvements, https://manual.manticoresearch.com/Searching/Conversational_search, and https://github.com/manticoresoftware/columnar.

Changes in this release

Security High

Fixes authentication/authorization permission-check bypass in MySQL multi-statement execution.

Fixes authentication/authorization permission-check bypass in MySQL multi-statement execution.

Source: llm_adapter@2026-07-15

Confidence: high

Breaking High

Breaks external UDF, ranker, and token-filter plugins due to ABI version bump.

Breaks external UDF, ranker, and token-filter plugins due to ABI version bump.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Adds `custom_prompt` support for CREATE CHAT MODEL in Buddy, enabling custom instruction handling.

Adds `custom_prompt` support for CREATE CHAT MODEL in Buddy, enabling custom instruction handling.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Adds zero‑count facet bucket support for faceted search via `ZEROES` SQL and `

Adds zero‑count facet bucket support for faceted search via `ZEROES` SQL and `

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Adds `embeddings_threads` setting to cap CPU threads for auto‑embedding and KNN queries.

Adds `embeddings_threads` setting to cap CPU threads for auto‑embedding and KNN queries.

Source: llm_adapter@2026-07-15

Confidence: low

Feature Medium

Improves KNN search performance by batching distance calculations during rescore.

Improves KNN search performance by batching distance calculations during rescore.

Source: llm_adapter@2026-07-15

Confidence: low

Feature Low

Introduces `embeddings_threads` setting to cap CPU threads used by auto‑embedding inserts, ALTER TABLE ... REBUILD KNN, and text‑to‑vector KNN queries in MCL.

Introduces `embeddings_threads` setting to cap CPU threads used by auto‑embedding inserts, ALTER TABLE ... REBUILD KNN, and text‑to‑vector KNN queries in MCL.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Low

Introduces `profile='relevance'` in CREATE TABLE, providing built‑in full‑text ranking and implicit keyword‑combining behavior without repeating query options.

Introduces `profile='relevance'` in CREATE TABLE, providing built‑in full‑text ranking and implicit keyword‑combining behavior without repeating query options.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix High

Fixes authenticated replication-cluster restart recovery by persisting the stored replication user.

Fixes authenticated replication-cluster restart recovery by persisting the stored replication user.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Corrects COUNT(DISTINCT ...) handling to prevent incorrect carry‑over and rowset corruption in multi‑statement queries.

Corrects COUNT(DISTINCT ...) handling to prevent incorrect carry‑over and rowset corruption in multi‑statement queries.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Cleans up interrupted columnar/KNN merge temporary files, preventing orphaned .tmp.spc.* files from breaking later operations.

Cleans up interrupted columnar/KNN merge temporary files, preventing orphaned .tmp.spc.* files from breaking later operations.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Fixes Ukrainian lemmatizer to normalize apostrophe words correctly (e.g., здоров'ям → здоров'я).

Fixes Ukrainian lemmatizer to normalize apostrophe words correctly (e.g., здоров'ям → здоров'я).

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Improves DBeaver compatibility by accepting simple single‑table aliases in SELECT queries.

Improves DBeaver compatibility by accepting simple single‑table aliases in SELECT queries.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Restores native‑password login flow for Connector/J and PyMySQL clients in MySQL protocol startup.

Restores native‑password login flow for Connector/J and PyMySQL clients in MySQL protocol startup.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Full changelog

Version 28.4.4

Released: July 10th 2026

This release focuses on KNN performance, conversational search improvements, easier installation, better faceting and embedding controls, and fixes across authentication security, replication, SQL compatibility, distributed queries, and columnar/KNN internals.

New Features and Improvements

Breaking Changes

  • ⚠️ v28.0.0 Issue #4667 PR #4668 Breaking change: plugin ABI version SPH_UDF_VERSION is bumped to 12 so token-filter plugins can correctly receive long dict=keywords_32k tokens instead of silently bypassing values over the legacy 126-byte limit. This breaks existing external UDF, ranker, and token-filter plugin binaries: they must be rebuilt before loading into this version, and token-filter implementations that copy token text into fixed-size buffers may also need code changes to handle much longer tokens. Existing table data and configuration remain compatible, and no index migration is required. Downgrade is possible if you also restore plugin binaries built for the older ABI and do not rely on the new long-token plugin behavior.

Bug Fixes

  • 🪲 v28.4.4 Updated README.Debian.in and man pages.
  • 🪲 v28.4.3 Issue #1250 PR #4623 Fixed incompatible multi-statement handling around COUNT(DISTINCT ...), preventing incorrect carry-over and rowset corruption in multi-query result processing.
  • 🪲 v28.4.2 PR #4713 Fixed an authentication/authorization permission-check bypass in MySQL multi-statement execution, so each statement in a multi-statement request is validated correctly under auth.
  • 🪲 v28.4.1 Issue #4705 PR #4712 Fixed authenticated replication-cluster restart recovery by persisting the stored replication user in cluster metadata, so nodes can restore and automatically rejoin without losing the configured cluster user.
  • 🪲 v28.3.7 Issue #4697 PR #4698 Fixed interrupted columnar/KNN merge cleanup so temporary component files under the tracked temp prefix are removed correctly, preventing orphaned .tmp.spc.* files from breaking later table rename, attach, or drop operations.
  • 🪲 v28.3.6 PR #4695 Improved DBeaver compatibility by accepting simple single-table aliases in SELECT queries, so default DBeaver table-browsing queries no longer fail.
  • 🪲 v28.3.5 Issue #4682 PR #4683 Fixed the built-in Ukrainian lemmatizer so apostrophe words are normalized correctly, allowing forms like здоров'ям to match здоров'я under lemmatize_uk_all.
  • 🪲 v28.3.4 Issue #4691 PR #4696 Fixed authenticated MySQL protocol startup compatibility so Connector/J and PyMySQL clients can complete native-password login flows and harmless session SET statements no longer fail under auth.
  • 🪲 v28.3.3 Issue #4641 PR #4649 Fixed AOT blended-keyword handling to honor the configured blend_mode, restoring separator-stripped variants consistently for indexing and keyword extraction.
  • 🪲 v28.3.2 PR #186 Updated MCL to include an explicit DOCS_PER_CHUNK build fix, preventing bundled KNN library build/open failures in the new submodule-based columnar workflow.
  • 🪲 v28.3.1 Issue #4432 PR #4689 Fixed replication-cluster startup when a node was left alone in the cluster, so a remaining self-only node can recover cleanly instead of failing to start.
  • 🪲 v28.1.5 PR #4687 Fixed distributed stored-field fetching to validate remote GETFIELD replies before using them, preventing malformed agent responses from being trusted.
  • 🪲 v28.1.4 PR #4676 Fixed the migrated MCL submodule build and packaging workflow, restoring correct CI, package, and dependency-resolution handling for the bundled columnar library after the daemon-side submodule transition.
  • 🪲 v28.1.3 PR #4663 Fixed several memory leaks and cleanup bugs across optional library loading, SSL key handling, RT dictionary cleanup, timer-thread shutdown, and facet-zeroes aggregation paths.
  • 🪲 v28.1.2 Issue #4672 PR #4679 Fixed a crash when percentiles aggregations were used together with terms aggregations in the same /search request on multi-chunk RT tables.
  • 🪲 v28.1.1 PR #4669 Fixed RT auto-optimization so OPTIMIZE TABLE no longer compacts a table below 2 disk chunks unless that lower cutoff is explicitly requested.
  • 🪲 v28.0.2 Issue #4632 PR #4673 Fixed distributed queries with remote stored fields to fail on remote GETFIELD fetch errors instead of returning successful rows with silently empty stored-field values.
  • 🪲 v28.0.1 Issue #4615 PR #4631 Fixed long SQL parse errors to preserve UTF-8 character boundaries, so invalid queries containing Cyrillic and other multibyte text no longer produce truncated or corrupted error messages.

Breaking Changes

  • Plugin ABI version SPH_UDF_VERSION bumped to 12; existing external UDF, ranker, and token‑filter binaries must be rebuilt before loading.

Security Fixes

  • Fixed authentication/authorization permission‑check bypass in MySQL multi‑statement execution, ensuring each statement is validated under auth.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Manticore Search

Get notified when new releases ship.

Sign up free

About Manticore Search

Full-text search and data analytics, with fast response time for small, medium and big data (alternative to Elasticsearch)

All releases →

Beta — feedback welcome: [email protected]