Skip to content

Pimcore

v2026.1.6 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

cdp cms cms-framework customer-data-platform dam data-management
+13 more
digital-platform ecommerce ecommerce-platform experience-manager master-data-management mdm online-shop pim pimcore product-information-management product-management shop wcms

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates Fix, NumericRange/DateRange/Geopoint/Geobounds, and upgrade-notes across a mixed release.

Full changelog

What's Changed

  • [Bug]: Prevent/handle eager db connection resolution during bootstrap by @mcop1 in https://github.com/pimcore/pimcore/pull/19152
  • [Security]: Improve unserialize security in Hotspot Image by @kingjia90 in https://github.com/pimcore/pimcore/pull/19181
  • [Security] Deserialization of Untrusted Data in pimcore/pimcore by @robertSt7 in https://github.com/pimcore/pimcore/pull/19167
  • [Security] Harden field name validation by @mcop1 in https://github.com/pimcore/pimcore/pull/19183
  • [Security]: Improve sql concatenation in Custom Reports by @kingjia90 in https://github.com/pimcore/pimcore/pull/19175
  • [Task] Update TmpStore documentation structure by @mcop1 in https://github.com/pimcore/pimcore/pull/19185
  • Error “Failed to open stream: Too many open files” occurs during long-running processes involving asset operations by @robertSt7 in https://github.com/pimcore/pimcore/pull/19129
  • [Document Editor] Deprecate editable dialog width/height configuration options by @lukmzig in https://github.com/pimcore/pimcore/pull/19187
  • [Security] Restrict allowed classes when unserializing the admin session token by @mcop1 in https://github.com/pimcore/pimcore/pull/19191
  • [Bug, EC] PEES-989: MimeType gets guessed wrong by @robertSt7 in https://github.com/pimcore/pimcore/pull/19186
  • [Documentation] Update the Dialog Box Configuration by @ValeriaMaltseva in https://github.com/pimcore/pimcore/pull/19157
  • [Task] Fix broken markdown link in admin session token allowed-classes doc by @mcop1 in https://github.com/pimcore/pimcore/pull/19192
  • Fix: add method and property check to twig SecurityPolicy by @robertSt7 in https://github.com/pimcore/pimcore/pull/19193
  • Snippets will be cached with wrong links in preview view by @blankse in https://github.com/pimcore/pimcore/pull/18808
  • [Bugfix] Composite data types drop values when a sub-value is empty (NumericRange/DateRange/Geopoint/Geobounds) #18144 by @mcop1 in https://github.com/pimcore/pimcore/pull/19197
  • docs(upgrade-notes): note removal of doctrine enum mapping_type by @mcop1 in https://github.com/pimcore/pimcore/pull/19198
  • fix: Listing::getTotalCount() should use connected parameters by @youwe-petervanderwal in https://github.com/pimcore/pimcore/pull/18907
  • [Bug][Asset Preview] Fallback for SVGs that cannot be converted by @kingjia90 in https://github.com/pimcore/pimcore/pull/19184
  • Docs: Add MimeType Event by @robertSt7 in https://github.com/pimcore/pimcore/pull/19200
  • [Bug] Fix SVG/vector transparent background rendered as black by @kingjia90 in https://github.com/pimcore/pimcore/pull/19201
  • [Bug]: pimcoreblock inside pimcoremanualblock does not work with new syntax by @robertSt7 in https://github.com/pimcore/pimcore/pull/19196
  • [Bug] Fix Video editable rendering states in Studio by @markus-moser in https://github.com/pimcore/pimcore/pull/19106
  • Allow restricting subtypes and classes in link edit panel by @jdreesen in https://github.com/pimcore/pimcore/pull/18840
  • [Bug]: Fix Content from document with assigned content-main document by @kingjia90 in https://github.com/pimcore/pimcore/pull/19209
  • [Bug][Documents][Renderlets] Streamline passing of config attributes to renderlets by @robertSt7 in https://github.com/pimcore/pimcore/pull/19212
  • Remove broken and unnecessary transaction handling from NotificationService by @jdreesen in https://github.com/pimcore/pimcore/pull/19207
  • skip checking pdf after it has been checked and marked safe. by @cancan101 in https://github.com/pimcore/pimcore/pull/18541
  • [Bug]: performance problem when copying object to folder with many children objects by @robertSt7 in https://github.com/pimcore/pimcore/pull/19205
  • Fix typo in the docs by @jdreesen in https://github.com/pimcore/pimcore/pull/18951
  • Remove service definition for non-existing service by @pimcoreneusta in https://github.com/pimcore/pimcore/pull/19100
  • Fix Pimcore version in the docs by @jdreesen in https://github.com/pimcore/pimcore/pull/18950
  • Fix null argument exception in tree by @wwnorden in https://github.com/pimcore/pimcore/pull/19111
  • [Bug] Drop classic-UI markup from Video editable in-progress / error states by @markus-moser in https://github.com/pimcore/pimcore/pull/19107
  • Add Copilot code-review agent skill by @mcop1 in https://github.com/pimcore/pimcore/pull/19219
  • [Bug] Fix TypeError in for empty link localization (#19165] by @simonkey in https://github.com/pimcore/pimcore/pull/19208

New Contributors

  • @ValeriaMaltseva made their first contribution in https://github.com/pimcore/pimcore/pull/19157
  • @wwnorden made their first contribution in https://github.com/pimcore/pimcore/pull/19111
  • @simonkey made their first contribution in https://github.com/pimcore/pimcore/pull/19208

Full Changelog: https://github.com/pimcore/pimcore/compare/v2026.1.5...v2026.1.6

Security Fixes

  • Improve unserialize security in Hotspot Image
  • Deserialization of Untrusted Data in pimcore/pimcore
  • Harden field name validation
  • Improve sql concatenation in Custom Reports
  • Restrict allowed classes when unserializing the admin session token

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pimcore

Get notified when new releases ship.

Sign up free

About Pimcore

Multi-channel experience and engagement management platform.

All releases →

Related context

Beta — feedback welcome: [email protected]