This release includes 1 security fix for security teams reviewing exposed deployments.
Published 27d
Data Warehouses & Analytics
✓ No known CVEs patched
This release patches 1 known CVE
Topics
cdp
cms
cms-framework
customer-data-platform
dam
data-management
+13 more
digital-platform
ecommerce
ecommerce-platform
experience-manager
master-data-management
mdm
online-shop
pim
pimcore
product-information-management
product-management
shop
wcms
Affected surfaces
rce_ssrf
Summary
AI summaryRestrict allowed classes in Site deserialization for security.
Full changelog
What's Changed
- Refine return type of
UserAwareController::getPimcoreUser()by @jdreesen in https://github.com/pimcore/pimcore/pull/18693 - Remove unnecessary blank line in codeception.yaml by @bluvulture in https://github.com/pimcore/pimcore/pull/18829
- Refactor v11 specific workflows to v12 by @kingjia90 in https://github.com/pimcore/pimcore/pull/19082
- feat: add TemplateProviderInterface extension point to ControllerDataProvider by @fashxp in https://github.com/pimcore/pimcore/pull/19146
- Delete backup workflow files by @berfinyuksel in https://github.com/pimcore/pimcore/pull/19096
- Remove some admin functions and deprecate admin translations by @robertSt7 in https://github.com/pimcore/pimcore/pull/19131
- [Improvement] CDN integration by @mcop1 in https://github.com/pimcore/pimcore/pull/19122
- security: restrict allowed_classes in Site::setDomains() and setLocalizedErrorDocuments() deserialization by @XananasX7 in https://github.com/pimcore/pimcore/pull/19162
- Revise README for improved clarity and structure by @fashxp in https://github.com/pimcore/pimcore/pull/19194
- [Task] CDN integration -image optimizer support by @mcop1 in https://github.com/pimcore/pimcore/pull/19178
- [User] Add theme column to user by @martineiber in https://github.com/pimcore/pimcore/pull/19214
- Handle case where mime type is not found by @cancan101 in https://github.com/pimcore/pimcore/pull/18889
- Ensure that dimensions are integers by @cancan101 in https://github.com/pimcore/pimcore/pull/18890
- docs update by @fashxp in https://github.com/pimcore/pimcore/pull/19222
- Fix deprecation from
FOSJsRoutingBundleby @jdreesen in https://github.com/pimcore/pimcore/pull/18852 - Add missing
ownernamecondition when fetching objectbrick relations by @codata-swiss in https://github.com/pimcore/pimcore/pull/19180 - Refactor
ControllerDataProvider& allow to define templates exclusively via custom template providers by @jdreesen in https://github.com/pimcore/pimcore/pull/19147
New Contributors
- @XananasX7 made their first contribution in https://github.com/pimcore/pimcore/pull/19162
- @codata-swiss made their first contribution in https://github.com/pimcore/pimcore/pull/19180
Full Changelog: https://github.com/pimcore/pimcore/compare/v2026.1.6...v2026.2.1
Security Fixes
- security: restrict allowed_classes in Site::setDomains() and setLocalizedErrorDocuments() deserialization
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]