Skip to content

portainer

v2.39.4 Security

This release includes 15 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 15 known CVEs

Topics

docker docker-deployment docker-swarm docker-ui kubernetes moby
+2 more
portainer ui

Affected surfaces

deps breaking_upgrade

Summary

AI summary

Updates Known issues, Deprecated and removed features, and Deprecated features None across a mixed release.

Full changelog

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

  • Added an API endpoint to refresh Team/Group membership for a user
  • Fixed an issue where users with no environment access are able to enumerate Kubernetes resources
  • Fixed ecr token pre-validation error with warning log
  • Fixed the way a standard user could not redeploy team stack or delete registry image
  • Fixed the restore endpoint allowing admin takeover for uninitialised Portainer instances
  • Fixed link on timed out page
  • Replaced docker binary with libstack
  • Fixed the volume label dropdown becoming blank
  • Bump go-git to 5.19.1 to address the following CVEs:
    • CVE-2026-45570
    • CVE-2026-45571
    • GHSA-w5pp-99ch-qj29
  • Bumped go stdlib to 1.25.11 to remediate the following stdlib CVEs:
    • CVE-2026-42504
    • CVE-2026-27145
    • CVE-2026-42499
    • CVE-2026-39836
    • CVE-2026-39820
    • CVE-2026-33814
    • CVE-2026-33811
    • CVE-2026-39826
    • CVE-2026-39823
    • CVE-2026-39825
    • CVE-2026-42504
    • CVE-2026-27145
    • CVE-2026-42507

Deprecated and removed features

Deprecated features

None

Removed features

None

Security Fixes

  • Fixed restore endpoint allowing admin takeover for uninitialised Portainer instances
  • Bump go-git to 5.19.1 – addresses CVE-2026-45570, CVE-2026-45571, GHSA-w5pp-99ch-qj29
  • Bumped go stdlib to 1.25.11 – remediates CVE-2026-42504, CVE-2026-27145, CVE-2026-42499, CVE-2026-39836, CVE-2026-39820, CVE-2026-33814, CVE-2026-33811, CVE-2026-39826, CVE-2026-39823, CVE-2026-39825, CVE-2026-42507
  • CVE-2026-45571
  • CVE-2026-27145
  • CVE-2026-42499
  • CVE-2026-39836
  • CVE-2026-39820
  • CVE-2026-33814
  • CVE-2026-33811
  • CVE-2026-39826
  • CVE-2026-39823
  • CVE-2026-39825
  • CVE-2026-27145
  • CVE-2026-42507

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track portainer

Get notified when new releases ship.

Sign up free

About portainer

Making Docker and Kubernetes management easy.

All releases →

Related context

Earlier breaking changes

  • v2.42.0 Removal of legacy CSRF fallback feature flag.

Beta — feedback welcome: [email protected]