This release includes 15 security fixes for security teams reviewing exposed deployments.
Published 1mo
Containers & Orchestration
✓ No known CVEs patched
This release patches 15 known CVEs
Topics
docker
docker-deployment
docker-swarm
docker-ui
kubernetes
moby
+2 more
portainer
ui
Affected surfaces
deps
breaking_upgrade
Summary
AI summaryUpdates Known issues, Deprecated and removed features, and Deprecated features None across a mixed release.
Full changelog
Known issues
- On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
- kubectl port-forward fails with Portainer kubeconfig in some configurations
Known issues with Podman support
- Podman environments aren't supported by auto-onboarding script
- It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
- Support for only CentOS 9, Podman 5 rootful
Changes
- Added an API endpoint to refresh Team/Group membership for a user
- Fixed an issue where users with no environment access are able to enumerate Kubernetes resources
- Fixed ecr token pre-validation error with warning log
- Fixed the way a standard user could not redeploy team stack or delete registry image
- Fixed the restore endpoint allowing admin takeover for uninitialised Portainer instances
- Fixed link on timed out page
- Replaced docker binary with libstack
- Fixed the volume label dropdown becoming blank
- Bump go-git to 5.19.1 to address the following CVEs:
- CVE-2026-45570
- CVE-2026-45571
- GHSA-w5pp-99ch-qj29
- Bumped go stdlib to 1.25.11 to remediate the following stdlib CVEs:
- CVE-2026-42504
- CVE-2026-27145
- CVE-2026-42499
- CVE-2026-39836
- CVE-2026-39820
- CVE-2026-33814
- CVE-2026-33811
- CVE-2026-39826
- CVE-2026-39823
- CVE-2026-39825
- CVE-2026-42504
- CVE-2026-27145
- CVE-2026-42507
Deprecated and removed features
Deprecated features
None
Removed features
None
Security Fixes
- Fixed restore endpoint allowing admin takeover for uninitialised Portainer instances
- Bump go-git to 5.19.1 – addresses CVE-2026-45570, CVE-2026-45571, GHSA-w5pp-99ch-qj29
- Bumped go stdlib to 1.25.11 – remediates CVE-2026-42504, CVE-2026-27145, CVE-2026-42499, CVE-2026-39836, CVE-2026-39820, CVE-2026-33814, CVE-2026-33811, CVE-2026-39826, CVE-2026-39823, CVE-2026-39825, CVE-2026-42507
- CVE-2026-45571
- CVE-2026-27145
- CVE-2026-42499
- CVE-2026-39836
- CVE-2026-39820
- CVE-2026-33814
- CVE-2026-33811
- CVE-2026-39826
- CVE-2026-39823
- CVE-2026-39825
- CVE-2026-27145
- CVE-2026-42507
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]