This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Monitoring & Metrics
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
alerting
graphing
prometheus
monitoring
time-series
Affected surfaces
auth
deps
Summary
AI summaryFixes secrets exposure via /-/config endpoint and bumps dependencies to address multiple CVEs.
Full changelog
This release fixes multiple security issues.
- [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via
/-/configendpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18650 - [SECURITY] Dependencies: Bump
golang.org/x/netto v0.55.0 and OpenTelemetry to v1.43.0 to fix reported CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985). #18934 - [SECURITY] UI: Bump mantine-ui dependencies (
react-router-dom,vitest,vite,postcss) to their patched versions to resolve security advisories. #18935 - [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18792
Security Fixes
- GHSA-39j6-789q-qxvh – secrets exposed in plaintext via /-/config endpoint
- dep: GO-2026-5026, GO-2026-4918, GO-2026-4985 fixed by bumping golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0
- dep: Security advisories resolved by bumping mantine-ui dependencies (react-router-dom, vitest, vite, postcss)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]