This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Moderate signalThe agent updater now omits API token forwarding on cross‑host redirects for security.
Why it matters: Security severity rated 90; prevents token leakage during redirect flows.
Summary
AI summaryUpdates Validation Summary, ✅ Release Asset Validation, and https://github.com/rcourtman/Pulse/actions/runs/27338490866 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Agent updater no longer forwards API token on cross-host redirects (GHSA-v644-29mm-jwx3). Agent updater no longer forwards API token on cross-host redirects (GHSA-v644-29mm-jwx3). Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Ceph pool overrides resolve consistently, fixing missing alert configurations and metric gaps. Ceph pool overrides resolve consistently, fixing missing alert configurations and metric gaps. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Unreachable Proxmox hosts remain visible with nodes marked offline instead of freezing at last snapshot. Unreachable Proxmox hosts remain visible with nodes marked offline instead of freezing at last snapshot. Source: llm_adapter@2026-06-11 Confidence: high |
— |
Full changelog
✅ Release Asset Validation (Post-Publish): PASSED
Assets were revalidated after publication due to a release edit.
Status: Live release assets re-validated ✅
Validated: 2026-06-11 09:50:29 UTC
Workflow: Validate Release Assets #87
Validation Summary
- All required assets present ✓
- Checksums verified ✓
- Version strings correct ✓
- Binary architectures validated ✓
Pulse v5.1.35
Final v5 maintenance release ahead of Pulse v6.
Security
- Agent updater no longer forwards the agent API token (X-API-Token) when a
configured Pulse server issues a cross-host redirect. The updater now refuses
to follow redirects rather than re-sending credentials to the redirect
target (GHSA-v644-29mm-jwx3). Reported by tonghuaroot.
Fixes
- Ceph pool overrides now resolve consistently across reporting sources, fixing
pool alert configuration disappearing from the Alerts tab and intermittent
Proxmox cluster metric gaps. - Proxmox hosts that become unreachable now stay visible on the dashboard with
their nodes marked offline, instead of freezing at their last online snapshot
or never appearing when the host was already down at Pulse startup.
Installation
If you run Pulse via Docker or Compose, update to rcourtman/pulse:5.1.35.
See the Installation Guide for other deployment methods.
Security Fixes
- GHSA-v644-29mm-jwx3 — Agent updater no longer forwards X-API-Token on cross‑host redirects, preventing credential leakage.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pulse
Real-time monitoring for Proxmox, Docker, and Kubernetes with AI-powered insights, smart alerts, and a beautiful unified dashboard
Related context
Related tools
Beta — feedback welcome: [email protected]