Skip to content

Pulse

v5.1.35 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Monitoring & Metrics
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai alerts web docker docker-monitoring go
+13 more
self-hosted infrastructure-monitoring kubernetes monitoring proxmox proxmox-backup-server proxmox-mail-gateway proxmox-ve solidjs truenas typescript vsphere webhooks

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The agent updater now omits API token forwarding on cross‑host redirects for security.

Why it matters: Security severity rated 90; prevents token leakage during redirect flows.

Summary

AI summary

Updates Validation Summary, ✅ Release Asset Validation, and https://github.com/rcourtman/Pulse/actions/runs/27338490866 across a mixed release.

Changes in this release

Security Critical

Agent updater no longer forwards API token on cross-host redirects (GHSA-v644-29mm-jwx3).

Agent updater no longer forwards API token on cross-host redirects (GHSA-v644-29mm-jwx3).

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Ceph pool overrides resolve consistently, fixing missing alert configurations and metric gaps.

Ceph pool overrides resolve consistently, fixing missing alert configurations and metric gaps.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Unreachable Proxmox hosts remain visible with nodes marked offline instead of freezing at last snapshot.

Unreachable Proxmox hosts remain visible with nodes marked offline instead of freezing at last snapshot.

Source: llm_adapter@2026-06-11

Confidence: high

Full changelog

✅ Release Asset Validation (Post-Publish): PASSED

Assets were revalidated after publication due to a release edit.

Status: Live release assets re-validated ✅
Validated: 2026-06-11 09:50:29 UTC
Workflow: Validate Release Assets #87

Validation Summary

  • All required assets present ✓
  • Checksums verified ✓
  • Version strings correct ✓
  • Binary architectures validated ✓

Pulse v5.1.35

Final v5 maintenance release ahead of Pulse v6.

Security

  • Agent updater no longer forwards the agent API token (X-API-Token) when a
    configured Pulse server issues a cross-host redirect. The updater now refuses
    to follow redirects rather than re-sending credentials to the redirect
    target (GHSA-v644-29mm-jwx3). Reported by tonghuaroot.

Fixes

  • Ceph pool overrides now resolve consistently across reporting sources, fixing
    pool alert configuration disappearing from the Alerts tab and intermittent
    Proxmox cluster metric gaps.
  • Proxmox hosts that become unreachable now stay visible on the dashboard with
    their nodes marked offline, instead of freezing at their last online snapshot
    or never appearing when the host was already down at Pulse startup.

Installation

If you run Pulse via Docker or Compose, update to rcourtman/pulse:5.1.35.

See the Installation Guide for other deployment methods.

Security Fixes

  • GHSA-v644-29mm-jwx3 — Agent updater no longer forwards X-API-Token on cross‑host redirects, preventing credential leakage.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pulse

Get notified when new releases ship.

Sign up free

About Pulse

Real-time monitoring for Proxmox, Docker, and Kubernetes with AI-powered insights, smart alerts, and a beautiful unified dashboard

All releases →

Related context

Beta — feedback welcome: [email protected]