Skip to content

semaphore

v2.18.26 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ansible awx ci-cd devops docker docker-ui
+7 more
go jenkins opentofu pulumi terraform terraform-ui terragrunt

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 12d

ReleasePort v2.18.26 now verifies the current password during authentication changes to fix CWE-620.

Why it matters: Addresses CWE-620 by enforcing current‑password verification in the auth flow, improving credential security with a severity score of 70.

Summary

AI summary

Fixes CWE-620 by requiring the current password for authentication changes.

Changes in this release

Security High

Fixes CWE-620 by verifying current password during auth operations

Fixes CWE-620 by verifying current password during auth operations

Source: llm_adapter@2026-07-14

Confidence: low

Security Medium

Verifies current password to mitigate CWE-620

Verifies current password to mitigate CWE-620

Source: granite4.1:30b@2026-07-14-audit

Confidence: low

Full changelog

Changelog

  • ee781a032ccb58c61de6b9a70993f9b6dc77dcf8 feat(auth): verify current password to fix CWE-620

Security Fixes

  • CWE-620 — authentication changes now require verification of the current password

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track semaphore

Get notified when new releases ship.

Sign up free

About semaphore

Modern UI and powerful API for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools.

All releases →

Beta — feedback welcome: [email protected]