This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort v2.18.26 now verifies the current password during authentication changes to fix CWE-620.
Why it matters: Addresses CWE-620 by enforcing current‑password verification in the auth flow, improving credential security with a severity score of 70.
Summary
AI summaryFixes CWE-620 by requiring the current password for authentication changes.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Fixes CWE-620 by verifying current password during auth operations Fixes CWE-620 by verifying current password during auth operations Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Security | Medium |
Verifies current password to mitigate CWE-620 Verifies current password to mitigate CWE-620 Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
Full changelog
Changelog
- ee781a032ccb58c61de6b9a70993f9b6dc77dcf8 feat(auth): verify current password to fix CWE-620
Security Fixes
- CWE-620 — authentication changes now require verification of the current password
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About semaphore
Modern UI and powerful API for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools.
Related context
Beta — feedback welcome: [email protected]