This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
ReleasePort's take
Moderate signalUpgrade the idna dependency to versionβ―3.16 to remediate CVEβ2026β45409.
Why it matters: CVEβ2026β45409 (CVSSβ―9.8) affects all deployments using the current idna library; upgrading to 3.16 eliminates the vulnerability immediately.
Summary
AI summaryBroad release touches π§° Maintenance, π Features, π Bug Fixes, and chore.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Upgrade idna dependency to 3.16, fixing CVE-2026-45409. Upgrade idna dependency to 3.16, fixing CVE-2026-45409. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Introduce v2 create and get dashboard API endpoints. Introduce v2 create and get dashboard API endpoints. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Upgrade OpenFGA authorization library from version 1.11.2 to 1.14.1. Upgrade OpenFGA authorization library from version 1.11.2 to 1.14.1. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Add clear filter button and restructure UI in trace details header. Add clear filter button and restructure UI in trace details header. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Introduce base route, authβretry streaming, and rateβlimit UX for AI assistant. Introduce base route, authβretry streaming, and rateβlimit UX for AI assistant. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Apply new soft colour palette to waterfall and flamegraph visualizations. Apply new soft colour palette to waterfall and flamegraph visualizations. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Feature | Low |
Replace Radio components with ToggleGroup in various components. Replace Radio components with ToggleGroup in various components. Source: granite4.1:30b@2026-05-28-audit Confidence: low |
β |
| Bugfix | Medium |
Ensure timestamp is always emitted in milliseconds. Ensure timestamp is always emitted in milliseconds. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Bugfix | Medium |
Resolve ClickHouse 25.12.5 Trace Operator query analyzer failure caused by dangling CTE. Resolve ClickHouse 25.12.5 Trace Operator query analyzer failure caused by dangling CTE. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Refactor | Low |
Replace antd Checkbox with @signozhq/ui Checkbox component. Replace antd Checkbox with @signozhq/ui Checkbox component. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Refactor | Low |
Migrate antd Tag component to signozhq/ui Badge. Migrate antd Tag component to signozhq/ui Badge. Source: llm_adapter@2026-05-28 Confidence: high |
β |
| Refactor | Low |
Migrate Avatar from antd to signozhq/ui Avatar. Migrate Avatar from antd to signozhq/ui Avatar. Source: granite4.1:30b@2026-05-28-audit Confidence: low |
β |
| Refactor | Low |
Refactor: migrate plain antd dropdown to @signozhq/ui/dropdown. Refactor: migrate plain antd dropdown to @signozhq/ui/dropdown. Source: granite4.1:30b@2026-05-28-audit Confidence: low |
β |
Full changelog
What's Changed
π Features
- refactor: replace antd Checkbox with @signozhq/ui Checkbox (#11396) @YounixM
- feat: replace Radio components with ToggleGroup in various components (#11391) @YounixM
- feat: new soft colour palette for waterfall + flamegraph (#11468) @aks07
- feat: v2 create and get dashboard API (#11125) @namanv3
- feat(authz): upgrade OpenFGA from v1.11.2 to v1.14.1 (#11475) @vikrantgupta25
- feat(ai-assistant): base route, auth-retry streaming, and rate-limit UX (#11457) @YounixM
- feat(trace-details): added clear filter button in trace details header + UI restructure (#11345) @aks07
π Bug Fixes
- fix: ensure timestamp is always in ms (#11483) @nityanandagohain
- fix: ClickHouse 25.12.5 Trace Operator query analyzer fail due to dangling CTE (#11268) @piyushsingariya
- fix: added utility functions to calculate minimum step intervals and β¦ (#11447) @YounixM
- fix(rules): use alertmanager external URL for related logs/traces and generator URL (#11413) @jatinderjit
- fix(deps): upgrade idna to 3.16 to fix CVE-2026-45409 (#11479) @vikrantgupta25
π§° Maintenance
- chore(release): bump SigNoz to v0.126.1 (#11487) @primus-bot
- chore: migrate antd Tag to badge (#11421) @manika-signoz
- chore(meterreporter): document jitter config in example.yaml (#11482) @karanbalani
- chore: migrate antd divider to signozhq/ui divider (#11474) @manika-signoz
- chore: preserve order of pipelines between
memory_limiterandbatch(#11461) @piyushsingariya - chore(agents): add more instructions for code quality (#11466) @H4ad
- chore: migrate Avatar from antd to signozhq/ui Avatar (#11478) @manika-signoz
- chore: breakdown query range function (#11211) @tushar-signoz
- refactor(frontend): migrate plain antd dropdown to @signozhq/ui/dropdown (#11400) @tewarig
Security Fixes
- dep: idna upgraded to 3.16 to fix CVE-2026-45409
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About signoz
SigNoz is an open-source observability platform native to OpenTelemetry with logs, traces and metrics in a single application. An open-source alternative to DataDog, NewRelic, etc. . Open source Application Performance Monitoring (APM) & Observability tool
Related context
Related tools
Beta — feedback welcome: [email protected]