This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
Summary
AI summaryBroad release touches New Features none, hnsw, feat, and Breaking Changes none.
Full changelog
Breaking Changes
none
New Features
none
Fixes
- test(replication): stabilize TestReadRepairDeleteOnConflict against node-boot timing by @jeroiraz in https://github.com/weaviate/weaviate/pull/11748
- Fix wrong authz check for get groups for role by @dirkkul in https://github.com/weaviate/weaviate/pull/11728
- Fix backup concurrency calculation by @dirkkul in https://github.com/weaviate/weaviate/pull/11733
- feat(module): add generative-deepseek module by @antas-marcin in https://github.com/weaviate/weaviate/pull/11769
- fix(shard): make initTargetVector idempotent to prevent double-create by @amourao in https://github.com/weaviate/weaviate/pull/11584
- fix(dynamic): serialize config updates and Iterate against the flat->hnsw upgrade by @amourao in https://github.com/weaviate/weaviate/pull/11582
- fix(hnsw): read compression config under compressActionLock in insert validation by @amourao in https://github.com/weaviate/weaviate/pull/11583
- backport: feat: add location configuration to text2vec-google module (#8418) by @antas-marcin in https://github.com/weaviate/weaviate/pull/11762
- feat: add support for endpoint setting in OpenAI client by @antas-marcin in https://github.com/weaviate/weaviate/pull/11763
- feat(generative-google): add support for location setting by @antas-marcin in https://github.com/weaviate/weaviate/pull/11766
- fix(bm25): record max-impact pair on memtable BlockEntry by @amourao in https://github.com/weaviate/weaviate/pull/11780
- feat: add support for dimensions setting in text2vec-aws module by @antas-marcin in https://github.com/weaviate/weaviate/pull/11764
- security(modules): validate X-*-BaseURL request headers to close SSRF bypass by @spiros-spiros in https://github.com/weaviate/weaviate/pull/11683
- chore(generative-deepseek): add support for stop setting in module settings by @antas-marcin in https://github.com/weaviate/weaviate/pull/11796
- Remove flaky assertion for dynamic index by @trengrj in https://github.com/weaviate/weaviate/pull/11801
- security: bump golang.org/x/net and golang.org/x/crypto libs by @antas-marcin in https://github.com/weaviate/weaviate/pull/11840
- Fix backup RBAC checks by @dirkkul in https://github.com/weaviate/weaviate/pull/11123
- Snapshot in-place-mutated bbolt files during active-shard backup by @tsmith023 in https://github.com/weaviate/weaviate/pull/11832
- fix(usage): don't abort the whole usage report in case of missing tenant by @antas-marcin in https://github.com/weaviate/weaviate/pull/11849
- fix(hnsw): parallel-cursor prefill for unbounded uncompressed vector cache by @etiennedi in https://github.com/weaviate/weaviate/pull/11838
Full Changelog: https://github.com/weaviate/weaviate/compare/v1.36.18...v1.36.19
Security Fixes
- Validate X-*-BaseURL request headers to close SSRF bypass
- Bump golang.org/x/net and golang.org/x/crypto libs
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About weaviate
Weaviate is an open-source vector database that stores both objects and vectors, allowing for the combination of vector search with structured filtering with the fault tolerance and scalability of a cloud-native database.
Beta — feedback welcome: [email protected]