Skip to content

Databases & Storage

Relational, document, time-series, and vector databases — plus storage tooling.

Subscribe
← Releases
v1.4.3 (1d) Security neutralization
Review required
eLabFTW 5.5.13 Security relevant
Auth RBAC Breaking upgrade

Security patches

Upgrade now
v2 2.3.1 Security relevant
Auth RCE / SSRF

Security fixes

Upgrade now
dolibarr 22.0.5 Security relevant
RCE / SSRF Dependencies

SQL injection fix

No immediate action
doris 4.1.1 Security relevant

Source update + x64 binaries

patches CVE-2021-44228 patches CVE-2021-45046 patches CVE-2022-22965 +1 more
Open
Upgrade now
postiz-app v2.21.8 Security relevant

Security fix + contributor form + scrollable notifications

Upgrade now
timescaledb 2.27.1 Security relevant
Auth RBAC

Job errors view leakage fix

Upgrade now
dolibarr 23.0.3 Security relevant
Auth RBAC RCE / SSRF

IDOR + SSRF + SQLi fixes

Upgrade now
liquibase v5.0.3 Security relevant
Auth

generate-changelog sanitization fix

Upgrade now
rallly v4.10.1 Security relevant

CVE-2026-23870 patch

Review required
plane v1.3.1 Security relevant
Auth RBAC RCE / SSRF +1 more

ORM field injection prevention

No immediate action
yugabyte-db v2025.2.3.0 Security

Routine maintenance and dependency updates.

patches CVE-2025-31125
Open
Upgrade now
KurrentDB v26.0.3 Security relevant
Dependencies Breaking upgrade

CVE workarounds

Upgrade now
twenty v2.4.0 Security relevant
Dependencies RCE / SSRF

FTP command injection fix

grafana v12.3.6+security-04 Security relevant
⚠ Upgrade required
  • Alertmanager config updates no longer error when autogenerated receivers are present.
Security fixes
  • CVE-2026-28374
  • CVE-2026-28376
  • CVE-2026-28383
v12.4.3+security-02 (22d) CVE-2026-28374
v12.2.8+security-04 (22d) Security patches across supported versions.
v11.6.14+security-04 (22d) Security fixes
v13.0.1+security-01 (22d) CVE-2026 fixes
No immediate action
dgraph v25.3.4 Security relevant

CVE-2026-44840 fix

v24.1.9 (23d) CVE-2026-44840
VictoriaMetrics v1.136.9 Security relevant
Security fixes
  • Upgrade Go builder to version 1.26.3, addressing security issues listed in the Go 1.26.3 changelog.
v1.143.0 (23d) Go builder upgrade
Review required
InsForge v2.1.2 Security relevant
Auth

Auth posture hardening

valkey 7.2.13 Security relevant
Security fixes
  • CVE-2026-23479 — Use‑After‑Free in unblock client flow
  • CVE-2026-25243 — Invalid Memory Access in RESTORE command
  • CVE-2026-23631 — Use‑after‑free when full sync occurs during a yielding Lua/function execution
v8.0.8 (29d) CVE security fixes
v8.1.7 (29d) Security fixes CVEs
v9.0.4 (29d) Security fixes CVEs

Beta — feedback welcome: [email protected]