Observability & Monitoring
Metrics, tracing, logging, and dashboards for modern infrastructure.
v3.6.13
(2d)
Security fixes + bug fixes
Review required
Auth
RBAC
RCE / SSRF
Critical security fixes
v2.15.4
(27d)
Critical security fixes
v2.16.2
(27d)
Security fixes + filter-expression permission
Upgrade now
Auth
Dependencies
Secrets exposure fix + dependency bumps
⚠ Upgrade required
- Alertmanager config updates no longer error when autogenerated receivers are present.
Security fixes
- CVE-2026-28374
- CVE-2026-28376
- CVE-2026-28383
v12.4.3+security-02
(2mo)
CVE-2026-28374
v12.2.8+security-04
(2mo)
Security patches across supported versions.
v11.6.14+security-04
(2mo)
Security fixes
v13.0.1+security-01
(2mo)
CVE-2026 fixes
Security fixes
- Upgrade Go builder to version 1.26.3, addressing security issues listed in the Go 1.26.3 changelog.
v1.143.0
(2mo)
Go builder upgrade
⚠ Upgrade required
- If unable to update immediately, block external access to the /install/ directory at your webserver level as a temporary mitigation.
- A full security advisory will be published in approximately 30 days.
Security fixes
- Fixed critical vulnerability affecting all Wavelog installations from version 1.8 onward; temporary mitigation: block external access to /install/ directory.
Notable features
- Lightweight search page for qrz.com embedding
- User agent added for JWKS request in SSO implementation
- Option to skip first login wizard for clubstation members
⚠ Upgrade required
- Remove invalid --upload flag from cosign sign in release workflow
Security fixes
- Prevent client‑supplied X-Forwarded-Authorization from shadowing service‑account-token
- Harden CSRF token handling
- Stop trusting X-Forwarded-* headers in same-origin check
Notable features
- Support forwarded host in same-origin check
- Relax hex requirement for session key-pairs
- Trigger publish workflows only on stable releases
Security fixes
- Fixed security vulnerability in API key authentication affecting versions v0.7.0 through v0.10.0
Notable features
- New resource overview dashboard
- User‑controlled display scale setting
Security fixes
- AzureAD OAuth client_secret exposed in plaintext via /-/config endpoint (CVE-2026-42151, GHSA-wg65-39gg-5wfj)
- Remote-read snappy-compressed requests with excessive decoded length (CVE-2026-42154, GHSA-8rm2-7qqf-34qm)
- Old UI stored XSS via unescaped le label values in heatmap (GHSA-fw8g-cg8f-9j28)
v3.5.3
(3mo)
OAuth credential exposure, snappy decompression, XSS
Security fixes
- Go builder upgraded from 1.25.9 to 1.26.2
- Alpine base image upgraded from 3.23.3 to 3.23.4
v1.136.6
(3mo)
Alpine security update
Security fixes
- DAPI callable resolution restriction
- Buffer overflow in analysisd regex match
- Path traversal in authd via agent group name
Security fixes
- Fix(rss): prevent path traversal via unvalidated feed_id in get_feed_file_path.
Get this as a security brief. Track Observability & Monitoring releases straight to your inbox.