Skip to content
ReleasePort Weekly 2026-W20

Week 20 · May 11–17, 2026

Week of May 11–17, 2026

459 releases 89 breaking 55 security 9 tools featured

openproject v17.4.0, dolibarr 23.0.3, passbolt_api v5.12.0, rallly v4.10.1, and langchain‑core ==1.4.0 patch high‑severity IDOR and dependency vulnerabilities this week.

Editor's Picks

passbolt_api v5.12.0

Passbolt Community Edition (CE) API.

Fixes critical lodash package vulnerability (PB-50340).

Read full release →
langchain langchain-core==1.4.0

The agent engineering platform

Upgrades pygments to >=2.20.0 for CVE-2026-4539

Read full release →
openproject v17.4.0

OpenProject is the leading open source project management software.

IDOR in PATCH request to /api/v3/documents/{id} lets users modify foreign project documents by setting project_id before authorization checks.

Read full release →
plane v1.3.1

Open-source Jira, Linear, Monday, and ClickUp alternative.

Prevent ORM field injection via analytics segment parameter.

Read full release →
rallly v4.10.1

Rallly is an open-source scheduling and collaboration tool designed to make organizing events...

Patches Next.js May 2026 security advisory and CVE-2026-23870 (React Server Components DoS).

Read full release →

Category Pulse

AI & Machine Learning
150 releases
↓26% vs prior 1 KEV
Self-Hosted
102 releases
↓8% vs prior 1 KEV
Observability
64 releases
↑45% vs prior 1 KEV
Infrastructure
49 releases
↑32% vs prior 1 KEV
Security
31 releases
flat
Developer Tools
30 releases
↑58% vs prior
CI/CD
22 releases
↓42% vs prior 1 KEV
Data & Databases
10 releases
↓60% vs prior 1 KEV
MCP Servers
1 release
↓67% vs prior

Archive

Security & Auth tools · 12 releases +
Show low-signal releases (1)
AI & Machine Learning · 30 releases +
Infrastructure · 14 releases +
Show low-signal releases (1)
Observability · 11 releases +
Show low-signal releases (1)
Developer Tools · 3 releases +
CI/CD · 9 releases +
Self-Hosted · 28 releases +
Show low-signal releases (1)
Data & Databases · 2 releases +
Show low-signal releases (2)
MCP Servers · 1 release +

Get the weekly brief in your inbox. No spam, just software releases that matter.

Subscribe

Beta — feedback welcome: [email protected]