Elestio Catalog Updates: 106 New Releases This Week (September 20-26, 2026)

Elestio Catalog Updates: 106 New Releases This Week (September 20-26, 2026)

One hundred and six stable releases shipped across 47 services in the Elestio catalog between September 20 and 26. The headline is security again: GitLab pushed a critical patch for two flaws in its regular expression engine, and WordPress 7.1.2 was being exploited the day it came out. If a project shipped one fix to several branches on the same day, those versions are grouped on one line.

Security alerts

Patch these first.

  • GitLab 19.4.1 / 19.3.3 / 19.2.7 (Sept 23): a critical patch release. It fixes two Critical issues in the regular expression parser and compiler (a double free and an integer overflow), a High severity XSS in the merge request diff viewer, and an authorization gap in MCP API scope enforcement. GitLab says to upgrade immediately.
  • WordPress 7.1.2 and nine older branches down to 6.2.13 (Sept 22): fixes CVE-2026-87902 (CVSS 9.2), a path traversal in page template resolution that lets an unauthenticated attacker include a local PHP file. Exploitation attempts started the same day.
  • Open WebUI 0.11.4 (Sept 21): access control fixes. Credentials are no longer logged during identity provider sign-in, and role mapping is now enforced for federated logins. The slim image also drops to about 175 MB.
  • Discourse 2026.9.0 plus 2026.8.1, 2026.7.3 and 2026.1.9 (Sept 22): three security fixes, backported to every supported line. 2026.9.0 also adds a built-in MCP server.
  • Label Studio 1.23.1 (Sept 25): SSRF protection and blocking of local ML backends are now on by default. It needs PostgreSQL 14 or newer because it now runs on Django 5.2.
  • Huginn v2026.09.22 (Sept 21): legacy JSONPath method calls are limited to an allowlist (GHSA-9x7r-mpvj-vj8v), and RFC 9535 evaluation becomes the default.
  • Wekan 12.04 (Sept 25): fixes "InactiveBleed". Disabled accounts could previously get new sessions through REST or keep using revoked credentials.
  • Appsmith 2.4.2 (Sept 24): bundled dependency updates for reported vulnerabilities. This is also the last reminder that Appsmith AI queries stop working on September 30.

Databases

  • ClickHouse 26.9.1 (Sept 21), up to 26.9.3 on Sept 26, plus seven builds on the 26.3, 26.7 and 26.8 lines: the new monthly release. The default compression switches from LZ4 to ZSTD(3), the analyzer can no longer be disabled, the CatBoost integration is removed, and CREATE TOKEN generates short-lived secrets with scoped grants. Read the backward-incompatible list before you upgrade.
  • Weaviate 1.39.7 (Sept 25), with 1.39.6 and 1.38.17 (Sept 22): fixes a RAFT boot-time race and async replication issues, and improves LSM store performance.
  • M3DB 1.6.0 (Sept 25): library dependency changes only; on-disk and wire formats are unchanged.
  • Neo4j 5.26.31 (Sept 21): LTS maintenance.

AI and GPU

  • Ollama 0.34.4 (Sept 23): structured outputs on thinking models now run in a single pass, and intermittent "model not found" errors on large libraries are fixed.
  • ComfyUI 0.37.0 (Sept 21), up to 0.37.4 (Sept 25): auto-detects fast disks, and keeps the text encoder on the GPU with dynamic VRAM.
  • AnythingLLM 1.16.2 (Sept 22): adds Google Vertex AI as a provider, a generate-image agent skill, and optional arguments for agent flow variables.
  • Langflow 1.12.3 (Sept 22): adds a slash command menu and a 100-step budget to the assistant. Missing MCP servers now return a proper 404.

Development

  • n8n 2.41.0 (Sept 22), up to 2.41.3, plus 2.40.6 to 2.40.7 and 1.123.82: Agents are enabled by default from 2.41.1, pubsub subscriptions recover after a Redis reconnect, and OpenTelemetry export keeps working after a restart.
  • Appwrite 2.3.0 (Sept 23): dev keys are removed entirely, and every console link now comes from a single _APP_CONSOLE_URL. Search your scripts for dev key headers before you upgrade.
  • Meilisearch 1.54.0 (Sept 21): breaking changes to the experimental dynamic search rules API. Rules migrate automatically if you upgrade with --upgrade-db.
  • Directus 12.4.0 (Sept 22) and 12.4.1: MapLibre jumps from 1.15 to 6.9, so maps now need WebGL2 and no longer render on Safari 14 or older.
  • Strapi 5.55.0 (Sept 23) and 5.55.1: content type folders, and token management now shows up in audit logs. 5.55.1 reverts a documentation plugin change that slowed projects down.
  • Zitadel 4.19.1 (Sept 23): skip 4.18.0, whose setup step fails. Go straight to 4.19.x.
  • Supabase self-hosted 0.8.2 (Sept 23), Hasura 2.51.0 (Sept 21), ToolJet 3.20.231 to 3.20.233-lts (Sept 22 to 25), Budibase 3.46.0 (Sept 21), Jenkins 2.582 and 2.583 (Sept 20 and 22) and Hoppscotch 2026.8.2 (Sept 23, Enterprise sync only): maintenance releases.

Hosting and infrastructure

  • Prometheus 3.15.0 (Sept 24): subqueries in range queries that aren't aligned to the step no longer evaluate past the last step, which used to inflate peakSamples and waste storage reads.
  • SigNoz 0.143.0 (Sept 23): adds AI observability for LLM and agent workloads, with token, cost and latency views and attributes normalized to OpenTelemetry gen_ai.* keys.
  • Mailu 2024.06.59 (Sept 23): Roundcube 1.6.18, fixing a cURL SSL option error on modern Roundcube.
  • Zabbix 7.4.15 and 7.0.31 (Sept 22 to 23): maintenance releases.

Applications

  • Zammad 7.2.0 (Sept 23): a tamper-proof admin audit log, better spam protection, and finer control over AI usage and cost.
  • ERPNext 16.36.0 / 15.121.4 (Sept 23): adds access checks to several actions and record lookups. Custom permission setups get the new grants during the upgrade, but test your roles.
  • BookStack v26.09 (Sept 24): a UI layout customization system. APP_KEY must now be set, with no silent fallback.
  • Drupal 11.4.8 / 10.6.18 (Sept 26): fixes forms that were silently unpublishing entities on save, and a memory leak in long-running processes.
  • Wekan 12.05 (Sept 26): flow analytics pages with Monte Carlo forecasts, closing a nine-release week.
  • Penpot 2.18.0 (Sept 23): Line and Arrow tools, comments inside the workspace, and a fix for the MCP integration hanging in background tabs.
  • Paperless-ngx 3.2.1 (Sept 20): the search index now rebuilds automatically when Tantivy files are missing.
  • Ghost 6.65.0 (Sept 22): sitemap rebuilds use less memory and no longer slow the site down.
  • Mautic 7.2.1 (Sept 23): campaign emails now arrive at the right local time for contacts in timezones ahead of UTC.
  • Nextcloud 35.0.1 (Sept 24), Mattermost 11.11.1 (Sept 24), Zulip 12.3 (Sept 21), Matomo 5.14.0 (Sept 21), Metabase 0.63.18.2 (Sept 23), Element Web 1.12.29 (Sept 22) and Jitsi Meet 9479 to 9482 (Sept 25): patch releases.

What stood out this week

GitLab's regex engine bugs. Two memory safety flaws in the parser that handles your regular expressions, both rated Critical. Anything that lets users supply a pattern can reach it. It's the second critical GitLab patch in a row, so a tested upgrade routine is worth more than a heroic one.

ClickHouse switching its default compression. ZSTD(3) instead of LZ4 means smaller parts and more CPU per insert. Existing parts are untouched, but watch insert latency on write-heavy clusters after the upgrade.

Security defaults tightening across the catalog. Label Studio blocks private network requests, Huginn restricts JSONPath, and Wekan finally cuts off disabled accounts. Each can break an integration that relied on the old behavior.

Agents moving to default-on. n8n turned Agents on by default, SigNoz added cost tracking for LLM spans, and Discourse shipped a built-in MCP server. If you haven't decided how your team governs these features, now's the time.

Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.

See you next Sunday 👋