Elestio Catalog Updates: 113 New Releases This Week (September 27 - October 3, 2026)

Elestio Catalog Updates: 113 New Releases This Week (September 27 - October 3, 2026)

One hundred and thirteen stable releases shipped across 47 services in the Elestio catalog between September 27 and October 3. Most of the urgent work this week is in identity: Keycloak fixed 14 CVEs in one patch release, and Zitadel closed two account takeover bugs. If a project shipped one fix to several branches on the same day, those versions are grouped on one line.

Security alerts

Patch these first.

  • Keycloak 26.7.5 (Sept 30): 14 CVEs, 10 of them in Keycloak itself. They include an incomplete fix for the CIBA brute-force lockout bypass (CVE-2026-16103), SAML redirect binding parameter pollution (CVE-2026-18217), client secrets visible to the view-clients role (CVE-2026-89298), and device grants still issuing tokens to locked accounts (CVE-2026-88770).
  • Zitadel 4.19.2 (Sept 28): two High severity account takeovers, one through SAML identity provider confusion and one through the unsigned Login V2 session cookie. Set ZITADEL_SESSION_COOKIE_SECRET (at least 32 characters, identical on every replica) on the Login UI before you upgrade, or it reports not ready.
  • Grafana 13.2.3 / 13.1.7 / 13.0.10 / 12.4.12 (Sept 29): fixes CVE-2026-13719, CVE-2026-13720 and CVE-2026-81841. The 13.0 and 12.4 lines also fix CVE-2026-81842.
  • PeerTube 8.3.1 (Sept 28): fixes vulnerabilities rated medium to critical. Details will be published a week after release, so upgrade before they go public.
  • OpenProject 17.8.1 and 17.9.0 (Sept 30): the meeting API leaked private work package subjects (GHSA-4p83-c4wg-59q4). Separately, S3 direct uploads could be replayed to swap a file after it passed antivirus scanning (GHSA-c5j2-2mfg-49h7).
  • Gitea 28.0.0 (Sept 30): Gitea now rejects invalid and duplicate Git objects on push, and approval gates hold for cancelled fork PR runs. Git network traffic now goes through an internal egress proxy, which is a breaking change, so review your egress settings.
  • Wekan 12.17 (Oct 3): fixes SamlSubjectBleed (GHSA-966m-4qgp-j8w4), where a different SAML subject could take over an existing account. The day before, 12.15 fixed CacheBleed and fifteen more named issues.
  • Label Studio 1.23.2 (Sept 29): pip installs saved the generated SECRET_KEY in a file any local user could read. The file is locked down now, but if anyone else can read that machine's data directory, rotate the key.
  • Prometheus 3.13.4 (Sept 29): updates gRPC to fix memory exhaustion from fragmented HTTP/2 DATA frames (GO-2026-6348).

Databases

  • OpenSearch 3.9.0 (Sept 29): drain and finish APIs for zero-downtime node deployments and automatic restore of remote-store primaries when a node is lost.
  • TimescaleDB 2.30.2 (Sept 29): fixes a crash when merging chunks with different column layouts, and DROP SCHEMA CASCADE no longer leaves orphaned compressed chunks. The granular refresh options are renamed to timescaledb.cagg_granular_refresh_*.
  • Milvus 3.0.2 (Sept 28), plus 2.6.24 and 2.6.25: removes contention in filtered search, group-by and index builds. On the 2.6 line, peak memory during segment loading is lower.
  • Weaviate 1.39.8 / 1.38.18 (Oct 1): backup endpoints no longer expose collections the caller can't access.
  • ClickHouse 26.9.9 (Oct 3): ten patch builds this week across the 26.9, 26.8 LTS, 26.7 and 26.3 LTS lines.
  • Apache Kafka 4.2.2 (Sept 28) and InfluxDB 3.12.0 (Oct 1): a bug-fix release for Kafka 4.2 and a new InfluxDB 3 minor release.

AI/GPU

  • LibreChat 0.8.8 (Oct 1): you can now interrupt, steer and approve tool calls while an agent runs. It also adds background tasks, a Langfuse trace viewer and experimental plugins that bundle Skills and MCP servers.
  • Ollama 0.35.0 (Sept 29) and 0.35.1 (Oct 2): decision models through /v1/systemone. They return choices and scores instead of text, which suits ticket triage and model routing. 0.35.1 adds Cloudflare's multimodal Clef models.
  • Langflow 1.12.4 (Sept 29): rejects mixed DNS answers that dodge IP allowlists, fails closed on unowned build jobs, and replaces Passlib with bcrypt.
  • InvokeAI 6.14.2 (Sept 27): fixes a path traversal in model keys and adds custom fonts for the Canvas text tool.
  • AnythingLLM 1.17.0 (Oct 1): malformed agent WebSocket frames no longer crash the server, and spreadsheet dates import correctly.
  • ComfyUI 0.38.0 (Sept 29) through 0.38.2 and Gradio 6.29.0 (Sept 29) plus 6.29.1: ComfyUI drops its torchaudio dependency and speeds up several models, and Gradio adds height controls for accordions and tabs.

Development

  • Keycloak 26.8.0 (Oct 1): stateless multi-cluster mode and the SCIM API are now supported. It also adds token exchange delegation for AI agents with consent, and OID4VCI wallet credentials move to preview.
  • NocoDB 2026.09.1 (Sept 29): one MCP connection now reaches every base you pick, and the server has 199 tools. Account-wide MCP is not in the Community Edition.
  • Appsmith 2.4.3 (Sept 30): Appsmith AI reached end of life on September 30. MCP sessions now use the Redis set in APPSMITH_REDIS_URL. If you use restricted ACLs, allow appsmith:mcp:*.
  • Strapi 5.56.0 (Sept 30): audit logs now record admin account, password and webhook changes.
  • n8n 2.42.0 (Sept 29) through 2.42.2, with 2.41.4 to 2.41.6 and 1.123.83: queued executions no longer hang waiting on Bull, and task runners survive unhandled promise rejections.
  • Meilisearch 1.54.3 / 1.53.3 / 1.52.4 (Oct 1): an important stability fix on three lines.
  • Hoppscotch 2026.9.0 (Sept 30), Jenkins 2.580.1 LTS (Sept 30) with weekly 2.584, Zitadel 4.19.3 / 4.19.4 (Sept 29 and Oct 1), Budibase 3.47.0 (Sept 28) and ToolJet 3.20.234 to 3.20.237 LTS: feature and patch releases.

Hosting & Infrastructure

  • VictoriaMetrics 1.153.0 (Sept 28): two security fixes (GHSA-8g4f-32hw-vqf8, GHSA-xxqh-2hcc-9fp6). Read the update note first: pure Go builds can fail to read valid blocks and crash. linux/amd64 and linux/arm64 builds are not affected.
  • K3s 1.37.1 / 1.36.5 / 1.35.9 / 1.34.12 (Oct 1 to 2): restoring compressed etcd snapshots works again, and gRPC is updated for CVE-2026-84445. On the 1.35 and 1.34 lines, the Traefik chart 40.x renames the ingress-nginx provider to kubernetesIngressNGINX.
  • Mailu 2024.06.60 / .61 (Sept 28 and 30): DEFER_ON_TLS_ERROR=False and two other boolean settings now actually turn off, and stale webmail cookies are cleared on SSO login.
  • SigNoz 0.144.0 (Sept 29): a new alert rules list API and onboarding for vLLM, SGLang and Karpenter.

Applications

What stood out this week

Identity got the most security fixes. Keycloak and Zitadel together fixed 17 security issues, several of them account takeovers or lockout bypasses. A bug in your login layer affects every app behind it, so patch these two first.

Some upgrades need a config change first. Zitadel needs a cookie secret before it starts, BookStack needs an APP_KEY, and Appsmith's MCP needs Redis ACLs. Read the upgrade notes before you pull the new image.

Some versions are best skipped. VictoriaMetrics told users of pure Go builds not to upgrade, and Ghost pulled 6.66.0. Check which build you run before you hit update.

Agents are getting controls. LibreChat added tool-call approval, Keycloak added delegation tokens, and NocoDB's MCP server never grants more than your own role. Agent features this week came with limits built in.

Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.

See you next Sunday 👋