Elestio Catalog Updates: 125 New Releases This Week (October 4-10, 2026)
One hundred and twenty-five stable releases shipped across 51 services in the Elestio catalog between October 4 and October 10. A lot of this week's security work fixed the same kind of bug: a permission check that didn't hold. Vault, Portainer, Appwrite and ToolJet all patched cases where someone could do more than their role allowed. If a project shipped one fix to several branches on the same day, those versions share a line.
Security alerts
- WordPress 7.1.3 (Oct 6): seven security fixes, backported all the way to the 6.2 branch (6.2.14). They include a stored XSS on the Comments screen through pending comments, a second-order SQL injection in the WXR export, and unauthenticated disclosure of comments on private posts.
- Vaultwarden 1.37.4 (Oct 5): seven advisories. The worst is rated High (8.1): revoked organization members could keep access (GHSA-69q9-v8p6-xvx3). The others cover two-factor login, invitations, attachments, event logs and cipher sharing.
- Vault 2.1.2 (Oct 7): exact-deny ACL policies could be dodged with case-variant role names, and plugin catalog entries restored from a snapshot could run a binary outside
plugin_directory. One breaking change: ACME with the defaultsign-verbatimpolicy now rejects CSRs carrying URI, email or Other SANs. - Portainer 2.45.2 LTS (Oct 8): non-admins could bypass "Hide bind mounts" and read host files through Compose
configs,secretsorenv_file. The server and agent also skipped TLS verification when talking to the in-cluster Kubernetes API. - Appwrite 1.9.7 (Oct 8): a project admin could copy another project's databases on the same instance through a local migration. Migration sources must now be public, and JWTs die with their session.
- Rocket.Chat 8.9.0 LTS (Oct 5): a security hotfix for Omnichannel agent and manager endpoints and the contact and chat history data they return. Support for 7.10.x ended September 30, and 8.9 is the direct upgrade target.
- Open WebUI 0.12.0 (Oct 10): carries security and access-control fixes, and not all of them are listed in the notes. It also adds enforced two-factor sign-in (
ENABLE_MFA) with recovery codes. - Langflow 1.12.5 (Oct 6): built-in code execution is now limited to administrators, chat attachments stay in authorized storage, and MCP management responses no longer show server credentials.
- Smaller fixes: ToolJet 3.20.242 LTS (Oct 9) now enforces
ENABLE_SIGNUPon the signup endpoint, Qdrant 1.19.2 (Oct 5) accepts only read-write keys on internal gRPC, and Mage AI 0.9.80 (Oct 9) closes a shell injection when adding Git hosts.
Databases
- Weaviate 1.40.0 (Oct 7): Namespaces and drop vector index are now generally available, and the release adds MUVERA for HFresh and RQ-4 quantization. Namespaces require a license. Patch builds 1.39.9 to 1.39.11 and 1.38.19 to 1.38.20 shipped too, and 1.39.11 pins zlib for CVE-2026-85091.
- ClickHouse 26.9.15 (Oct 10): 26 patch builds this week across the 26.9, 26.8 LTS, 26.7 and 26.3 LTS lines.
- InfluxDB 3.11.6 (Oct 5) and Neo4j 5.26.32 (Oct 8): maintenance releases.
AI/GPU
- Open WebUI 0.12.0 (Oct 10): beyond the MFA work, voice mode can run through an OpenAI Realtime model that hands real tasks to your chat model. Shared chats can now accept replies from everyone they're shared with, and models get named controls such as a reasoning-effort slider.
- Ollama 0.40.1 (Oct 7) and 0.40.2 (Oct 8): older models get upgraded in the background the first time you run them, and the originals stay on disk as backups. The release notes include a script to delete those backups if disk space is tight.
- LobeHub 2.2.19 (Oct 7): a security hardening pass, MCP OAuth fixes, and a GitHub App loop that routes pull request feedback back to the agent that opened it.
- ComfyUI 0.39.0 (Oct 5) through 0.39.2, Gradio 6.30.0 (Oct 8) and Jupyter Notebook 7.5.8 (Oct 5): ComfyUI adds higher-quality video defaults, Gradio adds an app view to
gr.Workflow, and Notebook moves to JupyterLab 4.5.11.
Development
- Appwrite 2.4.0 (Oct 8): custom profile photos, Webflow sign-in, push to a user without a device target, and webhook retries that only resend what failed. Read the upgrade section first if you reach private hosts for OAuth2, webhooks or messaging.
- Directus 12.5.0 (Oct 7): TFA enforcement now respects IP allow lists. Policies storing a malformed subnet such as
10.0.0.0/ 24will now fail every request, so checkip_accessvalues before upgrading. - Appsmith 2.5.0 (Oct 9): Git-connected apps move to schema 13, and changing a datasource setting now asks for credentials again.
- Gitea 28.1.0 (Oct 6): adds missing checks to several API and web handlers and uses READ COMMITTED transactions on MySQL and MariaDB.
- Strapi 5.57.0 (Oct 7): renaming an attribute now keeps its data, and review workflow actions go into the audit log.
- n8n 2.42.6 (Oct 9) with five more patch builds, Node-RED 5.0.8 and 4.1.16 (Oct 8), PocketBase 0.40.5 and 0.22.56 (Oct 8), SonarQube 26.10 (Oct 5), Apache Solr 9.11.0 (Oct 4), Budibase 3.48.0 (Oct 5), Jenkins 2.585 (Oct 6), Huginn 2026.10.04 (Oct 4) and five more ToolJet LTS builds: feature and patch releases.
Hosting & Infrastructure
- SigNoz 0.145.0 (Oct 5): fine-grained authorization now covers users and password reset tokens.
- Loki Operator 0.12.0 (Oct 7): updates gRPC and golang.org/x/net to clear High severity advisories.
- Uptime Kuma 2.5.6 (Oct 9): dependency security updates and a fix for the average response badge.
Applications
- Flarum 2.0.0 (Oct 9): the first stable 2.0 release. Extensions written for 1.x need 2.0-compatible versions, so check yours before upgrading.
- Immich 3.3.0 (Oct 7) and 3.3.1: share people with other users, birthday memories, and OAuth claims synced on every login.
- ERPNext 16.50.0 (Oct 6) and 15.122.0: breaking change. User permissions are now checked on records used in accounting, stock and manufacturing actions.
- Paperless-ngx 3.3.0 (Oct 6): barcode contents are stored and searchable, and the AI features accept a separate embedding API key.
- PhotoPrism October 7: better image classification and NSFW detection, and every built-in model can now run on an NVIDIA GPU.
- Ghost 6.69.0 (Oct 7) and 6.68.0, Jellyfin 12.2 (Oct 5), Syncthing 2.1.6 (Oct 6), Metabase 64.1 (Oct 7) with 64.1.5 and 63.19.6, Zammad 7.2.2 and 7.2.1, Drupal 11.4.9 (Oct 9), Mattermost 11.7.12 (Oct 8), Penpot 2.18.3 and 2.18.2, Matomo 5.14.1 (Oct 4), Invoice Ninja 5.13.47 with three earlier builds, and Wekan 12.18 to 12.27: feature and patch releases. Wekan 12.26 adds imports from 20 more tools, including Planner, monday.com and Linear.
What stood out this week
Authorization bugs led the list. Vault, Portainer, Appwrite, ToolJet, Vaultwarden and Langflow all fixed cases where a user or role could reach more than it should. If you rely on role separation in any of these, patch before anything else.
Some fixes now break bad configs. Directus rejects malformed subnets, Vault rejects unverified SANs in ACME, and ERPNext checks permissions it used to skip. Each one can stop a request that worked last week, so read the upgrade notes.
Two-factor keeps spreading. Open WebUI can now enforce MFA for every user, and Rocket.Chat fixed 2FA for SAML sign-in. With shared chats now letting several people write in one conversation, it's a good week to turn MFA on.
Watch your disk after Ollama 0.40. Upgraded models keep a backup copy until a future release cleans them up, so check free space on GPU boxes with a big model library.
Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.
See you next Sunday 👋