Elestio Catalog Updates: 125 New Releases This Week (October 4-10, 2026)

Elestio Catalog Updates: 125 New Releases This Week (October 4-10, 2026)

One hundred and twenty-five stable releases shipped across 51 services in the Elestio catalog between October 4 and October 10. A lot of this week's security work fixed the same kind of bug: a permission check that didn't hold. Vault, Portainer, Appwrite and ToolJet all patched cases where someone could do more than their role allowed. If a project shipped one fix to several branches on the same day, those versions share a line.

Security alerts

  • WordPress 7.1.3 (Oct 6): seven security fixes, backported all the way to the 6.2 branch (6.2.14). They include a stored XSS on the Comments screen through pending comments, a second-order SQL injection in the WXR export, and unauthenticated disclosure of comments on private posts.
  • Vaultwarden 1.37.4 (Oct 5): seven advisories. The worst is rated High (8.1): revoked organization members could keep access (GHSA-69q9-v8p6-xvx3). The others cover two-factor login, invitations, attachments, event logs and cipher sharing.
  • Vault 2.1.2 (Oct 7): exact-deny ACL policies could be dodged with case-variant role names, and plugin catalog entries restored from a snapshot could run a binary outside plugin_directory. One breaking change: ACME with the default sign-verbatim policy now rejects CSRs carrying URI, email or Other SANs.
  • Portainer 2.45.2 LTS (Oct 8): non-admins could bypass "Hide bind mounts" and read host files through Compose configs, secrets or env_file. The server and agent also skipped TLS verification when talking to the in-cluster Kubernetes API.
  • Appwrite 1.9.7 (Oct 8): a project admin could copy another project's databases on the same instance through a local migration. Migration sources must now be public, and JWTs die with their session.
  • Rocket.Chat 8.9.0 LTS (Oct 5): a security hotfix for Omnichannel agent and manager endpoints and the contact and chat history data they return. Support for 7.10.x ended September 30, and 8.9 is the direct upgrade target.
  • Open WebUI 0.12.0 (Oct 10): carries security and access-control fixes, and not all of them are listed in the notes. It also adds enforced two-factor sign-in (ENABLE_MFA) with recovery codes.
  • Langflow 1.12.5 (Oct 6): built-in code execution is now limited to administrators, chat attachments stay in authorized storage, and MCP management responses no longer show server credentials.
  • Smaller fixes: ToolJet 3.20.242 LTS (Oct 9) now enforces ENABLE_SIGNUP on the signup endpoint, Qdrant 1.19.2 (Oct 5) accepts only read-write keys on internal gRPC, and Mage AI 0.9.80 (Oct 9) closes a shell injection when adding Git hosts.

Databases

  • Weaviate 1.40.0 (Oct 7): Namespaces and drop vector index are now generally available, and the release adds MUVERA for HFresh and RQ-4 quantization. Namespaces require a license. Patch builds 1.39.9 to 1.39.11 and 1.38.19 to 1.38.20 shipped too, and 1.39.11 pins zlib for CVE-2026-85091.
  • ClickHouse 26.9.15 (Oct 10): 26 patch builds this week across the 26.9, 26.8 LTS, 26.7 and 26.3 LTS lines.
  • InfluxDB 3.11.6 (Oct 5) and Neo4j 5.26.32 (Oct 8): maintenance releases.

AI/GPU

  • Open WebUI 0.12.0 (Oct 10): beyond the MFA work, voice mode can run through an OpenAI Realtime model that hands real tasks to your chat model. Shared chats can now accept replies from everyone they're shared with, and models get named controls such as a reasoning-effort slider.
  • Ollama 0.40.1 (Oct 7) and 0.40.2 (Oct 8): older models get upgraded in the background the first time you run them, and the originals stay on disk as backups. The release notes include a script to delete those backups if disk space is tight.
  • LobeHub 2.2.19 (Oct 7): a security hardening pass, MCP OAuth fixes, and a GitHub App loop that routes pull request feedback back to the agent that opened it.
  • ComfyUI 0.39.0 (Oct 5) through 0.39.2, Gradio 6.30.0 (Oct 8) and Jupyter Notebook 7.5.8 (Oct 5): ComfyUI adds higher-quality video defaults, Gradio adds an app view to gr.Workflow, and Notebook moves to JupyterLab 4.5.11.

Development

  • Appwrite 2.4.0 (Oct 8): custom profile photos, Webflow sign-in, push to a user without a device target, and webhook retries that only resend what failed. Read the upgrade section first if you reach private hosts for OAuth2, webhooks or messaging.
  • Directus 12.5.0 (Oct 7): TFA enforcement now respects IP allow lists. Policies storing a malformed subnet such as 10.0.0.0/ 24 will now fail every request, so check ip_access values before upgrading.
  • Appsmith 2.5.0 (Oct 9): Git-connected apps move to schema 13, and changing a datasource setting now asks for credentials again.
  • Gitea 28.1.0 (Oct 6): adds missing checks to several API and web handlers and uses READ COMMITTED transactions on MySQL and MariaDB.
  • Strapi 5.57.0 (Oct 7): renaming an attribute now keeps its data, and review workflow actions go into the audit log.
  • n8n 2.42.6 (Oct 9) with five more patch builds, Node-RED 5.0.8 and 4.1.16 (Oct 8), PocketBase 0.40.5 and 0.22.56 (Oct 8), SonarQube 26.10 (Oct 5), Apache Solr 9.11.0 (Oct 4), Budibase 3.48.0 (Oct 5), Jenkins 2.585 (Oct 6), Huginn 2026.10.04 (Oct 4) and five more ToolJet LTS builds: feature and patch releases.

Hosting & Infrastructure

  • SigNoz 0.145.0 (Oct 5): fine-grained authorization now covers users and password reset tokens.
  • Loki Operator 0.12.0 (Oct 7): updates gRPC and golang.org/x/net to clear High severity advisories.
  • Uptime Kuma 2.5.6 (Oct 9): dependency security updates and a fix for the average response badge.

Applications

What stood out this week

Authorization bugs led the list. Vault, Portainer, Appwrite, ToolJet, Vaultwarden and Langflow all fixed cases where a user or role could reach more than it should. If you rely on role separation in any of these, patch before anything else.

Some fixes now break bad configs. Directus rejects malformed subnets, Vault rejects unverified SANs in ACME, and ERPNext checks permissions it used to skip. Each one can stop a request that worked last week, so read the upgrade notes.

Two-factor keeps spreading. Open WebUI can now enforce MFA for every user, and Rocket.Chat fixed 2FA for SAML sign-in. With shared chats now letting several people write in one conversation, it's a good week to turn MFA on.

Watch your disk after Ollama 0.40. Upgraded models keep a backup copy until a future release cleans them up, so check free space on GPU boxes with a big model library.

Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.

See you next Sunday 👋