Elestio Catalog Updates: 127 New Releases This Week (September 13-19, 2026)
One hundred and twenty-seven stable releases landed across 57 services in the Elestio catalog between September 13 and 19. Security set the tone: WordPress pushed 11 fixes to ten branches at once, Keycloak closed six CVEs including a privilege escalation, and Redis shipped the same security patch to five supported lines. Where a project shipped one fix across several branches on the same day, those versions share a line.
Security alerts
Patch these first.
- Keycloak 26.7.4 (Sept 16): six CVEs. The worst is CVE-2026-17526, where the "impersonation" role could impersonate a realm administrator. Also fixed: an unauthenticated DoS, a username takeover, a path-matching bypass, artifact replay on MySQL and MariaDB, and a zlib state leak in SAML redirects.
- WordPress 7.1.1 and nine older branches down to 6.2.12 (Sept 17): 11 security fixes plus 17 core and 19 block editor bug fixes. WordPress says update immediately.
- Redis 8.10.2 / 8.8.3 / 8.6.7 / 8.4.7 / 8.2.10 (Sept 17): commands queued in a MULTI block could still touch keys whose ACL permissions were revoked before EXEC, and the cluster bus port now warns when unauthenticated, with a new cluster-bus-port-protected-mode option.
- Grafana 13.2.2 / 13.1.6 / 13.0.9 / 12.4.11 (Sept 15): CVE-2026-15815, CVE-2026-76154 and CVE-2026-79656.
- VictoriaMetrics 1.152.0 (Sept 14): authorization bypass in vmauth JWT routing when match_claims is used (GHSA-f99m-22fh-qw96), plus an XSS in the relabel debug page.
- Mattermost 10.11.24 (Sept 16) and 11.10.2 / 11.9.2 / 11.7.11 (Sept 15): the ESR notes state a High severity security fix. Details follow Mattermost's 30-day disclosure policy.
- Drupal 11.4.7 / 11.3.17 / 10.6.17 (Sept 16): SA-CORE-2026-013, moderately critical, a CKEditor security update bundled into core.
- Mastodon 4.7.2 / 4.6.8 / 4.5.18 / 4.4.25 (Sept 15): HEIF support temporarily disabled as a security measure, plus several 500-error fixes.
- BookStack 26.05.5 (Sept 14): social login accounts from different providers could be mismatched. Upgrade if you have ever enabled more than one social login.
- Vault 2.1.1 (Sept 17): security bumps to Apache Thrift, x/crypto and gRPC.
- Appsmith 2.4.1 (Sept 17): netty update for CVE-2026-75595 and input validation fixes.
- Element Web 1.12.28 (Sept 16): fixes GHSA-wqmv-r2qj-2j9p. Desktop builds now require glibc 2.34.
- Portainer 2.45.1 / 2.39.8 (Sept 17): outbound requests hardened against SSRF for Helm and Git operations; the LTS line gets a Go toolchain bump covering seven CVEs.
- Loki 3.7.8 / 3.6.17 (Sept 17): gRPC and containerd security updates rated High.
- Apache Airflow 3.3.2 (Sept 17): backfill endpoints no longer reveal which backfill IDs exist across DAGs.
Databases
- TimescaleDB 2.30.1 (Sept 17): fixes duplicate rows from the new DeferredChunkAppend node when LIMIT is not pushed down, and a cstring cast error in the same path.
- MariaDB 13.0.2 (Sept 15): point release on the 13.0 line.
- ClickHouse 26.8.8.8-lts and eight more builds across 26.6, 26.7 and 26.8 (Sept 15 to 19): maintenance builds.
- Milvus 3.0.2 (Sept 18) and 2.6.24 (Sept 16): 3.0.2 serializes snapshot restores targeting the same collection.
- Weaviate 1.39.5 / 1.38.16 / 1.38.15 / 1.37.17 (Sept 14 to 18): streamed memtable flushes and the /v1/modules endpoint removed.
- InfluxDB 3.11.5 (Sept 17): patch release.
AI and GPU
- Ollama 0.34.1 (Sept 15) and 0.34.2 (Sept 17): /api/tags drops from 3.1 s to 294 ms cold on large libraries, MLX safetensors create leaves experimental, and 0.34.2 adds a first-run setup offering sign-in or "continue locally".
- ComfyUI 0.36.0 (Sept 15): new model blueprints and reorganized subgraph categories.
- Langflow 1.12.2 (Sept 16): Guardrails component gains combined rule and model checks.
- Gradio 6.28.0 (Sept 18): workflow getting-started templates and faster multipage navigation.
- JupyterHub 6.0.1 (Sept 14): first patch of the 6.x line.
Development
- n8n 2.40.1 to 2.40.3 plus 2.39.6 to 2.39.8 and 1.123.81 (Sept 16 to 18): the 2.40 line adds a Microsoft Dataverse node, forced tool calls on the AI Agent's first iteration, and Teams meeting operations.
- Strapi 5.54.0 (Sept 17): the redesigned Media Library becomes the default, with an always-visible folder tree.
- Appwrite 2.2.0 (Sept 15): email policies (deny disposable, free, aliased or corporate addresses) reach self-hosted and executions finish moving to ClickHouse.
- GitLab 19.4.0 (Sept 16): monthly feature release.
- Authentik 2026.8.3 (Sept 17): outposts refresh sessions when impersonation changes.
- ToolJet 3.20.227 to 3.20.230-lts (Sept 15 to 18): users can request access to apps, and workspace PATs can call workflows.
- Budibase 3.45.0 (Sept 14): tool configuration modal and landscape PDF pages.
- Jenkins 2.582 (Sept 15): weekly release.
- Hoppscotch 2026.8.1 (Sept 14): patch for the Enterprise edition only.
Hosting and infrastructure
- K3s 1.37.0+k3s1 (Sept 15): Kubernetes 1.37 lands in K3s.
- RabbitMQ 4.3.6 (Sept 14): maintenance; Erlang 27 minimum.
- Uptime Kuma 2.5.5 (Sept 16): memory leak in the TCP monitor fixed.
- SigNoz 0.142.0 / 0.142.1 (Sept 16 to 17): AI trace alerts, heatmap queries, and a Markdown text panel.
- Nomad 2.0.7 (Sept 18): task restarts no longer skip shutdown_delay.
Applications
- Nextcloud 35.0.0 (Sept 15): the Hub 26 Summer server. Dedicated Teams app, redesigned Photos, and one-time passwords on file shares.
- Paperless-ngx 3.2.0 (Sept 19): in-place fuzzy matching, CJK search, centralized share links and bundles, and a configurable regex timeout.
- PhotoPrism 260919 (Sept 19): new face detection and embedding models that find small faces and stop merging different people. Existing libraries keep the old model until you run photoprism faces migrate.
- Umami 3.4.0 (Sept 17): chart annotations, read-only MCP support, API key management, and a typed API client.
- Chatwoot 4.18.0 (Sept 18): Captain assignment and tool controls, per-inbox call recording, and message deletion audits.
- PeerTube 8.3.0 (Sept 15): a migration script must be run manually after upgrading; large instances should plan downtime.
- Immich 3.2.1 / 3.2.2 (Sept 14 to 15): connection pool exhaustion during sync and search modal fixes.
- Jellyfin 12.1 (Sept 15): 47 fixes.
- Ghost 6.64.0 (Sept 15): members choosing no newsletter were being subscribed to all of them. Fixed.
- Vaultwarden 1.37.3 (Sept 13): newer web vault password change fix and SSO_SIGNUPS_ALLOWED.
- ERPNext 16.35.0 / 15.121.3 (Sept 15): the "Print IRS 1099 Forms" button is removed on both lines.
- Moodle 5.2.3 / 5.1.7 / 5.0.10 / 4.5.14 (Sept 13): maintenance point releases following the September 9 security set.
- Metabase 0.63.18.1 (Sept 18), Flarum 1.8.20 (Sept 17), Invoice Ninja 5.13.41 to 5.13.43 (Sept 17 to 18), Wekan 11.78 to 11.87 (Sept 14 to 19), and Jitsi Meet 9459 to 9463 (Sept 18): patch and packaging releases.
What stood out this week
Keycloak's impersonation escalation. A role that support teams hand out routinely turning into realm admin is the kind of thing that gets exploited quietly. Patch, then audit who holds it.
Redis fixing ACLs inside transactions. Revoking a permission and having queued commands ignore it is a subtle bug with an obvious consequence. Valkey users should check whether the same logic applies to their line.
TimescaleDB patching last week's headline feature. 2.30.0 shipped DeferredChunkAppend for faster LIMIT queries; 2.30.1 fixes it returning duplicate rows. New planner nodes deserve a week of soak time.
PhotoPrism's face model swap. The migration re-embeds every face in your library, so run it on a quiet night with a backup.
Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.
See you next Sunday 👋