Elestio Catalog Updates: 127 New Releases This Week (September 13-19, 2026)

Elestio Catalog Updates: 127 New Releases This Week (September 13-19, 2026)

One hundred and twenty-seven stable releases landed across 57 services in the Elestio catalog between September 13 and 19. Security set the tone: WordPress pushed 11 fixes to ten branches at once, Keycloak closed six CVEs including a privilege escalation, and Redis shipped the same security patch to five supported lines. Where a project shipped one fix across several branches on the same day, those versions share a line.

Security alerts

Patch these first.

  • Keycloak 26.7.4 (Sept 16): six CVEs. The worst is CVE-2026-17526, where the "impersonation" role could impersonate a realm administrator. Also fixed: an unauthenticated DoS, a username takeover, a path-matching bypass, artifact replay on MySQL and MariaDB, and a zlib state leak in SAML redirects.
  • WordPress 7.1.1 and nine older branches down to 6.2.12 (Sept 17): 11 security fixes plus 17 core and 19 block editor bug fixes. WordPress says update immediately.
  • Redis 8.10.2 / 8.8.3 / 8.6.7 / 8.4.7 / 8.2.10 (Sept 17): commands queued in a MULTI block could still touch keys whose ACL permissions were revoked before EXEC, and the cluster bus port now warns when unauthenticated, with a new cluster-bus-port-protected-mode option.
  • Grafana 13.2.2 / 13.1.6 / 13.0.9 / 12.4.11 (Sept 15): CVE-2026-15815, CVE-2026-76154 and CVE-2026-79656.
  • VictoriaMetrics 1.152.0 (Sept 14): authorization bypass in vmauth JWT routing when match_claims is used (GHSA-f99m-22fh-qw96), plus an XSS in the relabel debug page.
  • Mattermost 10.11.24 (Sept 16) and 11.10.2 / 11.9.2 / 11.7.11 (Sept 15): the ESR notes state a High severity security fix. Details follow Mattermost's 30-day disclosure policy.
  • Drupal 11.4.7 / 11.3.17 / 10.6.17 (Sept 16): SA-CORE-2026-013, moderately critical, a CKEditor security update bundled into core.
  • Mastodon 4.7.2 / 4.6.8 / 4.5.18 / 4.4.25 (Sept 15): HEIF support temporarily disabled as a security measure, plus several 500-error fixes.
  • BookStack 26.05.5 (Sept 14): social login accounts from different providers could be mismatched. Upgrade if you have ever enabled more than one social login.
  • Vault 2.1.1 (Sept 17): security bumps to Apache Thrift, x/crypto and gRPC.
  • Appsmith 2.4.1 (Sept 17): netty update for CVE-2026-75595 and input validation fixes.
  • Element Web 1.12.28 (Sept 16): fixes GHSA-wqmv-r2qj-2j9p. Desktop builds now require glibc 2.34.
  • Portainer 2.45.1 / 2.39.8 (Sept 17): outbound requests hardened against SSRF for Helm and Git operations; the LTS line gets a Go toolchain bump covering seven CVEs.
  • Loki 3.7.8 / 3.6.17 (Sept 17): gRPC and containerd security updates rated High.
  • Apache Airflow 3.3.2 (Sept 17): backfill endpoints no longer reveal which backfill IDs exist across DAGs.

Databases

AI and GPU

  • Ollama 0.34.1 (Sept 15) and 0.34.2 (Sept 17): /api/tags drops from 3.1 s to 294 ms cold on large libraries, MLX safetensors create leaves experimental, and 0.34.2 adds a first-run setup offering sign-in or "continue locally".
  • ComfyUI 0.36.0 (Sept 15): new model blueprints and reorganized subgraph categories.
  • Langflow 1.12.2 (Sept 16): Guardrails component gains combined rule and model checks.
  • Gradio 6.28.0 (Sept 18): workflow getting-started templates and faster multipage navigation.
  • JupyterHub 6.0.1 (Sept 14): first patch of the 6.x line.

Development

  • n8n 2.40.1 to 2.40.3 plus 2.39.6 to 2.39.8 and 1.123.81 (Sept 16 to 18): the 2.40 line adds a Microsoft Dataverse node, forced tool calls on the AI Agent's first iteration, and Teams meeting operations.
  • Strapi 5.54.0 (Sept 17): the redesigned Media Library becomes the default, with an always-visible folder tree.
  • Appwrite 2.2.0 (Sept 15): email policies (deny disposable, free, aliased or corporate addresses) reach self-hosted and executions finish moving to ClickHouse.
  • GitLab 19.4.0 (Sept 16): monthly feature release.
  • Authentik 2026.8.3 (Sept 17): outposts refresh sessions when impersonation changes.
  • ToolJet 3.20.227 to 3.20.230-lts (Sept 15 to 18): users can request access to apps, and workspace PATs can call workflows.
  • Budibase 3.45.0 (Sept 14): tool configuration modal and landscape PDF pages.
  • Jenkins 2.582 (Sept 15): weekly release.
  • Hoppscotch 2026.8.1 (Sept 14): patch for the Enterprise edition only.

Hosting and infrastructure

Applications

What stood out this week

Keycloak's impersonation escalation. A role that support teams hand out routinely turning into realm admin is the kind of thing that gets exploited quietly. Patch, then audit who holds it.

Redis fixing ACLs inside transactions. Revoking a permission and having queued commands ignore it is a subtle bug with an obvious consequence. Valkey users should check whether the same logic applies to their line.

TimescaleDB patching last week's headline feature. 2.30.0 shipped DeferredChunkAppend for faster LIMIT queries; 2.30.1 fixes it returning duplicate rows. New planner nodes deserve a week of soak time.

PhotoPrism's face model swap. The migration re-embeds every face in your library, so run it on a quiet night with a backup.

Every service above is available as a managed deployment in the Elestio catalog, with updates, backups and monitoring handled for you.

See you next Sunday 👋