Elestio Catalog Updates: 45 New Releases This Week (August 9-15, 2026)
Forty-five services in the Elestio catalog published new releases between August 9 and 15, two of which are Helm chart updates rather than new application versions. It was a heavier security week than usual: WordPress patched a remote code execution flaw serious enough to backport across ten branches, and Gitea, Portainer, and Nextcloud all shipped fixes of their own. Here's everything worth knowing, sorted by category.
Security Alerts
WordPress 7.0.4 (August 12) is the one to act on. It patches CVE-2026-65640, a High-severity authenticated remote code execution bug. An attacker with Author-level access or higher could upload a malicious PostScript file and get code execution, but only on installations using Imagick together with Ghostscript. The fix checks file contents before handing them to Imagick. WordPress backported it across every branch to 4.7, which tells you how seriously they took it.
Gitea 1.27.2 (August 13) leads its changelog with a security fix to collaborator access mode and httpsign handling, plus a WebAuthn fix that sets user verification per request.
Portainer 2.39.6 LTS (August 13) adds SSRF protection with a configurable allow-list (off, audit, or enforce modes) and fixes a path traversal in the Swarm compose deployer where config and secret file paths could escape the project root.
Nextcloud 34.0.3, 33.0.8, and 32.0.14 (August 13) are maintenance releases across three supported Hub branches carrying stability and security fixes, several sourced through Nextcloud's HackerOne program.
Databases
MariaDB 10.6.28 (August 13). Maintenance on the 10.6 LTS branch.
A quiet week otherwise. PostgreSQL, Redis, and ClickHouse held steady.
AI & GPU
Ollama 0.32.13 (August 14). Adds developer instruction support for qwen3.8. Ollama shipped seven point releases across the week, so pin a version if you need reproducible behavior.
ComfyUI 0.33.1 (August 13). Two releases in one day, following 0.33.0.
AnythingLLM 1.16.0 (August 13). New minor version.
InvokeAI 6.13.8 (August 13). Patch release.
Gradio 6.24.0 (August 12). Core bumped to 1.11.0 and the client to 2.5.0 alongside it.
Zep ingest 0.2.0 (August 12). New ingest component.
Langflow 1.11.3 (August 11). Patch release.
JupyterLab 4.6.3 (August 10). Patch on the 4.6 line.
JupyterHub 5.5.1 (August 10). Stable patch, with 6.0.0 betas later in the week.
Development
Gitea 1.27.2 (August 13). Covered in Security Alerts above.
n8n 2.34.6 (August 14). Stability work on the 2.34 line. The 2.35 branch is in prerelease.
PocketBase 0.39.11 (August 14). Patch release, with 0.22.52 shipped for the older branch the same day.
Zitadel 4.17.1 (August 14). Follows 4.17.0 two days earlier, which fixed invite codes for users whose auth methods were all removed and stopped Postgres logging a password during role creation.
ToolJet 3.20.212 LTS (August 14). Four LTS patches across the week.
Meilisearch 1.53.1 (August 13). The 1.53.0 release adds sharding for foreign filters and raises the foreign filter document limit from 100 to 1,000, plus new indexSize and usedIndexSize stats fields.
Appsmith 2.3 (August 13). New minor version.
Apache Airflow 3.3.1 (August 12). Note the pandas 3 change: DataFrame XComs now record pandas.DataFrame rather than pandas.core.frame.DataFrame, so the name written to the metadata database depends on your pandas version. Read that one before upgrading a busy scheduler.
Strapi 5.52.0 (August 12). MCP actions now get recorded in audit logs, Corsican locale codes added, and proxy settings improved in the Koa server config.
Supabase self-hosted 0.8.0 (August 11). New self-hosted bundle.
Budibase 3.42.0 (August 10). New minor version.
Authentik 2026.8.0 RC7 (August 10). Release candidate; 2026.8 stable should land shortly.
Hosting & Infrastructure
SigNoz 0.137.1 (August 14). 0.137.0 brought a GCP cloud integration, an AI explorer tab, member role assignment through the user_roles API, and a v2 reset-password endpoint.
WG-Easy 15.4.0 (August 14). Adds OAuth integration for external authentication, general security hardening, improved TOTP handling, and Japanese, Hindi, and Korean translations.
Portainer 2.39.6 LTS (August 13). Covered in Security Alerts above.
Nomad 2.0.5 (August 13). Patch on the 2.0 line.
Mailu 2024.06.58 (August 12). Maintenance release.
Loki Helm chart 7.3.0 (August 10). Chart update for Kubernetes deployments.
Prometheus 3.14.0 entered release candidate on August 11 but has not gone stable yet.
Applications
Wekan 10.95 (August 15). Eight point releases across the week, normal cadence here.
Invoice Ninja 5.13.32 (August 15). Patch release.
Mattermost 11.10.0 (August 14). New minor, shipped alongside patches for the 11.7, 11.8, 11.9, and 10.11 branches.
Discourse (August 14). Rolling release. Stable, beta, and ESR channels all refreshed.
ERPNext 16.32.1 (August 14). Two releases on both the 16 and 15 branches this week.
Nextcloud 34.0.3 (August 13). Covered in Security Alerts above. Nextcloud 35 also entered beta.
Mastodon 4.6.6 (August 13). Fixes connection errors when processing fediverse:creator that blocked preview card creation, and a bug making the web UI inaccessible on URLs ending in .zip. Requires asset recompilation, so read the upgrade notes. Patches also went out for 4.5.16 and 4.4.23, with 4.7.0 in release candidate.
Jitsi Meet 9384 (August 13). Six builds across the week on the project's usual rapid cadence.
OpenProject 17.7.2 (August 13). Bug fixes including hourly rates that couldn't be adjusted per project, and seeded custom styles getting lost when multiple were in use.
Superset Helm chart 0.22.6 (August 13). Chart update.
WordPress 7.0.4 (August 12). Covered in Security Alerts above.
PeerTube 8.2.4 (August 12). Patch release.
Umami 3.3.0 (August 12). The standout of the week. Adds TOTP two-factor authentication for self-hosted installs with QR setup, backup codes, team-level enforcement, admin 2FA reset, and rate limiting on repeated failures. Also brings session identity stitching, property filtering, board cloning, sparklines, and better bounce detection.
Jellyfin 12.0 RC5 (August 11). Fifth release candidate for the version that drops the long-standing 10. prefix. Check any automation pinned to 10.* tags before this goes stable.
Ghost 6.57.1 (August 10). Patch release.
Rocket.Chat 8.7.0 (August 10). Adds phishing-resistant MFA and a server-side OAuth flow with CSRF protection, state validation, and PKCE, enabled via Accounts_OAuth_Use_Modern_Flow. FIPS 140-3 compliant Docker images are now published. Supported until February 28, 2027.
Zulip Server 12.2 (August 10). Point release on the 12.x line.
What Stood Out This Week
WordPress 7.0.4 is the one with a deadline. A backport reaching all the way to the 4.7 branch is not routine. The mitigating factor is that you need both Imagick and Ghostscript installed and an attacker with Author-level access, which rules out a lot of small sites. If you run a multi-author WordPress install, patch it today.
Umami 3.3.0 finally brings 2FA to self-hosted analytics. Umami holds traffic data for every site you track, and until now the only thing standing between an attacker and that dashboard was a password. TOTP with backup codes and team-level enforcement closes a real gap. If you self-host Umami, this upgrade is worth doing before your next reporting cycle.
Rocket.Chat 8.7.0 is a serious authentication release. Moving OAuth fully server-side with PKCE and CSRF protection, plus phishing-resistant MFA and FIPS 140-3 images, is the kind of work that matters if you're running chat in a regulated environment. Note that the modern flow is opt-in behind a setting rather than the default.
Management UIs had a rough week. Portainer's Swarm compose deployer path traversal and new SSRF allow-list, alongside Gitea's collaborator access fix, are a reminder that these sit closer to your infrastructure than the workloads they manage. Patch them before the apps behind them.
All 45 of these services are available as one-click deployments with automated updates and backups on Elestio's managed catalog, so you can skip the upgrade sequencing entirely if you'd rather.
Thanks for reading ❤️ See you in the next one 👋