Self-Hosted Weekly: Week 41, 2026. WordPress 7.1.3, Vaultwarden Fixes, Supabase Buys Turso

Self-Hosted Weekly: Week 41, 2026. WordPress 7.1.3, Vaultwarden Fixes, Supabase Buys Turso

AI labs had a hand in four of the seven bugs fixed in this week's WordPress security release. Vaultwarden fixed seven advisories and changed how it reads client IPs behind a proxy. Supabase raised $150 million and bought Turso. Two LTS releases also arrived, Moodle 5.3 and Rocket.Chat 8.9, and both need homework before you upgrade. Here's what mattered.

1. WordPress 7.1.3: AI labs reported four of the seven bugs

WordPress 7.1.3 shipped on October 6 with seven security fixes, including a stored XSS on the Comments screen, a second-order SQL injection in the WXR exporter and unauthenticated disclosure of comments on private posts. Look at the credits: Anthropic reported three, and Trail of Bits reported one with OpenAI. WordPress published no CVE IDs or severity scores. Fixes are being backported to every branch down to 4.7.

Our take: Unlike last month's 7.1.2, WordPress hasn't reported any exploitation this time. The credits are the real story. AI-assisted auditing is now finding real bugs in the most-deployed CMS on the web, and attackers have the same tools. If you run WordPress, keep minor auto-updates on and stop treating them as optional.

2. Vaultwarden 1.37.4 fixes seven advisories and changes how it reads client IPs

Vaultwarden 1.37.4 (October 5) fixes seven security advisories. The most serious, rated High (8.1), affects organization member revocation. Others cover two-factor authentication, invitations, attachments, event logs, cipher sharing and the organization API key. Two behavior changes come with it. With IP_HEADER=X-Forwarded-For, Vaultwarden now takes the rightmost address that isn't a trusted proxy, where it used to take the leftmost. And the old /identity/accounts/register and /api/accounts/prelogin endpoints are gone.

Our take: Treat the proxy settings as part of the upgrade. If you have more than one proxy in front of it (a CDN plus Nginx, say), list all of them in IP_HEADER_TRUSTED_PROXIES. Otherwise every request will look like it comes from your CDN, and rate limiting will hit all your users at once. If any org admin isn't fully trusted, rotate the organization API key after the update, as the maintainers recommend. Running Vaultwarden behind Elestio's Nginx and a CDN? Both belong on that list.

3. Supabase raises $150M and buys Turso

On October 2, Supabase announced $150 million in new funding led by GIC, with CapitalG, IronArc and SquarePeg, and the acquisition of Turso, the company behind the SQLite-compatible database rewritten in Rust. Turso's own post says "Turso Database remains open source and actively developed" and that existing Turso Cloud databases keep running. The pitch is agents: "Agents are spinning up millions of databases," said CEO Paul Copplestone, and Turso can host millions of suspendable databases on one server.

Our take: If you self-host Supabase, nothing changes in your stack today. The core is still Postgres. The open question is libSQL, the SQLite fork many projects embedded. Turso's announcement promises a future for the Rust rewrite and doesn't mention libSQL by name. If libSQL is in your dependency tree, pin your version and watch the repo.

4. Appwrite 2.4 blocks outbound requests to private addresses

Appwrite 2.4.0 (October 8) refuses outbound requests to private and reserved addresses from OAuth2 and OIDC providers, webhooks, messaging webhooks, migration sources and avatar fetches. User JWTs now only work in the project that issued them, and impersonated sessions become read-only. Three upgrade steps are mandatory: list internal hosts in _APP_ALLOWED_INTERNAL_ADDRESSES, add public proxies such as Cloudflare to _APP_TRUSTED_PROXIES, and set _APP_VCS_GITHUB_WEBHOOK_SECRET, or your GitHub integration stops working.

Our take: It's the same class of SSRF fix Gitea shipped last week, with the same upgrade catch. If your self-hosted Appwrite calls an internal Keycloak or a webhook receiver on the same network, those calls get refused after the upgrade until you allowlist the address. Run through the three variables in staging first.

5. Moodle 5.3 LTS raises the floor to PHP 8.3 and PostgreSQL 17

Moodle 5.3, released October 5, is the new long-term support release. It requires 64-bit PHP 8.3, PostgreSQL 17 and MariaDB 11.4 (MySQL stays at 8.4). New features include learning outcomes, due dates in quizzes and an Anthropic Claude AI provider plugin.

Our take: Moodle upgrades usually stall on the database. If your instance still runs PostgreSQL 15 or 16, plan a pg_upgrade before the Moodle upgrade, and don't try both in one maintenance window. Schools that run Moodle on an academic calendar should upgrade during winter break, not the week before exams.

6. Rocket.Chat 8.9 LTS starts deprecating Custom OAuth on the free tier

Rocket.Chat 8.9.0 (October 5) is supported until October 31, 2027. It needs Node.js 24.15 and MongoDB 8.0, and fixes a security issue in the Omnichannel agent and manager endpoints. One line in the changelog stands out: it "deprecates Custom OAuth authentication on workspaces without a Premium plan."

Our take: The LTS window is welcome. The OAuth deprecation isn't. Custom OAuth is how many self-hosters connect Rocket.Chat to Authentik or Keycloak. The changelog gives no removal date, but the real-time API methods deprecated in the same release are scheduled to go in 9.0. It's the same open-core move we flagged with NocoDB last week. If SSO matters to you, check what your plan includes for SAML and LDAP before 9.0 arrives.

7. Paperless-ngx 3.3 makes barcodes searchable

Paperless-ngx v3.3.0 (October 6) stores barcode contents and lets you search documents by them. It also puts two-factor authentication in front of the Django admin and makes the AI features more flexible, with passthrough parameters for LLMs and a separate API key for embeddings.

Our take: Barcode search is the quiet winner. If you stamp invoices or patient files with a barcode, you can now find the document by scanning it. If you expose /admin, the 2FA change alone justifies upgrading your Paperless-ngx instance this week.

8. Immich 3.3 lets households share the people they've tagged

Immich v3.3.0 (October 7) lets users in a cluster group share recognized people, so one family member's face tagging shows up for everyone. It also stacks photos edited outside Immich with their originals and syncs storage quotas, roles and usernames from your OAuth provider on every login.

Our take: The OAuth sync matters most to admins. You can now manage Immich users from your identity provider instead of editing quotas by hand. Version 3.3.1 followed a day later, so start from that.

What we're watching next week

Ubuntu's kernel fix, still missing. Two weekly kernel cycles in, Ubuntu's tracker still shows CVE-2026-80521 as vulnerable on 24.04 LTS and 26.04 LTS. Hosts running untrusted containers should stay isolated until it's fixed.

PostgreSQL 19 RC1 on October 15. GA is planned for October 29. RC1 is the build to run your own test suite against, in staging and not under an app that doesn't support 19 yet.

Mattermost 12.0, due October 16. The deprecation list drops RHEL 7 and 8, OpenSearch 1.x and the atmos/camo image proxy. Check your Mattermost setup against it before release day.

The bottom line

This week, upgrading meant more than pulling a new image. Appwrite and Vaultwarden fixed real security issues, but both changed how they trust the network, so the upgrade also needs config changes. Moodle wants a newer database. Rocket.Chat added a year of support and put free-tier SSO on notice. And with AI labs behind four of WordPress's seven reports, expect more releases like these.

Thanks for reading ❤️ See you next Friday 👋