Search
Jaeger v2.21.0 introduces breaking changes to query and configuration defaults
The release of Jaeger v2.21.0, as detailed in the project's GitHub release notes, includes several breaking changes that may affect existing deployments. Notably, the v1 HTTP endpoints in the query…
Deprecation of --mmap, --mlock, and --direct-io in llama.cpp v0.4.1
The release of llama.cpp version 0.4.1 introduces several enhancements, including support for new models like Maple 20B-A1B and Tencent Hy 4, improved JSON schema handling, and updates to ggml…
Deprecated Trivy flag replaced in eraser-dev/eraser v1.5.0-beta.1
The release of eraser-dev/eraser v1.5.0-beta.1 introduces several updates, including the replacement of the deprecated `--vuln-type` flag with `--pkg-types` for Trivy, as noted in the project's…
Containerd API 1.12.0-rc.1 introduces deprecations requiring action
The containerd project has released API version 1.12.0-rc.1, aligning with containerd 2.4. This pre-release includes notable updates such as the addition of the UpdateSandbox RPC for sandbox…
Agentgateway v1.6.0-alpha.1 introduces deprecation warnings
The agentgateway project has released v1.6.0-alpha.1, marking the pre-release phase for the upcoming v1.6.0. According to the project's GitHub release notes, this version includes numerous updates…
ZITADEL OAuth2 Token Exchange Vulnerability Enables Privilege Escalation
According to the GitHub Security Advisory database, ZITADEL versions 3.0.0 through 3.4.12 and 4.0.0 through 4.15.2 contain a high-severity vulnerability in the OAuth2 Token Exchange endpoint. This…
ZITADEL Fixes Role Revocation Bug in Granted Projects
The ZITADEL project has addressed a medium-severity security vulnerability affecting versions 4.0.0 through 4.15.3 and 3.0.0 through 3.4.12, according to the GitHub Security Advisory database. The…
Odigos v1.37.0 introduces breaking changes to container privilege settings
The release of Odigos v1.37.0, as noted in the project's GitHub release notes, includes several breaking changes that alter default container privilege behavior. Specifically, the odiglet and…
LanceDB v0.39.0-beta.7 alters Function CRUD routes
LanceDB v0.39.0-beta.7 introduces breaking changes to remote Function CRUD routes, as noted in the project's GitHub release notes. The update aligns these routes, which may affect systems relying on…
Composio CLI Beta removes fastmode feature
The latest release of ComposioHQ/composio, version @composio/cli@0.4.2-beta.387, introduces several documentation updates, fixes, and workflow improvements. Among the changes, the release notes…
Google SecOps OAuth Scope Write Permissions Deprecated
According to the Google Cloud Release Notes dated September 11, 2026, Google has announced the deprecation of write permissions from the chronicle.readonly OAuth scope for Google SecOps and Google…
Amazon MQ adds RabbitMQ 4.3 support, deprecates classic queues v1 storage
AWS What's New announces support for RabbitMQ version 4.3 on Amazon MQ, introducing features like quorum queue enhancements, including compaction, expanded priority levels, native delayed retries…
Deprecation of tq1_0 quant support in ggml-org/llama.cpp
The latest release of ggml-org/llama.cpp, titled b10926, introduces a change that affects handling of unsupported tq1_0 quantization formats. According to the project's GitHub release notes, the…
Cortex v1.22.0-rc.0 introduces multiple deprecations and removals
The release candidate for Cortex v1.22.0, as detailed in the project's GitHub release notes, announces several significant deprecations and removals. Key changes include the removal of deprecated…
Selenium 4.49.0 removes deprecated Java endpoint
SeleniumHQ has released version 4.49.0, as noted in the project's GitHub release notes. Among the changes, the Java component has removed the deprecated GET /session/{sessionId}/se/files/{fileName}…
High-Severity RCE Vulnerability in dotnet/runtime: CVE-2026-71328
The dotnet/runtime project has disclosed a high-severity remote code execution vulnerability, tracked as CVE-2026-71328, according to the GitHub Security Advisory database. The issue arises from an…
Traefik HTTP/3 readTimeout vulnerability affects slow-body uploads
According to the GitHub Security Advisory database, a medium severity vulnerability has been identified in Traefik versions v2.8.2 through v2.10.x and v3.0 through v3.6. This issue arises from the…
ZITADEL fixes missing `exp` validation in JWT IdP provider
The ZITADEL project has addressed a security vulnerability affecting its external JWT Identity Provider (IdP) implementation in versions 3.x and 4.x. According to the GitHub Security Advisory…
ZITADEL auto-linking flaw exposes accounts under specific configurations
The GitHub Security Advisory database reports a medium-severity vulnerability in ZITADEL versions 3.0.0 through 3.4.12 and 4.0.0 through 4.15.2, including RC versions. The issue arises when…
Traefik vulnerability allows identity spoofing via header aliasing
Traefik versions v1.x, v2.11.55 and earlier, and v3.7.11 and earlier are affected by a medium severity vulnerability involving header aliasing, as detailed in the GitHub Security Advisory database…
Traefik HTTP/1 Rootless Request-Target Bypass in Path-Scoped Routing
The GitHub Security Advisory database has published a high-severity issue affecting Traefik versions v3.0 through v3.6, which are end-of-life, and v3.7 up to v3.7.12. The vulnerability involves…
Critical NTLM Connection Reuse Vulnerability in Traefik HTTP/3
According to the GitHub Security Advisory database, Traefik versions prior to v2.11.57 and v3.7.13 are affected by a critical vulnerability involving NTLM and Negotiate authentication over HTTP/3…
Traefik v3.7.13 fixes header sanitization bypass via request trailers
Traefik v3.7.13 addresses a high-severity security issue where entrypoint header-name sanitization could be bypassed via request trailers. According to the GitHub Security Advisory database, affected…
High-severity HTTP request smuggling vulnerability in Traefik
Traefik versions v2.11.57 and v3.7.13 have addressed a high-severity vulnerability involving HTTP request smuggling and incorrect authorization, as detailed in the GitHub Security Advisory database…
High-Severity Elevation of Privilege Vulnerability in .NET Runtime
The dotnet/runtime project has disclosed a high-severity vulnerability, CVE-2026-69439, as detailed in the GitHub Security Advisory database. This issue involves an out-of-bounds write when parsing…
High-severity remote code execution vulnerability in dotnet/runtime
The dotnet/runtime project has disclosed a high-severity vulnerability, tracked as CVE-2026-69522, according to the GitHub Security Advisory database. This issue involves an out-of-bounds write when…
LF Edge eKuiper SSRF vulnerability patched in v2.4.0
LF Edge eKuiper has addressed a server-side request forgery (SSRF) vulnerability in its external service feature as detailed in a GitHub Security Advisory. Prior to version 2.4.0, eKuiper did not…
Path Traversal Vulnerability in LF Edge eKuiper Plugin Endpoint
LF Edge eKuiper versions prior to 2.4.1 are affected by a path traversal vulnerability in the plugin installation endpoint, as detailed in the GitHub Security Advisory database. The issue allows…
containerd CRI ExecSync Goroutine Leak Causes Node-Level Denial of Service
According to the GitHub Security Advisory database, containerd versions prior to 2.3.5, 2.2.8, 2.0.12, and 1.7.35 are affected by a medium-severity issue where the CRI ExecSync implementation can…
Instructor v1.17.0 introduces cache isolation and async validation changes
The release of Instructor v1.17.0 by 567-labs includes several significant updates and fixes, as outlined in the project's GitHub release notes. Among the changes, cached responses now use new keys…
Infracost v0.10.45 fixes symlink traversal vulnerability
The Infracost project has addressed a medium-severity security vulnerability in its config-template parser as detailed in the GitHub Security Advisory database. The issue, present in versions up to…
Infracost v0.10.45 fixes Terraform token disclosure vulnerability
Infracost has addressed a security issue in its Terraform Cloud and registry integration, as detailed in the GitHub Security Advisory database. The vulnerability involved sensitive token exposure due…
vLLM Cross-User Data Leak Vulnerability in Inference Batches
The vLLM project has disclosed a medium-severity vulnerability, GHSA-7m6h-x95x-82q5, according to the GitHub Security Advisory database. This issue affects inference batches in vLLM versions prior to…
SSRF and local file read vulnerability in vLLM multimodal processor
The vLLM project has disclosed a medium-severity security vulnerability, GHSA-4hhp-h66f-j5j7, affecting the multimodal processor `MiMoV2OmniMultiModalProcessor` within the…
Unleash v8.2.0 deprecates IFeatureStrategyPayload schema
The Unleash project has released version 8.2.0, as detailed in its GitHub release notes. Among the numerous changes, this version removes the deprecated IFeatureStrategyPayload schema and replaces it…
Urunc v0.8.0 introduces breaking changes and security fixes
The release of urunc v0.8.0, as detailed in the project's GitHub release notes, includes several updates that change default behavior, address security vulnerabilities, and introduce new features…
Hosted explanation capability added in skyhook-io/radar k8s-ui-v1.14.3
The skyhook-io/radar project has released version k8s-ui-v1.14.3, introducing an optional capability for hosted agents to explain saved assessments. According to the project's GitHub release notes…
Hosted Agent Explanation Capability Added in skyhook-io/radar v1.13.3
The skyhook-io/radar project has released version v1.13.3, introducing an optional capability for hosted agents to explain saved assessments. According to the project's GitHub release notes, this…
Deprecation of fallback_model in pydantic-ai v2.41.0
The pydantic/pydantic-ai project has announced the deprecation of the fallback_model parameter in favor of fallback_subagent_model for ImageGeneration and XSearch in its v2.41.0 release, according to…
Kestra 2.0.0 introduces breaking changes to API error format and plugin defaults
The release of Kestra version 2.0.0, as detailed in the project's GitHub release notes, includes significant breaking changes that operators must address. The API error format has been updated to…
Weaviate v1.38.14 introduces security fixes and performance improvements
The release of Weaviate v1.38.14, as detailed in the project's GitHub release notes, focuses on aggregate performance improvements, security updates, and bug fixes. Notable changes include…
Optuna v5.0.0 introduces significant default behavior changes
Optuna v5.0.0, as detailed in the project's GitHub release notes, introduces several major updates that change default behaviors. The TPESampler now enables multivariate TPE and the constant liar…
Astron Agent v1.1.2 deprecates legacy code executor
The Astron Agent v1.1.2 release, as detailed in the project's GitHub release notes, addresses critical security vulnerabilities affecting versions v1.1.1 and earlier. These include unsafe workflow…
Deprecation of CPU fallback for Vulkan GET_ROWS in ggml-org/llama.cpp
The latest release of ggml-org/llama.cpp introduces significant updates to the Vulkan backend, particularly addressing the handling of misaligned offsets in the GET_ROWS operation. According to the…
Amazon EC2 AMIs Now Support Instance Type Restrictions
Amazon EC2 has introduced a feature allowing AMI owners to specify compatible and incompatible instance types for their AMIs. According to AWS What's New's official changelog, this ensures that any…
LanceDB v0.39.0-beta.2 alters default behavior for blob tables and job tracking
The release of LanceDB v0.39.0-beta.2 introduces breaking changes that modify default behaviors, according to the project's GitHub release notes. Specifically, stable row IDs are no longer enabled by…
vLLM Derender Endpoints Lack Output Bounds, Pose Resource Risks
According to the GitHub Security Advisory database, a medium-severity issue has been identified in vLLM's `/v1/completions/derender` and `/v1/chat/completions/derender` endpoints. These endpoints…
vLLM Security Advisory: Internal Path Disclosure via Error Messages
The vLLM project has disclosed a medium-severity vulnerability, according to the GitHub Security Advisory database, involving unauthenticated disclosure of internal paths and usernames through…
vLLM Security Advisory: ReDoS Vulnerability in lm-format-enforcer Backend
According to the GitHub Security Advisory database, vLLM has a medium-severity vulnerability (GHSA-48jh-3gj7-fg8v) in its lm-format-enforcer backend. The issue stems from the absence of timeout and…
vLLM Security Advisory: Incomplete CVE-2025-62164 Fix Bypassed
According to the GitHub Security Advisory database, vLLM revision `26587f9519e22a5c4549ead7595ad9ca3229c4fd` contains an incomplete remediation for CVE-2025-62164. The issue arises from concurrent…