Normale weergave
Distribution Release: Plop Linux 26.1
Xml Notepad 2.9.0.21
Fix issue security advisory on DTD processing. Make default Ignore DTD option True, which is more secure.
Xml Notepad 2.9.0.20
Fix issue security advisory on DTD processing. Make default Ignore DTD option True, which is more secure.
Release v2.4.3
You can install pre-built binaries from https://repo.dovecot.org/
Docker images can be found at https://hub.docker.com/r/dovecot/dovecot
Please review https://doc.dovecot.org/2.4.3/installation/upgrade/2.3-to-2.4.html and https://doc.dovecot.org/2.4.3/installation/installation.html.
Important
There are experimental features in 2.4, one is enabled with --enable-experimental-mail-utf8, and another with --enable-experimental-imap4rev2, and you also need to set mail_utf8_extensions=yes and imap4rev2_enabled=yes to enable them in config.
Critical bug fixes
- CVE-2025-59028: Invalid base64 authentication can cause DoS for other
logins. - CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks
and read unintended files during indexing. Fixed by dropping the script. - CVE-2026-24031: SQL injection possible if auth_username_chars is
configured empty. Fixed escaping to always happen. v2.4 regression. - CVE-2026-27859: Excessive RFC 2231 MIME parameters in email would cause
excessive CPU usage. Fixed by limiting number of parameters to process. - CVE-2026-27860: LDAP query injection possible if auth_username_chars
is configured empty. Fixed escaping to always happen. v2.4 regression. - CVE-2026-27857: Sending excessive parenthesis causes imap-login to use
excessive memory. - CVE-2026-27856: Doveadm credentials were not checked using timing-safe
checking function. - CVE-2026-27855: OTP driver vulnerable to replay attack.
Changes
- Remove default service/*/service_extra_groups=$SET:default_internal_group.
They are now replaced by default mail_access_groups=$SET:default_internal_group. - The version file has been renamed as version.txt to avoid clash with
C++ headers. - auth: oauth2 - Do not export token automatically, must be exported using
fields. - config: Don't accept 0 as meaning unlimited anymore for
last_valid_uid, last_valid_gid, mail_cache_max_headers_count,
mail_cache_max_header_name_length, mail_vsize_bg_after_count,
mail_sort_max_read_count, message_max_size, submission_max_recipients
and quota_mail_size. - imap, pop3: Don't autoexpunge if Dovecot is shutting down or process
is killed. - imap: LIST - Handle invalid mUTF-7 mailbox names as never matching anything
- lazy-expunge: Change lazy_expunge_only_last_instance default to yes.
- lda: Use EX_TEMPFAIL (75) if configuration is invalid instead of 89.
v2.4 regression. - lib-master: Increase ANVIL_DEFAULT_LOOKUP_TIMEOUT_MSECS from 5s to 30s
- lib: crc32 - Use zlib's built-in CRC32 function
New features
- Improve UTF-8 support for mail storage.
- auth: Add default auth-token UNIX socket for token-based authentication.
- doc: solr-config-9.xml - Make it compatible with Solr 9.8.0
- doveadm: dsync - Search mails when exporting to reduce number of mails
exported by dsync-server. - dovecot-sysreport: Add -D|--destdir support.
- imap, imap-hibernate: Use DOVECOT-TOKEN authentication for unhibernation.
Default imap-master socket permissioms have been changed due to this. - imap: Add APPENDLIMIT capability when configured with quota_mail_size.
- imap: Support STATUS (DELETED) for IMAP4rev2.
- imapc: Add support for SEARCH MIMEPART
- imapc: Improve error forwarding.
- imapc: Support SORT and ESORT extensions.
- imapc: Support STATUS (DELETED) for IMAP4rev2.
- lib-sql: Support parameterized queries.
- lib-test: Add new test-dir API for better temporary test directory
handling. - lmtp: Advertize SIZE capability when configured with quota_mail_size.
- lmtp: Support XCLIENT DESTADDR and DESTPORT
- pop3-login: proxy - Add support for XCLIENT DESTIP and DESTPORT
- submission-login: proxy - Add support for XCLIENT DESTIP and DESTPORT
- Various optimizations have been made to the code.
Bug fixes
- Fix building dovecot with BSD, Solaris and macOS.
- auth: Crash would occur if users were iterated but
userdb_ldap_iterate_fields was not set. - auth: Fix request leak when client authenticates with unsupported mechanism.
- auth: Some passdbs would default to PLAIN instead of CRYPT scheme.
- config: Section and setting names could have been intermixed, resulting
in the setting being silently ignored. - configure: Fix checking if BUILD_IMAP_HIBERNATE is set
- doveadm: dsync - -e parameter was handled wrong with dsync-server.
- fts-flatcurve: Mailbox leak would occur if mailbox failed to open.
- imap: Fix potential issues with unhibernation and process state handling.
- imapc: SEARCH failure handling was done wrong.
- imapc: UID STORE commands included extra comma in uidset.
- lib-auth-client: auth-master - Fix panic when reconnecting after
handshake timeout. - lib-compression: Lz4 algorithm would assert-crash with malicious data.
- lib-dcrypt: Fix digest algorithm handling.
- lib-dict: Escape username paths to prevent traversal issues with dict-fs.
- lib-http: Fix HTTP parsing edge cases and state handling.
- lib-iostream: Disallow empty ssl_min_protocol.
- lib-json: Fix incorrect character handling logic.
- lib-ldap: Fix various TLS related bugs.
- lib-mail: Fix charset translation and MIME parsing edge cases.
- lib-mail: Fix multiple bounds checks and parsing issues in message handling.
- lib-var-expand: Multiple fixes and improvements for expansion handling.
- lib: Fix punycode decoding out-of-bounds reads.
- lib: Fix unicode normalization edge cases causing crashes.
- lib-http: Chunked transfer trailer size was not limited.
- login-common: Improve logging and internal error handling.
- login-common: login_log_format_elements was split by spaces naively, which
could break variable expansion. Use template aware splitting now. - master: Dovecot would fail to start if listen directive was used and
dovenull or dovecot user was missing. - pop3c: Connection might've hung with SSL.
- util: Fix handling of environment variables containing control characters.
- Many other bugs have been fixed.
Xml Notepad 2.9.0.19
Fix issue security advisory on DTD processing.
Development Release: Edubuntu 26.04 Beta
29.6.6
Releases Notes for 29.6.6
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
- Uses electron 40.8.4
- #2143 , #1055
- Updates to draw.io core 29.6.6.
OpenVINO AI Plugins are now available for macOS
OpenVINO AI Plugins are now available for macOS
By Leo Wattenberg
Wednesday, June 11, 2025With Audacity 3.7.4, we finally are adding macOS support to the Intel OpenVINO AI plugins. Once youβve downloaded Audacity 3.7.4 and downloaded the OpenVINO plugins (and installed both), you should find them in Effects β OpenVINO AI Effects.
As a reminder, these effects are completely free and run on your own machine, no internet connection required.
The following effects are available:
-
- Music separation
- Separate a mono or stereo track into individual stems -- Drums, Bass, Vocals, & Other Instruments.
-
- Noise suppression
- Reduce background noise in a recording. Works best on spoken word audio.
-
- Music generation and continuation
- Uses MusicGen LLM to generate snippets of music, or to generate a continuation of an existing snippet of music.
-
- Whisper transcription
- Transcribe audio to text using OpenAI's Whisper model. Tip: You can export the resulting label track as a subtitle file via File β Export other β Export labels.
-
- Audio Super resolution
- Increase the sampling rate of an audio signal β in other words, it upsamples audio to improve its fidelity, clarity, or compatibility with high-resolution standards. Useful for older 8kHz recordings, such as telephone calls.
Feedback wanted
As this is the first release of these plugins for macOS, weβre considering them to be a beta of sorts: While weβve tested them on our machines, thereβs only so many devices flying about in our team. Thus, if youβve got moment to try and test them on yours, weβd be greatful. Weβre especially interested in the following information:
- Did the effects you tried work?
- What kind of mac model (year; Intel or Apple Silicon) and OS version are you using?
- What kind of binary are you using? (Apple Silicon/ARM or Intel/x64)
- Did you run into any trouble during the process of installing or using the plugins?
You can send us this feedback through various channels:
- Discord
- Our forum
- Our bug tracker (if you have a reproducible bug)
- Intelβs bug tracker (for OpenVINO feature requests)
How to download & release notes
You can download Audacity 3.7.4 here and the OpenVINO plugin there. We will also have them show up in the Get Effects button inside Audacity in the near future.
From our testing, it appears that in some cases, the Intel binaries perform better, even on Apple Silicon macs. You may want to experiment with what binary you use.
The model downloader and installer supports macOS 12 onwards. If you compile from source or get the models from elsewhere, you might be able to get it running from OSX 10.15 (Intel macs) or macOS 11 (Apple Silicon macs) as well.
Audacity turns 25 years old!
Audacity turns 25 years old!
By Leo Wattenberg
Wednesday, May 28, 2025On this day, 25 years ago, the very first public version of Audacity was released, Audacity 0.8.
Audacity 0.8 was very different to what we have today: It couldnβt record, it couldnβt use plugins, and it could only export as WAV, AIFF, SF and AU.
![]()
Since then, a lot has happened. Audacity 1.0 was released two years later, sporting a logo and layout thatβs still recognizable today. PCs have turned notably less boxy and beige, and are much faster as well. Theyβre so fast in fact, that many features which would have been unthinkable 25 years ago are now very much possible - and even expected. We have worked tirelessly to improve Audacityβs audio editing capabilities, adding features like realtime effects, non-destructive edits and time stretching, a master channel and even some AI-powered effects which are actually useful.
If youβre curious to learn more about Audacityβs history, our product owner Martin Keary released a video about it when he took over, and our designer Leo Wattenberg ran Audacityβs source code through a visualizer to show the evolution of files within Audacity.
Whatβs next for Audacity
Weβre planning to release another minor patch (Audacity 3.7.4) in the next couple weeks, which among various bug fixes finally brings aforementioned AI effects to macOS.
In addition to that, weβre still working hard on Audacity 4.0, which wonβt be quite yet a DAW β but will tackle a lot of UX snags, which made Audacity so far more annoying to use than necessary. We will soon post an update on what to expect exactly for Audacity 4.0.
Letβs celebrate with Audacity merch!
After 25 years of making it rather difficult to send any money our way, we finally have opened up a merch store at merch.audacityteam.org. Every purchase made will help support our full-size development team, and accelerate Audacityβs progress to becoming not just the free option for audio editing - but the best option.
Weβll add more designs over the coming months - follow us on YouTube or join our Discord to get notified when new merch drops!
Audacity 3.7
Audacity 3.7
By Leo Wattenberg
Wednesday, October 30, 2024Audacity 3.7 has been released!
It features everyoneβs favorite βbug fixes and performance improvementsβ. See the full changelog for details.
Other than that Ββ thereβs nothing exciting to see here. Which in itself is exciting! The reason for this very thin release is that weβve focused most of our attention towards Audacity 4.0 instead! Audacity 4 will feature a complete remake of the UI and is still quite some ways out. Weβll update you on scope and progress on that over the coming months.
In the meantime: Check out the MuseHub for some cool plugins.
Asterisk Release certified-22.8-cert2
The Asterisk Development Team would like to announce
the release of Certified asterisk-22.8-cert2.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/certified-22.8-cert2
and
https://downloads.asterisk.org/pub/telephony/certified-asterisk
Repository: https://github.com/asterisk/asterisk
Tag: certified-22.8-cert2
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-certified-22.8-cert2
Links:
Summary:
- Commits: 1
- Commit Authors: 1
- Issues Resolved: 1
- Security Advisories Resolved: 0
User Notes:
Upgrade Notes:
Developer Notes:
Commit Authors:
- Mike Bradeen: (1)
Issue and Commit Detail:
Closed Issues:
- 1833: [bug]: Address security vulnerabilities in pjproject
Commits By Author:
-
Mike Bradeen (1):
- res_pjsip: Address pjproject security vulnerabilities
Commit List:
- res_pjsip: Address pjproject security vulnerabilities
Commit Details:
res_pjsip: Address pjproject security vulnerabilities
Author: Mike Bradeen
Date: 2026-03-25
Address the following pjproject security vulnerabilities
GHSA-j29p-pvh2-pvqp - Buffer overflow in ICE with long username
GHSA-8fj4-fv9f-hjpc - Heap use-after-free in PJSIP presense subscription termination header
GHSA-g88q-c2hm-q7p7 - ICE session use-after-free race conditions
GHSA-x5pq-qrp4-fmrj - Out-of-bounds read in SIP multipart parsing
Resolves: #1833
Asterisk Release certified-20.7-cert10
The Asterisk Development Team would like to announce
the release of Certified asterisk-20.7-cert10.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/certified-20.7-cert10
and
https://downloads.asterisk.org/pub/telephony/certified-asterisk
Repository: https://github.com/asterisk/asterisk
Tag: certified-20.7-cert10
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-certified-20.7-cert10
Links:
Summary:
- Commits: 1
- Commit Authors: 1
- Issues Resolved: 1
- Security Advisories Resolved: 0
User Notes:
Upgrade Notes:
Developer Notes:
Commit Authors:
- Mike Bradeen: (1)
Issue and Commit Detail:
Closed Issues:
- 1833: [bug]: Address security vulnerabilities in pjproject
Commits By Author:
-
Mike Bradeen (1):
- res_pjsip: Address pjproject security vulnerabilities
Commit List:
- res_pjsip: Address pjproject security vulnerabilities
Commit Details:
res_pjsip: Address pjproject security vulnerabilities
Author: Mike Bradeen
Date: 2026-03-24
Address the following pjproject security vulnerabilities
GHSA-j29p-pvh2-pvqp - Buffer overflow in ICE with long username
GHSA-8fj4-fv9f-hjpc - Heap use-after-free in PJSIP presense subscription termination header
GHSA-g88q-c2hm-q7p7 - ICE session use-after-free race conditions
GHSA-x5pq-qrp4-fmrj - Out-of-bounds read in SIP multipart parsing
Resolves: #1833
Asterisk Release 21.12.2
The Asterisk Development Team would like to announce
the release of asterisk-21.12.2.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/21.12.2
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 21.12.2
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-21.12.2
Links:
Summary:
- Commits: 1
- Commit Authors: 1
- Issues Resolved: 1
- Security Advisories Resolved: 0
User Notes:
Upgrade Notes:
Developer Notes:
Commit Authors:
- Mike Bradeen: (1)
Issue and Commit Detail:
Closed Issues:
- 1833: [bug]: Address security vulnerabilities in pjproject
Commits By Author:
-
Mike Bradeen (1):
- res_pjsip: Address pjproject security vulnerabilities
Commit List:
- res_pjsip: Address pjproject security vulnerabilities
Commit Details:
res_pjsip: Address pjproject security vulnerabilities
Author: Mike Bradeen
Date: 2026-03-25
Address the following pjproject security vulnerabilities
GHSA-j29p-pvh2-pvqp - Buffer overflow in ICE with long username
GHSA-8fj4-fv9f-hjpc - Heap use-after-free in PJSIP presense subscription termination header
GHSA-g88q-c2hm-q7p7 - ICE session use-after-free race conditions
GHSA-x5pq-qrp4-fmrj - Out-of-bounds read in SIP multipart parsing
Resolves: #1833
Asterisk Release 22.9.0-rc1
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-22.9.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/22.9.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 22.9.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-22.9.0-rc1
Links:
Summary:
- Commits: 48
- Commit Authors: 20
- Issues Resolved: 31
- Security Advisories Resolved: 0
Asterisk Release 23.3.0-rc1
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-23.3.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/23.3.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 23.3.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-23.3.0-rc1
Links:
Summary:
- Commits: 48
- Commit Authors: 20
- Issues Resolved: 31
- Security Advisories Resolved: 0
Asterisk Release 20.19.0-rc1
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-20.19.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/20.19.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 20.19.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
Change Log for Release asterisk-20.19.0-rc1
Links:
Summary:
- Commits: 48
- Commit Authors: 20
- Issues Resolved: 31
- Security Advisories Resolved: 0
v25.12.2
Hi,
The OpenWrt community is proud to announce the second service release of the OpenWrt 25.12 stable series.
Download firmware images using the OpenWrt Firmware Selector:
Download firmware images directly from our download servers:
Main changes between OpenWrt 25.12.1 and OpenWrt 25.12.2
Only the main changes are listed below. See the full changelog for details.
Device support
- airoha: rename kernel module
kmod-pwm-an7581tokmod-pwm-airohaβ users with this module explicitly installed need to reinstall under the new name - apm821xx: fix U-Boot environment definitions for NETGEAR WNDR4700, Western Digital MyBookLive, Meraki MR24 and Meraki MX60; fix PCIe boot failure on Meraki MX60
- ath79: fix initramfs boot for Huawei AP5030DN and AP6010DN
- ath79: fix VLAN CPU port tagging on 2-CPU-port devices (affects several dual-CPU switch configurations)
- ath79: remove incorrectly included WiFi packages from Mikrotik RB750r2 (device has no WiFi hardware)
- ipq40xx: fix ART partition name for Linksys Velop WHW03 V1 β restores correct WiFi calibration data access
- ipq40xx: fix MAC address reading for Linksys devices using eMMC-based NVMEM
- lantiq: xrx200: fix failsafe mode on BT HomeHub 5A β LAN ports 1 & 2 now work correctly in failsafe (#22480)
- mediatek: Bananapi BPI-R4: fix SFP+ electric module support β modules that stopped working after a snapshot upgrade are now functional again (#19878)
- ramips: fix kernel decompress error that bricked ELECOM WRC-X1800GS on 25.12.0 (#22270)
- ramips: fix initramfs kernel load address for TP-Link EAP615-Wall v1
- ramips: fix MAC address assignment for Xiaomi Mi AC2100
- realtek: fix D-Link fan control script
WiFi fixes and improvements
- wifi-scripts: fix 160 MHz channel width configuration β hostapd was not correctly configured for 160 MHz, preventing its use (#22481)
- wifi-scripts: fix SU beamformee antenna count β incorrect count was passed to the driver
- hostapd: fix memory leak in Radio Resource Management (RRM) ubus interface
- mac80211: ath12k: add thermal sensor support for QCA/IPQ devices
- mac80211: ath9k: fix GPIO mask handling from device tree
- mt76: fix severe WiFi latency regression (up to multiple seconds) on 2.4 GHz introduced in 25.12.1 β affected many MediaTek devices including OpenWrt One, Zyxel EX5601, ASUS RT-AX53U, Xiaomi AX3000T/AX6000, Cudy WR3000/X6, GL Flint 2 and others (#22491)
- mt76: multiple further stability fixes for MediaTek WiFi chipsets (MT7615/MT7915/MT7996/MT7992/MT792x):
- add per-link beacon monitoring for MLO (Multi-Link Operation)
- fix MT7996/MT7992 link handling during MLO station add/remove
- fix scan work requeue race with spinlock
Upgrading to 25.12.2
Upgrading from 24.10 to 25.12 should be transparent on most devices, as most configuration data has either remained the same or will be translated correctly on first boot by the package init scripts.
For upgrades within the OpenWrt 25.12 stable series, Attended Sysupgrade is also supported, which allows preserving the installed packages.
-
Sysupgrade from 23.05 or earlier to 25.12 is not officially supported.
-
Cron log level was fixed in busybox.
system.@system[0].cronloglevelshould be set to7for normal logging.7is the default now. If this option is not set, the default is used and no manual action is needed. fc0c518 -
Bananapi BPI-R4: Interface
eth1was renamed tosfp-lanorlan4, and interfaceeth2was renamed tosfp-wanto match the labels. You have to upgrade without saving the configuration. cd8dcfe -
TP-Link RE355 v1, RE450 v1 and RE450 v2: The partition layout and block size changed in this release to fix configuration loss on sysupgrade. Users upgrading from OpenWrt 25.12.0 or earlier must use
sysupgrade -Fto force the upgrade. The image must not exceed 5.875 MB (6016 KiB). -
Meraki MX60: Direct sysupgrade to 25.12.2 is not possible without manual preparation β
meraki_loadaddrmust be changed before upgrading, as the default value is insufficient to boot OpenWrt 25.12+. See the device wiki page for instructions.
Known issues
- Zyxel EX5601-T0: the WAN interface was renamed from
eth1towanβ check and update your network configuration after upgrading. - Pixel 10 phones have problems connecting to WPA3-protected WiFi 6 APs. #21486
- 802.11r Fast Transition (FT) causes connection problems with some WiFi clients when WPA3 is used. #22200
- SQM CAKE MQ (
cake_mq): throughput may be unexpectedly low on some configurations after the scheduler fixes in this release. #22344
Full release notes and upgrade instructions are available at
https://openwrt.org/releases/25.12/notes-25.12.2
In particular, make sure to read the known issues before upgrading:
https://openwrt.org/releases/25.12/notes-25.12.2#known_issues
For a detailed list of all changes, refer to
https://openwrt.org/releases/25.12/changelog-25.12.2
To download the 25.12.2 images, navigate to:
https://downloads.openwrt.org/releases/25.12.2/targets/
Use OpenWrt Firmware Selector to download:
https://firmware-selector.openwrt.org?version=25.12.2
As always, a big thank you goes to all our active package maintainers, testers, documenters and supporters.
Have fun!
The OpenWrt Community
To stay informed of new OpenWrt releases and security advisories, there
are new channels available:
-
a low-volume mailing list for important announcements:
https://lists.openwrt.org/mailman/listinfo/openwrt-announce -
a dedicated "announcements" section in the forum:
https://forum.openwrt.org/c/announcements/14 -
other announcement channels (such as RSS feeds) might be added in the
future, they will be listed at https://openwrt.org/contact
Modernizing encryption of Home Assistant backups
Backups are one of those quiet, powerful features: when they work, you donβt notice them, but when you need them, theyβre everything. Weβve evolved Home Assistantβs built-in backup format over the years to keep it safe and secure, especially when backing up to remote locations. As modern cryptography has advanced, we needed to build a system to match. SecureTar v3 is a purpose-built library for creating and reading password-protected Home Assistant backups with modern cryptography and safer, stronger defaults.
To help us get this right, we commissioned Trail of Bits, a leading security engineering firm, to independently audit our work. Their review found that SecureTar v3 follows best-in-class practices for core security algorithms, such as hashing and encryption. They also identified three areas for improvement, which they confirmed were resolved in their follow-up review. This audit was paid for by the Open Home Foundation so we could invest in improvements that protect usersβ privacy, security, and control.
Your backups will start using this new encryption automatically, beginning with the release of version 2026.4 on April 1, 2026. Please note old backups will still work and be readable after this change (see Recommended next steps below). For more technical details, please read onβ¦
A bit of history
Home Assistant backups have always been encrypted by default, and use a high entropy key, to help ensure your data is safe. When we introduced backups, early formats (v1 and v2) used the same AES-128 encryption variant, along with a simple key derivation (the code that turns your passphrase into the actual key used for encryption). Sam Gleske brought to our attention that the key-derivation step was no longer up to modern standards.
Itβs worth stressing an important point: Home Assistantβs passphrase generator already produces long, high-entropy passphrases. This means that backups created previously were difficult to break if using this feature. To demonstrate this, we calculated that a brute force passphrase attack (where attackers try many passwords rapidly) on the backups would take more time than the average lifespan of a person to be successful.
Still, because it was possible to manually generate an insecure passphrase for advanced users, and the libraryβs internal cryptographic primitives could be improved, we decided to overhaul SecureTar to use best-in-class algorithms, and to have that work validated by an external audit.
What we changed and why
The goals were simple: choose modern, well-studied algorithms, avoid design mistakes that could weaken confidentiality or integrity, and make v3 the secure default.
Highlights of the SecureTar v3 design:
- Modern key derivation: SecureTar v3 uses Argon2id for password-based key derivation. Argon2id is a memory-hard algorithm that makes brute-force attacks much more costly.
- Modern encryption and authentication: Encryption is provided by the libsodium secretstream API (exposed in Python via PyNaCl), which implements a robust streaming authenticated-encryption construction using XChaCha20-Poly1305. That combination gives both confidentiality (nobody can read your data) and integrity/authentication (nobody can tamper with it without detection).
- Safer defaults and parsing: We set safer defaults so new backups use v3, and we fixed parsing logic to avoid silently treating corrupt data as valid legacy backups.
We made these choices to ensure that SecureTar is resilient to modern attacks and easier to reason about from a security perspective.
Independent audit by Trail of Bits
After implementing SecureTar v3, we commissioned Trail of Bits to perform the focused security assessment and fix review. Here is what the review found:
- Timing side-channel in a validation comparison (informational): The audit pointed out a minor coding issue in how we checked a validation key. It wasnβt a security risk (the value is stored openly in the file header), but we updated the check to a safer form so security tools stop flagging it.
- Insecure fallback to legacy protocol version (informational): Header parsing logic could be confused by corrupted data; we updated the logic so corrupted headers raise an error instead of silently falling back.
- Supply-chain risk in GitHub Actions workflow (medium): Workflow steps were not pinned to specific commit hashes and used broad permissions, opening the build process to possible supply-chain attacks. We pinned actions to specific commit hashes and tightened permissions.
Crucially, Trail of Bitsβ post-fix review confirmed all three findings were resolved. This shows we have not only adopted modern cryptography, but also closed the gaps the audit exposed.
You can read more about the audit and the fixes in the Trail of Bits report.
How you help support this work
Security work (especially external audits and specialist engineering) costs money. The Open Home Foundation provides the structure and finances that let us do this work. That money comes, in part, from people who buy official Home Assistant or ESPHome products from the foundationβs commercial partners, and merchandise from the Open Home Foundation Store: we really appreciate your support!
Because of this, we were able to commission experts, invest engineering time, and validate the fixes. That investment protects usersβ backups (which often contain configurations, passwords and API keys, integrations, and automations) and keeps Home Assistant a trustworthy, secure platform for everyone.
Recommended next steps
- Ensure Home Assistant is updated to the latest version. The 2026.4 release includes SecureTar v3.
- Any encrypted backup created after updating to 2026.4 will use v3βs improved format.
- Existing backups are still secure, as Home Assistantβs generated passphrase is strong. That said, for extra security, you can regenerate the encryption key in your backup settings (use the Change encryption key option at the bottom of the backup settings page).
- If you use the
ha backupCLI command, or thehassio.backup_fullorhassio.backup_partialactions to create backups, and youβve used a short/low entropy password, you should choose a new password.
For the curious: technical summary
- Key derivation: Argon2id (memory-hard), using separate sub-keys for each backup part.
- Encryption / AEAD: XChaCha20-Poly1305 via libsodium secretstream (PyNaCl) with 256-bit key size. AEAD means your data is not only encrypted, but also authenticated (validating the data is unchanged/not tampered with).
- Audit: Trail of Bits: 3 findings (2 informational, 1 medium), all resolved.
- Build hardening: GitHub Actions pinned to commit SHAs and narrower permissions to reduce supply-chain risk.
Looking for more? Check out the SecureTar repository on GitHub.
Final note
Security is iterative, and this latest work has helped build a stronger foundation for Home Assistant backups, and a clearer path forward for maintaining that security over time.
If you want to read about similar past efforts, see some of our other posts:
- One of our past security audits
- The upcoming release notes for Home Assistant 2026.4
By keeping Home Assistant secure, we make the platform safer, more trusted, and more enjoyable for the whole community. Thank you.
-
nginx
- nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default proxy HTTP version to HTTP/1.1 with keep-alive enabled.
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default proxy HTTP version to HTTP/1.1 with keep-alive enabled.
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default proxy HTTP version to HTTP/1.1 with keep-alive enabled.
uNmINeD 0.19.60-dev
New uNmINeD development snapshot is available for download!
Changes:
- (GUI) Datapack and mod load errors are now ignored when opening a world
- (GUI) The log now include a stack trace of errors that occur when opening the world
- Improved handling of broken mods/datapacks
Early Stable Update for Desktop
Β The Stable channel has been updated to 147.0.7727.24/.25 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.
You can find more details about early Stable releases here.
Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Srinivas Sista
Google Chrome
NVIDIA Driver 595.97
Although GeForce Game Ready Drivers and NVIDIA Studio Drivers can be installed on supported notebook GPUs, the original equipment manufacturer (OEM) provides certified drivers for your specific notebook on their website. NVIDIA recommends that you check with your notebook OEM for recommended software updates for your notebook.
Game Ready
This new GeForce Game Ready Driver optimizes your experience in the latest titles featuring DLSS, ray tracing, path tracing, and NVIDIA Reflex, and ensures the best possible experience in your wider library of games and apps.
Fixed Gaming Bugs
- Halo Infinite: Texture corruption may occur on R595 drivers [5957741]
- HITMAN World of Assassination: Game stability issues when NVIDIA Smooth Motion is enabled [5849519]
- Game stability issues after enabling DLSS FG when Instant Replay is enabled [5732936]
Fixed General Bugs
- N/A
Learn more in our Game Ready Driver article here.
![]()
v11.17.0
β οΈ Potential Breaking Changes
Added support for importing data in the background (#26914)
Imports now automatically time out after 1 hour, with a maximum of 20 running concurrently. These limits can be configured via IMPORT_TIMEOUT and IMPORT_MAX_CONCURRENCY, respectively.
Improved build times using tsdownβs oxc-transform (#26604)
Exports previously available from @directus/types/collab are now exported directly from @directus/types
Shrunk app UI to 90% and converted all px to rem (16px browser default) (#26826)
Potential breaking change: The app UI has been shrunk to 90% of its previous size. Extensions that rely on hardcoded px values or the old 14px root font-size may render incorrectly β all app sizing now uses rem based on the 16px browser default.
- @directus/api
- @directus/types
- @directus/specs
- Updated fast-xml-parser, qs, minimatch, tar, undici, vue-split-panel and flatted dependencies (#26951 by @br41nslug)
β¨ New Features & Improvements
- @directus/app
- Added support for importing data in the background (#26914 by @Nitwel)
- Added utility endpoint and UI to generate translations collections and fields. (#26742 by @bryantgillespie)
- Added deployment provider link on the run detail page, opening deployments directly in Vercel or Netlify dashboards. (#26888 by @LZylstra)
- Shrunk app UI to 90% and converted all px to rem (16px browser default) (#26826 by @formfcw)
- @directus/api
- Added tool search tool for Anthropic AI provider to reduce context usage (#26864 by @bryantgillespie)
- Added support for setting the
secureattribute on OpenID/OAuth2 cookies via theAUTH_<PROVIDER>_COOKIE_SECUREenvironment variable (#26628 by @dstockton) - Updated
FilesService.uploadOneto support an optionalstorageparameter (#26882 by @gaetansenn) - Added AI SDK Devtools middleware support for debugging AI Assistant in development only. Added AI telemetry provider (#26678 by @bryantgillespie)
config for Braintrust and Langfuse, enabling sending traces for observability, usage, and token costs. - Added utility endpoint and UI to generate translations collections and fields. (#26742 by @bryantgillespie)
- Added support for Redis namespace control (#26943 by @dstockton)
- @directus/errors
- @directus/env
- Added support for importing data in the background (#26914 by @Nitwel)
- Added support for Redis namespace control (#26943 by @dstockton)
- @directus/system-data
- Added utility endpoint and UI to generate translations collections and fields. (#26742 by @bryantgillespie)
- @directus/constants
- Added utility endpoint and UI to generate translations collections and fields. (#26742 by @bryantgillespie)
- @directus/extensions-sdk
- @directus/themes
π Bug Fixes & Optimizations
- @directus/app
- Fix file renaming (#26946 by @br41nslug)
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Fixed filtering out
preRegisterCheck === falsemodules from settings module bar config (#26953 by @AlexGaillard) - Prevented uncaught exception when v-menu has no tabbable elements (#26922 by @robluton)
- Fixed a bug where global draft updates failed for singleton collections (#26910 by @formfcw)
- Refactored "Clear value(s) on save when hidden" condition so it's applied inside a drawer (#26925 by @AlexGaillard)
- Added functionality to duplicate access policies (#26889 by @robluton)
- Reduced width of split panel resize handle to prevent scrollbar interference (#26908 by @robluton)
- Updated Vite to version 8.0.0 (#26887 by @Nitwel)
- Corrected field editability for conditional update policies and version items (#26815 by @HZooly)
- Fixed date picker not emitting value after month/year change. (#26880 by @powerseed)
- Fixed inconsistent dropdown arrows in visual editor header bar (#26904 by @formfcw)
- @directus/api
- Added API request counting to telemetry reports. Requests are tracked by HTTP method and cache status. (#26738 by @connorwinston)
- Fix file renaming (#26946 by @br41nslug)
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Fixed errors during import not propagated while the file is streaming (#26881 by @Nitwel)
- Added
cache clearCLI command with--systemand--dataflags (#26898 by @gaetansenn) - Improved build times using
tsdownβsoxc-transform(#26604 by @Nitwel) - Preserved M2A type info when using named GraphQL fragments (#26920 by @gaetansenn)
- Added GraphQL resolver deduplication (#26949 by @br41nslug)
- Fixed aggregation sanitization (#26948 by @br41nslug)
- Added cross origin opener policy settings (#26947 by @br41nslug)
- Fixed revisions not using prepareDelta (#26867 by @br41nslug)
- @directus/types
- Fix file renaming (#26946 by @br41nslug)
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Updated
FilesService.uploadOneto support an optionalstorageparameter (#26882 by @gaetansenn) - Added GraphQL resolver deduplication (#26949 by @br41nslug)
- Fixed revisions not using prepareDelta (#26867 by @br41nslug)
- @directus/env
- Fix file renaming (#26946 by @br41nslug)
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Added support for setting the
secureattribute on OpenID/OAuth2 cookies via theAUTH_<PROVIDER>_COOKIE_SECUREenvironment variable (#26628 by @dstockton) - Added AI SDK Devtools middleware support for debugging AI Assistant in development only. Added AI telemetry provider (#26678 by @bryantgillespie)
config for Braintrust and Langfuse, enabling sending traces for observability, usage, and token costs. - Added cross origin opener policy settings (#26947 by @br41nslug)
- @directus/ai
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/composables
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/constants
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/errors
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/extensions
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/extensions-registry
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/extensions-sdk
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Updated Vite to version 8.0.0 (#26887 by @Nitwel)
- Updated
- @directus/format-title
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/memory
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/pressure
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/release-notes-generator
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Fixed generated build (#26959 by @AlexGaillard)
- Updated
- @directus/schema
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/schema-builder
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-azure
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-cloudinary
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-gcs
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-local
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-s3
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/storage-driver-supabase
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/stores
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/system-data
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/themes
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/update-check
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/utils
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Preserved M2A type info when using named GraphQL fragments (#26920 by @gaetansenn)
- Fixed revisions not using prepareDelta (#26867 by @br41nslug)
- Updated
- @directus/validation
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard)
- Updated
- @directus/sdk
- Updated
@directus/tsconfigdependency from 3.0.0 to 4.0.0 (#26879 by @AlexGaillard) - Improved build times using
tsdownβsoxc-transform(#26604 by @Nitwel) - Fixed function typing in sdk for
dateandtimefields. (#26936 by @costajohnt)
- Updated
π¦ Published Versions
@directus/app@15.6.0@directus/api@35.0.0@directus/ai@1.3.1@directus/composables@11.2.16@directus/constants@14.3.0create-directus-extension@11.0.32@directus/env@5.7.0@directus/errors@2.3.0@directus/extensions@3.0.22@directus/extensions-registry@3.0.22@directus/extensions-sdk@17.1.0@directus/format-title@12.1.2@directus/memory@3.1.5@directus/pressure@3.0.20@directus/release-notes-generator@2.0.4@directus/schema@13.0.6@directus/schema-builder@0.0.17@directus/specs@13.0.0@directus/storage@12.0.4@directus/storage-driver-azure@12.0.20@directus/storage-driver-cloudinary@12.0.20@directus/storage-driver-gcs@12.0.20@directus/storage-driver-local@12.0.4@directus/storage-driver-s3@12.1.6@directus/storage-driver-supabase@3.0.20@directus/stores@2.0.1@directus/system-data@4.4.0@directus/themes@1.3.0@directus/types@15.0.0@directus/update-check@13.0.5@directus/utils@13.3.2@directus/validation@2.0.20@directus/sdk@21.2.1
Distribution Release: Kali Linux 2026.1
-
nginx
- nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default HTTP version to HTTP/1.1 with keep-alive enabled.
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default HTTP version to HTTP/1.1 with keep-alive enabled.
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755). Additionally, nginx-1.29.7 mainline version introduces support for Multipath TCP and upgrades the default HTTP version to HTTP/1.1 with keep-alive enabled.
uNmINeD 0.19.59-dev
New uNmINeD development snapshot is available for download!
Changes:
- (Hytale) Added texture average color calculation for vanilla blocks from the latest installed game assets
- (Hytale) Added texture average color calculation for custom blocks added by mods
- (Hytale) Updated vanilla stylesheet to version 2026-03-23
- (Minecraft) Fixed an issue where the Bedrock vanilla resource pack would not load in some cases
- (GUI) Fixed a zoom glitch when a map marker was under the mouse cursor
Development Build
Below are development builds for testing purposes.
Latest development build: 2.6.4.36 (April 3rd 2026)
Latest stable release build: 2.6.4
https://github.com/clsid2/mpc-hc/releases/tag/2.6.4
v4.0.0-beta.470
What's Changed
Security & Fixes
- Fixed proxy config validation to ensure stored config matches the current proxy type (#9146, fixes #9127)
- Fixed environment variables being incorrectly resolved in compose files instead of preserving ${VAR} references (#9147, fixes #9136)
- Fixed deployment issues with shell argument escaping in nixpacks commands (#9122, fixes #9042)
- Fixed GitHub webhook errors for unsupported event types (#9119, fixes #9090)
- Fixed server limit checks when using API tokens (#9123, fixes #9116)
- Fixed hostname validation to be case-insensitive and allow more characters (#9134, fixes #9131)
- Fixed duplicate subscription creation
- Fixed environment variable refresh when variables are missing or stale
- Fixed Docker cleanup logging when server is unreachable
New Services & Templates
- Added EspoCRM one-click service template (#8658)
Improvements
- Improved mobile responsiveness for confirmation modals
- Simplified Docker installation process
- Added storage API endpoints with UUID support for databases and services
- Added Nightwatch monitoring support
- Disabled Booklore service template (#9105)
- Bumped Sentinel and Traefik versions
What's Changed (Github)
- fix(github-webhook): handle unsupported event types gracefully by @andrasbacsai in #9119
- fix(deployment): properly escape shell arguments in nixpacks commands by @andrasbacsai in #9122
- fix(validation): make hostname validation case-insensitive and expand allowed name characters by @andrasbacsai in #9134
- fix(team): resolve server limit checks for API token authentication by @andrasbacsai in #9123
- chore(service): disable Booklore service by @Cinzya in #9105
- Add EspoCRM, provided by the official team by @tmachyshyn in #8658
- fix(parsers): preserve ${VAR} references in compose instead of resolving to DB values by @andrasbacsai in #9147
- fix(proxy): validate stored config matches proxy type by @andrasbacsai in #9146
- v4.0.0-beta.470 by @andrasbacsai in #9139
New Contributors
- @tmachyshyn made their first contribution in #8658
Full Changelog: v4.0.0-beta.469...v4.0.0-beta.470
-
nginx
- nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755)
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755)
nginx-1.28.3 stable and nginx-1.29.7 mainline versions have been released, with fixes for buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753) and OCSP result bypass vulnerability in stream (CVE-2026-28755)