A maintenance release with disclosed security fixes, dependency and toolchain updates, and changes to checkpoint and image-processing behavior. User-database reads are bounded in openUserFile, which may reject inputs that previously worked.
Action needed (2)
securitycriticalSecurity fixes for five disclosed CVEs
The release includes fixes for CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262, along with the associated GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, and GHSA-xhf5-7wjv-pqxp advisories.
breakingBounded
openUserFileuser-database readsUser-database file reads in
openUserFileare now bounded, so inputs that previously worked may be rejected.