6 hours ago
openssl

OpenSSL 3.0.22

OpenSSL 3.0.22 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

6 hours ago
openssl

OpenSSL 3.4.7

OpenSSL 3.4.7 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

6 hours ago
openssl

OpenSSL 3.5.8

OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

6 hours ago
openssl

OpenSSL 3.6.4

OpenSSL 3.6.4 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

6 hours ago
openssl

OpenSSL 4.0.2

OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

23 hours ago
dgraph

v25.4.1

What's Changed

Full Changelog: https://github.com/dgraph-io/dgraph/compare/v25.4.0...v25.4.1

1 days ago
questdb

10.0.1

QuestDB 10.0.1

QuestDB 10.0.1 is a maintenance release that builds on 10.0.0 with improvements across SQL, QWP, Live Views, DECIMAL, storage, and the Web Console. Expanded fuzz, fault-injection, and concurrency coverage strengthens a number of less-common execution and failure paths.

The release also improves high-cardinality window queries and Live View refreshes, streams eligible ordered UNION ALL queries without a full sort, reduces idle-worker allocation on JDK 24+, and bundles Web Console 2.0.3.

For any questions or feedback, please join us on Slack or on Discourse.

See also our prettier release notes page.

Highlights

Reliability and protocol hardening

  • QWP table-update caching now follows table lifecycle and schema changes more closely, including DROP/recreate, rename, and column-type changes. Durable acknowledgement accounting also covers transactions committed at the append-time row threshold. #7383, #7484
  • Partition squash and POSTING-index lifecycle paths gain additional concurrency and I/O handling, improving behavior around open partitions, concurrent writers, and rollback. #7487, #7485, #7382
  • Column type conversion now reports low-disk-space failures cleanly, and metadata compatibility improves for tables created before QuestDB 6.1. #7537, #7476

Faster and more capable windows and Live Views

Compatible window functions over the same PARTITION BY key can now share one map and one probe per row. The largest gains occur at high key cardinality: in the PR benchmark, a three-function bounded window over one million keys ran about 2.1x faster and retained 65 MiB less native memory on the cached path. The optimization is controlled by the reloadable cairo.sql.window.map.fusion.enabled setting. #7515

The same change substantially reduces Live View refresh, seal, restart, and transient-memory costs. In the reported 3.8-million-account benchmark, per-batch refresh fell from 4.43 seconds to 0.48 seconds and restart from 79.7 seconds to 3.86 seconds. Live Views can also project aliases and scalar expressions around window functions, with broader coverage for bounded RANGE frames, extreme timestamps, replay, and NOCACHE symbols.

Additional hardening makes view startup, routine base-table DDL, and concurrent refresh behavior more consistent. #7465, #7486, #7512

DECIMAL coverage and interoperability

Expanded DECIMAL coverage improves arithmetic and scale handling, NULL consistency, casts, bind variables, WAL replay, ILP, CSV import/export, Parquet filtering, and storage. #7452

ALTER TABLE ... ALTER COLUMN ... TYPE now converts between DECIMAL and FLOAT/DOUBLE in both directions. For Parquet-backed data, QuestDB converts the affected partitions to native format first.

SQL, protocols, and Web Console

  • Ordered UNION ALL can stream through a merge operator instead of sorting. Eligible full scans ran about 8-9x faster in the PR benchmark, while LIMIT queries can stop without materializing and sorting the full union. Branches must expose compatible designated timestamps and scan order. #7348
  • An all-SYMBOL UNION or UNION ALL now returns SYMBOL. HTTP metadata and CTAS preserve the type instead of widening it to STRING; PGWire continues to expose both through the VARCHAR OID. #7397
  • Scalar subqueries, indexed LATEST ON, lateral aggregates, large GROUP BY maps, VARCHAR date parsing, and SHOW CREATE DATABASE subqueries gain broader plan and edge-case coverage. #7388, #7481, #7432, #7434, #7417, #7384
  • PGWire result framing now handles additional ARRAY, IPv4, and GEOHASH format combinations. ILP TCP authentication handling is more robust for malformed input, and current_user() / session_user() report the authenticated principal. #7469, #7488, #7273
  • Web Console 2.0.3 adds light/dark themes, notebook-level auto-refresh with per-cell overrides, improved grid sizing and editor settings, and OIDC and terminology fixes. #7458, #7533

Changelog

Features

  • feat(sql): return SYMBOL from a UNION over symbol columns by @glasstiger in #7397

Performance

  • perf(core): reduce GC pressure from idle workers on JDK 24+ by @kafka1991 in #7459
  • perf(sql): speed up window queries and fix wrong results in windows and live views by @puzpuzpuz in #7515
  • perf(sql): stream ordered UNION ALL without sorting by @brunocalza in #7348

Fixes

  • fix(core): load view definitions before the engine publishes READY by @RaphDal in #7465
  • fix(sql): fix scalar subquery predicates and timestamp interval pruning by @nwoolmer in #7388
  • fix(core): fix crash when reading tables created before QuestDB 6.1 by @nwoolmer in #7476
  • fix(pgwire): fix queries hanging until the connection times out by @jerrinot in #7469
  • fix(sql): rebind bind variable in deferred indexed LATEST ON by @nwoolmer in #7481
  • fix(sql): handle conservative ASCII hints in VARCHAR date parsing by @jerrinot in #7417
  • fix(core): fix live views turning invalid after routine base table DDL by @bluestreak01 in #7486
  • fix(qwp): reject oversized table counts by @jerrinot in #7493
  • fix(core): fix covering-index reads on Windows by @glasstiger in #7499
  • fix(ilp): stop ILP TCP authentication failures escaping as unhandled errors by @bluestreak01 in #7488
  • fix(core): prevent invalid native-memory writes by @jerrinot in #7453
  • chore(core): harden decimal type handling by @RaphDal in #7452
  • fix(core): stop POSTING index close() truncating a region another writer published by @bluestreak01 in #7485
  • fix(core): prevent false live view invalidation during concurrent refresh by @bluestreak01 in #7512
  • fix(core): fix table suspension after a range replace removes its last partition by @puzpuzpuz in #7380
  • fix(sql): fix NULL results for count expressions in LEFT JOIN LATERAL by @kafka1991 in #7432
  • fix(core): signal restore cancellation promptly on shutdown by @jovfer in #7361
  • fix(qwp): fix silent row loss after DROP in the qwpudp table-update cache by @nwoolmer in #7383
  • fix(core): fix incorrect query results and premature memory-limit errors in large queries by @puzpuzpuz in #7434
  • fix(core): stop partition squash losing var-column data on the open partition by @bluestreak01 in #7487
  • fix(sql): fix filters on SHOW CREATE DATABASE subqueries by @nwoolmer in #7384
  • fix(qwp): fix durable acks issued before the WAL upload is confirmed by @bluestreak01 in #7484
  • fix(core): fix the web console showing "admin" instead of the authenticated user by @glasstiger in #7273
  • fix(core): fix a POSTING index crash on rollback after a value-file I/O error by @puzpuzpuz in #7382
  • fix(core): fix crash on column type conversion under low disk space by @ideoma in #7537

Web Console

Full Changelog: 10.0.0...10.0.1

3 days ago
seaweedfs

4.44

What's Changed

New Contributors

Full Changelog: https://github.com/seaweedfs/seaweedfs/compare/4.43...4.44