26.1 Release Candidate 1 (known as 26.1-rc-1 in the launcher) is the first release candidate for Java Edition 26.1, released on March 19, 2026. This is the first release candidate released in 2026 and the first release candidate to be released with only an unobfuscated build.
Full changelog: https://minecraft.wiki/Java_Edition_26.1-rc-1
UpSnap is, and always will be, free and open source software.
If someone is asking you to pay money for access to UpSnap binaries, source code, or licenses, you are being scammed.
The official and only trusted source for UpSnap is this repository (and its linked releases).
Do not pay third parties for something that is provided here for free.
Reloading has been refactored to encourage more careful consideration of the use of ammo. When you reload a magazine-fed weapon, all remaining ammo in the magazine is discarded and a new, full magazine is taken from the reserves.
Reserve ammunition is now represented either as number of magazines, shells, or bullets, depending on the weapon.
The fill-level of the current weapon is now displayed below the ammo count.
Tuned reserve magazine counts per-weapon.
[ MAP GUIDES ]
Limited map guides are now available in Competitive and Retakes (first 5 rounds of the half, 30 node max).
sv_allow_annotations_access_level supports 3 values: 0 โ disabled. 1 โ limited view. 2 โ full and editable.
sv_annotation_limits_max_rounds_per_half (default 5) determines how many rounds into the half guides are allowed. -1 for unlimited.
Minimal starter map guides have been added for all Active Duty maps.
[ WORKSHOP MAPS ]
Friends playing a Practice or Workshop map can be joined through the friends menu if they have Open Party set.
The Stable channel has been updated to 146.0.7680.153/154 for Windows/Macย andย 146.0.7680.153 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in theย Log
Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havenโt yet fixed.
This update includes 26 security fixes. Please see the Chrome Security Page for more information.
[TBD][475877320] Critical CVE-2026-4439: Out of bounds memory access in WebGL. Reported by Goodluck on 2026-01-15 [TBD][485935305] Critical CVE-2026-4440: Out of bounds read and write in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-20 [TBD][489381399] Critical CVE-2026-4441: Use after free in Base. Reported by Google on 2026-03-03 [TBD][484751092] High CVE-2026-4442: Heap buffer overflow in CSS. Reported by Syn4pse on 2026-02-16 [TBD][485292589] High CVE-2026-4443: Heap buffer overflow in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-18 [TBD][486349161] High CVE-2026-4444: Stack buffer overflow in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-21 [TBD][486421953] High CVE-2026-4445: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22 [TBD][486421954] High CVE-2026-4446: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22 [TBD][486657483] High CVE-2026-4447: Inappropriate implementation in V8. Reported by Erge on 2026-02-23 [TBD][486972661] High CVE-2026-4448: Heap buffer overflow in ANGLE. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-02-23 [TBD][487117772] High CVE-2026-4449: Use after free in Blink. Reported by Syn4pse on 2026-02-24 [TBD][487746373] High CVE-2026-4450: Out of bounds write in V8. Reported by qymag1c on 2026-02-26 [TBD][487768779] High CVE-2026-4451: Insufficient validation of untrusted input in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-26 [TBD][487977696] High CVE-2026-4452: Integer overflow in ANGLE. Reported by cinzinga on 2026-02-26 [TBD][488400770] High CVE-2026-4453: Integer overflow in Dawn. Reported by sweetchip on 2026-02-27 [TBD][488585488] High CVE-2026-4454: Use after free in Network. Reported by heapracer (@heapracer) on 2026-03-01 [TBD][488585504] High CVE-2026-4455: Heap buffer overflow in PDFium. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-01 [TBD][488617440] High CVE-2026-4456: Use after free in Digital Credentials API. Reported by sean wong on 2026-02-28 [TBD][488803413] High CVE-2026-4457: Type Confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-03-01 [TBD][489619753] High CVE-2026-4458: Use after free in Extensions. Reported by Shaheen Fazim on 2026-03-04 [TBD][490246422] High CVE-2026-4459: Out of bounds read and write in WebAudio. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-03-06 [TBD][490254124] High CVE-2026-4460: Out of bounds read in Skia. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-06 [TBD][490558172] High CVE-2026-4461: Inappropriate implementation in V8. Reported by Google on 2026-03-07 [TBD][491080830] High CVE-2026-4462: Out of bounds read in Blink. Reported by heapracer (@heapracer) on 2026-03-09 [TBD][491358681] High CVE-2026-4463: Heap buffer overflow in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-10 [TBD][487208468] Medium CVE-2026-4464: Integer overflow in ANGLE. Reported by heesun on 2026-02-24
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Interested in switching release channels? Find out howย here. If you find a new issue, please let us know byย filing a bug. Theย community help forumย is also a great place to reach out for help or learn about common issues.
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Asahi Linux is an open-source project that ports Fedora to Apple computers that use Apple's Silicon-powered (AArch64) processors. The project's latest version is Fedora Asahi Remix 43. "We are happy to announce the general availability of Fedora Asahi Remix 43. This release brings Fedora Linux 43 to Apple....
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Peropesis project has published a new release, version 3.2, which introduces a dozen new software packages. "Peropesis 3.2 is released. In the new edition, part of the old software was updated and new software was installed. New software installed: 1. git 2.53.0. Git is version control system,....
wireless-regdb: update from 2025.10.07 to 2026.02.04
OpenWrt 24.10 end of life
With the release of OpenWrt 25.12 stable series, the OpenWrt 24.10 stable series will go end of life in 6 months. We will not provide security updates for OpenWrt 24.10 after September 2026. We encourage everyone to upgrade to OpenWrt 25.12 before September 2026.
Upgrading to 24.10
Sysupgrade can be used to upgrade a device from 23.05 to 24.10, and configuration will be preserved in most cases.
For for upgrades inside the OpenWrt 24.10 stable series for example from a OpenWrt 24.10 release candidate Attended Sysupgrade is supported in addition which allows preserving the installed packages too.
Sysupgrade from 22.03 to 24.10 is not officially supported.
There is no configuration migration path for users of the ipq806x target for Qualcomm Atheros IPQ806X SoCs because it switched to DSA. You have to upgrade without saving the configuration.
''Image version mismatch. image 1.1 device 1.0 Please wipe config during upgrade (force required) or reinstall. Config cannot be migrated from swconfig to DSA Image check failed''
User of the Linksys E8450 aka. Belkin RT3200 running OpenWrt 23.05 or earlier will need to run installer version v1.1.3 or later in order to reorganize the UBI layout for the 24.10 release. A detailed description is in the OpenWrt wiki. Updating without using the installer will break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of the Xiaomi AX3200 aka. Redmi AX6S running OpenWrt 23.05 or earlier have to follow a special upgrade procedure described in the wiki. This will increase the flash memory available for OpenWrt. Updating without following the guide in the wiki break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of Zyxel GS1900 series switches running OpenWrt 23.05 or earlier have to perform a new factory install with the initramfs image due to a changed partition layout. Sysupgrade will show a warning before doing an incompatible upgrade and is not possible. After upgrading, the config file /etc/config/system should not be restored from a backup, as this will overwrite the new compat_version value.
Known issues
LEDs for Airoha AN8855 are not yet supported. Devices like the Xiaomi AX3000T with an Airoha switch will have their switch LEDs powered off. This issue will be addressed in an upcoming OpenWrt SNAPSHOT and the OpenWrt 24.10 minor release.
5GHz WiFi is non-functional on certain devices with ath10k chipsets. Affected models include the Phicomm K2T, TP-Link Archer C60 v3 and possibly others. For details, see issue #14541.
treewide: Linksys devices: fix MAC address assignment
WiFi fixes and improvements
mac80211: fix crash triggered by Channel Switch Announcement (CSA) when AP VLAN interfaces are in use
mt76: add MT7990 firmware support (new MediaTek WiFi 7 chipset)
mt76: mt7915: fix power save mode handling
mt76: mt7921/MT7902: add MT7902e MCU and DMA layout support
mt76: mt7996/mt7992: fix crash in transmit path, fix out-of-bounds access during hardware restart, improve MLO/CSA and radar detection support
wifi-scripts: fix incorrect VHT160 capability advertisement โ was incorrectly set on non-160 MHz AP configurations, degrading station upload speed (#22435)
luci-mod-network: fix XSS vulnerability in WiFi scan modal (CVE-2026-32721)
ustream-ssl (OpenSSL variant): fix use-after-free crash causing uhttpd (the LuCI web server) to crash under high load (#19349)
Networking and system fixes
firewall4: set as the preferred firewall package over the legacy firewall package
iptables: prefer the nftables-backed variants (iptables-nft, ip6tables-nft) when iptables is pulled in as a dependency
kernel: CAKE QoS scheduler fixes โ avoid unnecessary synchronization overhead when running without a rate limit, fix DiffServ rate scaling
kernel: SFP: improve Huawei MA5671a module support โ module is now accessible even when no fiber is connected
odhcpd: fix segfault when disabling a DHCP interface, fix DHCPv4 lease tree corruption, fix truncated field in DHCPv6 lease queries, fix DNS search list padding
ppp: fix potential memory safety issue (undefined behavior in memcpy with overlapping buffers); remove the MRU limit patch for PPPoE connections (ppp-project/ppp#573)
Package manager (apk)
apk: update to version 3.0.5 with several OpenWrt-specific bug fixes
apk: add --force-reinstall option to reinstall already-installed packages without requiring a version change
Core component updates
apk: update from 3.0.2 to 3.0.5
jsonfilter: update from 2025-10-04 to 2026-03-16 (fixes CVE-2026-30873)
libubox: update from 2026-02-13 to 2026-03-13 (ABI version stabilized for 25.12 stable series)
Linux kernel: update from 6.12.71 to 6.12.74
odhcpd: update from 2026-01-19 to 2026-03-16
omcproxy: update from 2025-10-04 to 2026-03-07
procd: update from 2026-02-20 to 2026-03-14 (fixes CVE-2026-30874)
umdns: update from 2025-10-04 to 2026-02-06 (fixes CVE-2026-30871, CVE-2026-30872)
ustream-ssl: update from 2025-10-03 to 2026-03-01
Upgrading to 25.12.1
Upgrading from 24.10 to 25.12 should be transparent on most devices, as most configuration data has either remained the same or will be translated correctly on first boot by the package init scripts.
For upgrades within the OpenWrt 25.12 stable series, Attended Sysupgrade is also supported, which allows preserving the installed packages.
Sysupgrade from 23.05 or earlier to 25.12 is not officially supported.
Cron log level was fixed in busybox. system.@system[0].cronloglevel should be set to 7 for normal logging. 7 is the default now. If this option is not set, the default is used and no manual action is needed. fc0c518
Bananapi BPI-R4: Interface eth1 was renamed to sfp-lan or lan4, and interface eth2 was renamed to sfp-wan to match the labels. You have to upgrade without saving the configuration. cd8dcfe
TP-Link RE355 v1, RE450 v1 and RE450 v2: The partition layout and block size changed in this release to fix configuration loss on sysupgrade. Users upgrading from OpenWrt 25.12.0 or earlier must use sysupgrade -F to force the upgrade. The image must not exceed 5.875 MB (6016 KiB).
Known issues
Zyxel EX5601-T0: the WAN interface was renamed from eth1 to wan โ check and update your network configuration after upgrading.
Pixel 10 phones have problems connecting to WPA3-protected WiFi 6 APs. #21486
802.11r Fast Transition (FT) causes connection problems with some WiFi clients when WPA3 is used. #22200
SQM CAKE MQ (cake_mq): throughput may be unexpectedly low on some configurations after the scheduler fixes in this release. #22344
160 MHz channel width cannot be configured. #22481
26.1 Pre-Release 3 (known as 26.1-pre-3 in the launcher) is the third and final pre-release for Java Edition 26.1, released on March 17, 2026.
Full changelog: https://minecraft.wiki/Java_Edition_26.1-pre-3
This is a security release to address a vulnerability where page content, which should be hidden by permissions, could be visible during certain markdown exports.
We strongly advise that you update your instance if you use permissions to control page visibility.
Thanks to Ghufran Raza Khan (GitHub Profile, LinkedIn Profile) for responsibly reporting this issue.
Also thanks to Alex Dan (GitHub Profile) for also reporting this before public announcement.
Full List of Changes
Updated queries used for pages in markdown exports.
[p]Players in Germany and Netherlands will have an X-Ray Scanner tab in their Inventory. For those players, containers can only be opened via X-ray Scanner. The X-Ray Scanner will come preloaded with a one-time exclusive non-tradable "Genuine P250 | X-ray", which must be claimed before using the X-Ray Scanner to reveal items in other containers.[/p][/*]
[p]Keyless Containers, like Souvenir Packages, can be opened without the X-Ray Scanner.[/p][/*]
IAMF: Projection mode Ambisonic Audio Elements muxing and demuxing
Formats: hxvs demuxer
Filters: drawvg, vpp_amf
This release features a lot of internal changes and bugfixes. The groundwork for the upcoming swscale rewrite is progressing.
The Vulkan compute-based codecs, and a few filters, no longer depend on runtime GLSL compilation, which speeds up their initialization.
A companion post about the Vulkan Compute-based codec implementations has been published on the
Khronos blog,
featuring technical details on the implementations and future plans.
We recommend users, distributors, and system integrators to upgrade unless they use current git master.
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: d77void GNU/Linux
News: SUSE may be for sale, MidnightBSD responds to age verification laws, TrueNAS takes its build system private, System76 pushes back against new age declaration bills, Debian updates Trixie media
Questions and answers: All about age verification laws and Linux
Released last week:....
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Paweล Pijanowski has announced the release of SparkyLinux 2026.03, a new update of the project's set of semi-rolling distributions based on Debian's "Testing" branch: "New SparkyLinux 2026.03 'Tiamat' ISO images are available. This release is based on the Debian 'Forky'. Main changes: packages updated from Debian and SparkyLinux....
If you like Part-DB, consider donating to support the development. Press the sponsor button on the main github page, for more info.
Important
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Improvements
Removed MPN fallback from LCSC barcode scanner, the SPN field is used instead for part matching (#1302)
Automatically detect the delimiter on generic CSV BOM imports
Fixed problem of GenericWeb info provider when used behind traefik (#1296)
Fixed 500 error, when mapping in generic CSV BOM import fails (#1298)
Fixed 500 error with displaying part prices, when a user has a currency preference different of base currency, and there is no conversion rate known for it (#1317)
Email/SMTP - The way BookStack sends messages has changed slightly (Specifically, the SMTP HELO domain). This isn't expected to be a breaking change but testing of emails (Using the test send action in Settings > Maintenance) is advised after updating to be sure there's no impact.
Theme System - Within a theme directory, the modules/ folder is now dedicated to theme modules. If you happened to already have a folder of this name in your theme, it's advised to use a different folder name instead.
Full List of Changes
Released in v26.03
Added new module system to the theme system. (#5998)
Added logical theme events for page content render and pre-save. (#6049)
Added logical theme event and class to allow inserting custom views before/after others. (#5998)
Added logical theme event to allow customising the OIDC authentication URL. (#6014)
Updated book delete to return to the parent shelf in a shelf context. (#6029)
Updated book read API endpoint to provide parent shelf information. (#6006)
Updated cursor to pointer for drawio diagrams. Thanks to @lublak. (#5864)
Updated description for per-page display limits. (#6005)
Updated emails to use the domain from the APP_URL in the SMTP HELO. (#5990)
Updated translations with latest Crowdin changes. (#6007)
Fixed empty extra space showing for descriptions when the input is left empty. (#5724)
The Debian project is pleased to announce the fourth update of its
stable distribution Debian 13 (codename trixie).
This point release mainly adds corrections for security issues,
along with a few adjustments for serious problems. Security advisories
have already been published separately and are referenced where available.
The Stable channel has been updated to 146.0.7680.80 for Windows/Macย andย 146.0.7680.80 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in theย Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havenโt yet fixed.
This update includes 1 security fix. Please see the Chrome Security Page for more information.
[N/A][491421267] High CVE-2026-3909: Out of bounds write in Skia. Reported by Google Threat Analysis Group on 2026-03-10
Google is aware that an exploit for CVE-2026-3909 exists in the wild.
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Interested in switching release channels? Find out howย here. If you find a new issue, please let us know byย filing a bug. Theย community help forumย is also a great place to reach out for help or learn about common issues.