❌

Normale weergave

UniFi Network Application 10.6.97

Door: UI-Glenn
20 Augustus 2026 om 21:56

Overview

UniFi Network Application 10.6.97 adds Drift Inspector, Topology Spotlight, and expanded Safe Ops features, along with the improvements and bug fixes listed below.


Β 


Added Drift Inspector to Blueprints in Site Manager

  • Make local changes to sites using Blueprint orchestrations, with a clear view of configuration drift and an easy way to resolve it.


Added Topology Spotlight

  • Quickly highlight and filter selected devices for easier navigation and troubleshooting in large topologies.


Improved SafeOps features

  • Expanded Test & Confirm support to VPN and Management networks.
  • Added Nightly Channel AI Optimization with configurable radio selection and an improved optimization algorithm.


Improved Time Machine Experience

  • Added Time Machine for Radios to review radio usage metrics, configuration changes, and radio events from the past 24 hours.
  • Expanded Port Manager Time Machine to All Ports, making it easier to identify and troubleshoot problematic network segments.

Improvements

  • Added a flapping devices filter to Port Manager Time Machine for clients with frequent reconnections.
  • Added the Reduced Firewall State Timeouts profile for EFG, EF-Core, and UXG-Enterprise.
  • Added a confirmation prompt when updating all devices from the Devices filter side panel.
  • Added sorting to Network Lists and descriptions on hover.
  • Added column sorting to tables in Settings Overview.
  • Added an Allow Empty Password option for RADIUS MAC Authentication.
  • Added the ability to disable the LCM screen on meshed UX7 devices.
  • Added Sort by Topology to the Devices page.
  • Added a notice for unsupported devices in Test & Confirm settings.
  • Added a disabled port filter to Port Manager.
  • Added an Additional Labels option to Infrastructure Topology.
  • Added a warning in Topology when Sonos devices with mixed wired and wireless connections are detected.
  • Added validation to prevent OpenVPN Server and Site-to-Site VPNs from using the same UDP port.
  • Added a Spotlight selection option in Topology.
  • Added the ability to disable insecure OpenVPN compression.
  • Added Multicast Suppressor support.
  • Requires UAP 8.8 or newer.
  • Added a Lock Port to UniFi Device option to Port Manager.
  • Requires Switch firmware version 7.6 or newer.
  • Added support for adopting multiple U5G devices on the same site over LAN.
  • Added support for using Domain Network Lists in QoS Policies.
  • Added support for customizing WAN interfaces used for Automatic Speed Tests.
  • Added Bulk Update Management to the Devices page.
  • Improved Device Auto-Recovery stability.
  • Improved Data Plane Protection resiliency.
  • Improved Traffic Activity Statistics accuracy.
  • Improved the Observability section.
  • Improved the device revert experience by allowing easy reversion for all devices with the same Device model and version.
  • Improved DHCP Options validation.
  • Improved the Dynamic DNS settings user experience.
  • Improved RADIUS settings validation.
  • Improved Virtual Network management in Topology.
  • Improved the AV Manager user experience.
  • Improved Honeypot validation.
  • Improved the display of unstable links in Infrastructure Topology.
  • Improved network subnet validation against static route destinations.
  • Improved Port Profiles management in Port Manager.
  • Improved Port Manager by automatically opening Time Machine.
  • Improved the Device Update confirmation screen by showing the number of connected devices that might be interrupted.
  • Improved OpenVPN server configuration files by removing periodic TLS key renegotiation.
  • Requires UniFi OS 5.1 or newer
  • Improved VPN Server settings validation.
  • Improved application startup resiliency.
  • Improved the Port Forwarding table user experience.
  • Removed the STP Edge note from Port Manager when Auto STP Edge is disabled.
  • Separated the Reset Stats and Clear Last Seen Device actions in Port Manager.
  • Enabled DHCP Guarding by default on new networks.

Bugfixes

  • Fixed an issue where client devices with a configured Power Source could be automatically enrolled in Device Auto-Recovery.
  • Fixed an issue where the AP Stopped Mesh system log could be generated repeatedly after an AP switched to a wired uplink.
  • Fixed an issue where the High Traffic alarm incorrectly reported wireless client downloads as uploads.
  • Fixed an issue where SD-WAN Mesh VPN tunnels could remain after the configuration was removed.
  • Fixed an issue where the client count in the WiFi Broadcast overview was incorrect when MLO clients were connected.
  • Fixed an issue where filter counters could flicker on the Connectivity page in rare cases.
  • Fixed an issue where the hostname was not set correctly for a UX7 connected via mesh.
  • Fixed an issue where a custom APN could be lost after moving a SIM between slots on a U5G.
  • Fixed an issue where the UX7 did not display connected wireless clients in the Devices list.
  • Fixed a rare issue where opening Client Observability could impact system stability.
  • Fixed an issue where DAS/DAC (CoA) was unavailable when using Open security with RADIUS MAC Authentication.
  • Fixed an issue where MC-LAG configurations could be lost after restoring a backup.
  • Fixed an issue where the Connectivity page was missing some roaming events.

Additional information



Β 

UniFi OS Server


Going forward, we recommend users upgrade toΒ UniFi OS ServerΒ for all self-hosted deployments. It provides the full UniFi OS Platform experience, ensuring you receive the latest features, improvements, and integrations.



UniFi Network Native Application for UniFi OS

Compatible with UDM, UDR, UDR7, UDR 5G Max, Express, Express 7, and UCG models (Ultra, Max, Fiber, and Industrial) on UniFi OS 3.1.6 or later. UDM-Pro, UDM-SE, and UDW have been using it since UniFi OS 5.1.5.

  • The UniFi OS update utilizes the application version compatible with your console.
  • The manual update process via SSH requires a compatible package. Incompatible packages will be rejected on installation.
  • Older UniFi OS versions (prior to UniFi OS 3.1.6) on the UDM and UDR continue to utilize the standard UniFi Network Application for UniFi OS.

Β 

Β Checksums

3c61771b272fce0dc4d885b27f5aacc3 | UniFi-installer.exe
a7e03c2267472a2ca92e08757af3664e | UniFi-Network-Server.dmg
edb6f32f292e5a1746c0759c3381d91c | UniFi.unix.zip
05a81e3c1e56c9bdb93b9e3203804441 | unifi_sysvinit_all.deb
14c2556535e87d5fbbb2331573455051 | unifi-uos_sysvinit.deb
4561503f51df61ab44bb793f45cf4641 | unifi-native_sysvinit.deb
601df32736f41e40a80a3e472450a3e1 | unifi_sh_api


------------------------------------------------------------------------------------------------------------------------


0a8bac122b9ff697fdbf1f591acaee20871fe8c2b3080ece50264fc8bd0014e3 | UniFi-installer.exe
8a60ce8b69575777e7f983642368a49c04f5a995dc78bda84ca74d16557c680d | UniFi-Network-Server.dmg
9d50b389b418c0007c4ad234b8d0e608150c2a88aabb1ab9b1f12394f489e3d3 | UniFi.unix.zip
a03edb46d0d1df8edd517c07d80588addf62799493a4b20846317705620fe5cc | unifi_sysvinit_all.deb
c6ff500ba2d21c99097fa3be89041965d4e90c76f90e0f4722855827319ce47c | unifi-uos_sysvinit.deb
ada60aa072c880df48f0d1f7cc5c4134fef20a6e501e1f56ecc075a4e5953a06 | unifi-native_sysvinit.deb
1791685039ea795970bcc7a61eec854058e3e6fc13c52770e31e20f3beb622eb | unifi_sh_api
  •  

Stable Channel Update for Desktop

20 Augustus 2026 om 22:28

The Stable channel has been updated to 151.0.7922.173/.174 for Windows and Mac and 151.0.7922.173 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 7 security fixes. Please see the Chrome Security Page for more information.


[N/A][522819252] Critical CVE-2026-76017: Use after free in Chromoting. Reported by Google on 2026-06-11

[N/A][513757918] High CVE-2026-76018: Privilege elevation in Import. Reported by Google on 2026-05-16

[TBD][539032888] High CVE-2026-76019: Incorrect authorization in Workers. Reported by Anonymous on 2026-07-26

[TBD][541837151] High CVE-2026-76020: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-03

[N/A][541854084] High CVE-2026-76021: Use after free in DOM. Reported by Google BigSleep@Grape on 2026-08-02

[TBD][543798025] High CVE-2026-76022: Buffer overflow in Network. Reported by 0xAlessandro on 2026-08-07

[TBD][545124048] High CVE-2026-76023: Improper resource control in Linux Toolkit Theming. Reported by Keita Sode and Daisuke Hatakeyama of SYZD Research on 2026-08-11


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Asterisk Release 23.5.0-rc2

20 Augustus 2026 om 17:41

The Asterisk Development Team would like to announce
release candidate 2 of asterisk-23.5.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/23.5.0-rc2
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 23.5.0-rc2

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-23.5.0-rc2

Links:

Summary:

  • Commits: 1
  • Commit Authors: 1
  • Issues Resolved: 1
  • Security Advisories Resolved: 0

User Notes:

Upgrade Notes:

Developer Notes:

Commit Authors:

  • George Joseph: (1)

Issue and Commit Detail:

Closed Issues:

  • 2085: [bug]: res_http_websocket: SEGV if we're a server and receive a PONG frame

Commits By Author:

  • George Joseph (1):

    • res_http_websocket: Check for client before handling PONG frames.

Commit List:

  • res_http_websocket: Check for client before handling PONG frames.

Commit Details:

res_http_websocket: Check for client before handling PONG frames.

Author: George Joseph
Date: 2026-08-13

websocket_handled_pong_or_close() now checks that session->client is valid
before trying to check missed_pong_count.

Resolves: #2085

  •  

Asterisk Release 20.21.0-rc2

20 Augustus 2026 om 17:41

The Asterisk Development Team would like to announce
release candidate 2 of asterisk-20.21.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/20.21.0-rc2
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 20.21.0-rc2

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-20.21.0-rc2

Links:

Summary:

  • Commits: 1
  • Commit Authors: 1
  • Issues Resolved: 1
  • Security Advisories Resolved: 0

User Notes:

Upgrade Notes:

Developer Notes:

Commit Authors:

  • George Joseph: (1)

Issue and Commit Detail:

Closed Issues:

  • 2085: [bug]: res_http_websocket: SEGV if we're a server and receive a PONG frame

Commits By Author:

  • George Joseph (1):

    • res_http_websocket: Check for client before handling PONG frames.

Commit List:

  • res_http_websocket: Check for client before handling PONG frames.

Commit Details:

res_http_websocket: Check for client before handling PONG frames.

Author: George Joseph
Date: 2026-08-13

websocket_handled_pong_or_close() now checks that session->client is valid
before trying to check missed_pong_count.

Resolves: #2085

  •  

Asterisk Release 22.11.0-rc2

20 Augustus 2026 om 17:40

The Asterisk Development Team would like to announce
release candidate 2 of asterisk-22.11.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/22.11.0-rc2
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 22.11.0-rc2

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-22.11.0-rc2

Links:

Summary:

  • Commits: 1
  • Commit Authors: 1
  • Issues Resolved: 1
  • Security Advisories Resolved: 0

User Notes:

Upgrade Notes:

Developer Notes:

Commit Authors:

  • George Joseph: (1)

Issue and Commit Detail:

Closed Issues:

  • 2085: [bug]: res_http_websocket: SEGV if we're a server and receive a PONG frame

Commits By Author:

  • George Joseph (1):

    • res_http_websocket: Check for client before handling PONG frames.

Commit List:

  • res_http_websocket: Check for client before handling PONG frames.

Commit Details:

res_http_websocket: Check for client before handling PONG frames.

Author: George Joseph
Date: 2026-08-13

websocket_handled_pong_or_close() now checks that session->client is valid
before trying to check missed_pong_count.

Resolves: #2085

  •  

1.61 Update: Volvo FH Series 6 100 Year Edition

Door: Petr
20 Augustus 2026 om 17:00

We are very excited to join Volvo Trucks in the celebrations of their 100th anniversary by welcoming the Volvo FH Series 6 100 Year Edition to Euro Truck Simulator 2 with the release of the upcoming 1.61 update! Let's take a look at what's in store.Β 

Volvo Group was established in 1927 and will be celebrating its 100th anniversary next year. To mark this special occasion, Volvo Trucks is introducing the anniversary edition of their latest model, the Volvo FH Series 6, and we are proud to be bringing the updates coming with this edition to Euro Truck Simulator 2 as well.

The Volvo FH Series 6 100 Year Edition will bring a new look for both the interior and exterior, reflecting Volvo's century of innovation with driver-centric features. These additions will be reflected in the base game of ETS2 with new accessories and paint jobs available for the Aero XL cabin of the Volvo FH Series 6, enabling every virtual trucker to drive the beautiful centennial edition in our game as well, when the 1.61 update releases.

On the exterior, this update introduces two new paint jobs: 100y Edition – Night and 100y Edition – Day. The two designs feature distinctive dark or light exterior colour striping, complemented by two additional Centennial logos on either side of the truck. You will also be able to choose from two different light boxes: one with the 100y logo and another one with the FH16 logo.

We are also adding one brand new interior option featuring black leather door panels with unique stitching, carpets, a rear wall decoration featuring the 100 Year Edition logo, and a decorative dashboard ambient LED lighting available in red or blue colour options.

To complete the interior, you will also have the option to customize it with a range of exclusive accessories. These include a black leather steering wheel and new two-tone seats combining a black leather base with a grey textile upper section and the 100y logo.

We are very proud to be able to bring these new additions to the world of Euro Truck Simulator 2 and enjoy the celebrations along with our community and Volvo Trucks, whom we wish many more successful years of producing great trucks and machines!

To keep track of future updates from our games, make sure to give ourΒ X/Twitter, Instagram, Facebook, Bluesky, TikTok, and YouTubeΒ a follow. OrΒ subscribe to our newsletterΒ to stay informed. Keep on trucking!

  •  

Firefox 151.0.4

9 Juni 2026 om 18:01

Fixed

  • Fixed an issue on Windows where Firefox could become unresponsive when using the back and forward buttons. (Bug 2039866)

  • Fixed an issue where Firefox could fall back to software rendering on some older GPUs, reducing graphics performance. (Bug 2043249)

  • Fixed a crash on Windows that could occur when Firefox interacted with accessibility services. (Bug 204330)

  • Fixed an issue where some text input fields could incorrectly show a resize handle. (Bug 2044051)

  •  

CPU-Z 3.01

20 Augustus 2026 om 18:00
  • CPU-Z Validator V3 (more information *at that address*).
  •  

Distribution Release: FydeOS 23.0

20 Augustus 2026 om 16:54
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The FydeOS project has announced the release of FydeOS 23.0, a significant update of the project's ChromeOS-based Linux distribution that aims to bring a Google Chromebook-like experience to standard PCs. This new version upgrades the Android subsystem to Android 13: "We are delighted to announce the release of....
  •  

Release 2026.08.20

20 Augustus 2026 om 02:52

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.08.20

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.08.20

Changes

  • upgrade yt-dlp from 2026.7.4 to 2026.8.19 (8695478)

  •  

Distribution Release: Garuda Linux 260819

20 Augustus 2026 om 02:04
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Garuda Linux project has published a new release. The new version, 260819 "Temeraire", introduces a refined way to handle disk sectors and switches the default kernel to match CachyOS. "When creating new disk layouts, the installer will pick the biggest sector size a disk supports, and for....
  •  

Counter-Strike 2 Update

20 Augustus 2026 om 01:36
[p]\[ MAPS ][/p][p]Boulder[/p]
  • [p]Updated to the latest version from the Community Workshop (Update Notes)[/p][/*]
[p]Poseidon[/p]
  • [p]Updated to the latest version from the Community Workshop (Update Notes)[/p][/*]
[p]\[ GAMEPLAY ][/p]
  • [p]Fixed a case where player speed was too high when moving against walls.[/p][/*]
  •  

Dopamine 3.0.9

Door: digimezzo
19 Augustus 2026 om 20:56

[3.0.9] - 2026-08-19

Added

  • Added an equalizer
  • Added a clear selection button on artists, genres, albums, playlist folders and playlists screens.
  • Added an option to show a more compact total duration in songs lists

Changed

  • Updated the Portuguese (Brazil) translation

Fixed

  • Crash on startup when failing to get the system color when "Follow system color" is enabled
  • Snap version does not start on the first launch
  • Artists whose names start with accented letters (e.g. Ş, Ü) incorrectly grouped under # instead of their base letter in the artists list
  • Tracks of multi-disc albums were grouped by disc number across albums instead of being listed per album
  • When sorting large playlists, songs sometimes move back to their original position.
  • Newline character not processed correctly on some lyrics

  •  

Early Stable Update for Desktop

19 Augustus 2026 om 18:58

The Stable channel has been updated to 152.0.7977.54/.55 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Iceland: Research Trip

Door: Petr
19 Augustus 2026 om 17:00

A few weeks ago, several members of our team embarked on a research trip to Iceland to gather valuable reference material for the upcoming DLC. Let's take a look at what they thought of their journey!

The team that traveled to Iceland consisted of the map DLC lead Ivo and two map designers, Ashley and Johana. Travelling with them also were some of our colleagues from the marketing department, as they had the opportunity for the first time to join a research trip and document the whole journey. That's why we will also be bringing you a packed SCS On The Road episode in the future where you will see this whole trip in more detail.

"Visiting Iceland was wonderful because first-hand experience allows you to take in the landscape with all your senses and provides an insight that digital sources struggle to match. It was fascinating to "get to know" the places on which we work and to find our bearings in a landscape we know well, even though we were seeing it for the first time," says Ivo.

Even though the development of this map expansion is already in a more advanced state, this trip will help the team gather any missing references as well as learn even more about The Land of Fire and Ice.

"Soon after arrival, we started noticing some of the landmarks we already knew from the game. Seeing Iceland with my own eyes was truly incredible. All the mountains were so vast and varied that I sometimes found it difficult to fully comprehend them. My personal favourite memories were when we were at a rest stop and had time to go for a short walk on a footpath, just seeing nature up close while surrounded by giant mountains," Ashley told us.

Everyone on the trip was amazed by the beauty of this island and admitted it helped them get the feeling of what it's like to be there in person, as Johana explains here: "You get a pretty good sense of how gorgeous the place is from everything you can look up on the internet, but once you're there it really hits you. One thing you can't really experience from the street view is the scale, which is an important thing when it comes to landscape. And boy, weren't we surprised at how BIG some of the mountains and waterfalls really are."

The team managed to cover quite a distance in the one week they were visiting, taking into account how many different places they needed to stop by to study and take references.

"We managed to drive the entire western half of the Ring Road, roughly from Lake MΓ½vatn in the north to VΓ­k in the south, and visit interesting locations along the way. Everywhere we went, we came across something unusual for us, be it high mountains, fjords, lava fields, numerous small waterfalls and torrents that suddenly appear in some narrow gorge, or sheep and horses grazing freely. As well as various types of roads and urban areas, particularly in Akureyri and ReykjavΓ­k," Ivo says.

Iceland has a completely different and unique landscape compared to what we have worked on in the past, so seeing it with their own eyes was an unforgettable experience for our map designers. "What impressed me most was the raw beauty of the landscape itself. Iceland is a living textbook of geological processes, and that's something that fascinates me. My personal favourite, however, was visiting Thingvellir National Park, because I'm a history nerd and standing on the spot where the Viking Althing used to meet was a dream come true for me," Ivo shared with us.

One thing the team had to get used to was Iceland's almost endless daylight. During their visit, the sun set for less than three hours each day, but at least it gave them a lot of extra time. "Back home, we're not used to seeing the sun even around midnight, but although it made it a bit harder to sleep, on the other hand it allowed us to make the most of every day," Ivo told us.

We also have to send a huge thanks to Volvo Trucks, who invited us to be part of the filming of their videos, which we cannot reveal right now, but we are working on making another SCS On The Road episode with a behind-the-scenes look at the shooting. Thanks to that, our map designers had the unique opportunity to get in the passenger seat of a truck for the first time and gain insight into how the view from a truck differs from that of a standard car.

"Thanks to Volvo, we were able to cover part of the journey in a truck with a local professional driver, which gave us a brilliant new perspective," Ivo shared. Ashley was also impressed by the experience: "It was much higher than I expected, and the view was certainly great. Overall, a very cool experience," she said. Johana added: "Never in my life have I expected to be inside a truck and be driven in Iceland of all the places. It was an amazing experience and a work trip I won't soon forget!"

Our map designers were also able to compare their ongoing work on the map expansion with what they saw in real life. "I was really happy about how familiar everything felt, compared to what we already have in-game. Almost as if I had stumbled into the game itself," Ashley said.

"I got to see the town Γ“lafsvΓ­k, which I'm working on in the map, and was able to check out their harbour, which was quite helpful since there aren't enough references online. Now back in Prague, I got the sense of a map designer's pride while looking at our own Iceland in the editor, thinking, yup, this is gonna look great!" Johana concluded.

If you want to get a similar experience as our map designers and travel around Iceland in ETS2, don't forget to add this map expansion to your Steam wishlist.

Also, remember to give our X/Twitter, Instagram, Facebook, Bluesky, and TikTok a follow to receive updates not only about Iceland, but also other news from our games straight to your feed. Or subscribe to our newsletter to stay informed. Until next time, happy haulin'!

  •  

FileZilla Client 3.71.0 released

Door: Tim Kosse
19 Augustus 2026 om 15:50

New features:

  • FTP(S), SFTP: Entering an empty path in the remote path edit field now returns back to the initial home directory

Bugfixes and minor changes:

  • FTP(S): Fix parsing of permissions for chmod dialog on servers that include both perms and unix.mode facts in MLSD output
  • SFTP: Updated fzssh to 1.4.0 to support additional algorithms and key file formats
  • Official binaries are now linked against wxWidgets 3.2.11
  • FTP(S): Fixed parsing of paths on servers with the server type set to DOS. Some malformed paths were wrongly accepted, confusing the engine; such paths are now rejected early.
  • Refactored engine internals to remove influences from FTP-specific concepts that were permeating into other protocols
  •  

v5.52.1

19 Augustus 2026 om 13:37

5.52.1 (2026-08-19)

πŸ”₯ Bug fix

  • admin: unrelated permission conditions no longer block page access (3ded36a7b0)
  • content-manager: deduplicate MCP tool names when an api has multiple content types (#27357)
  • content-manager: refraining from counting error draft relations … (#26900)
  • upload: show tooltip on truncated names in the media library (#27340)
  • users-permissions: unable to clear refresh token cookie on logout due to mismatched options (#25106)

βš™οΈ Chore

  • update develop with release 5.52.0 (#27343)
  • deps: bump fast-uri from 3.1.4 to 3.1.5 (#27242)

❀️ Thank You

  •  

v4.4-rc.1

19 Augustus 2026 om 13:10

Release candidate

This is the first release candidate for Coolify v4.4. It is intended for testing and validation before the stable v4.4 release.

Do not use this release candidate in production without appropriate testing. Please report regressions through GitHub Issues.

Changes in next

These notes include only changes currently unique to next compared with main.

OpenID Connect and authentication

  • Added first-class OpenID Connect (OIDC) authentication, including discovery, JWKS signing-key resolution, token validation, PKCE support, and identity linking.
  • Added OIDC configuration and registration-policy controls to instance settings.
  • Added an option to automatically join OIDC users to the root team.
  • Improved OAuth login handling and profile indication for SSO accounts.

Integration tokens

  • Added team-scoped integration-token management under Security settings.
  • Added create, edit, permission, and authorization handling for integration tokens.

Settings and server management

  • Improved email-provider configuration and enforced mutually exclusive provider selection.
  • Added notification-channel enable/disable handling for Discord, email, Pushover, Slack, Telegram, and webhooks.
  • Improved Docker prerequisite and package installation, including Alpine Linux package handling.
  • Improved log-drain toggle rollback behavior and SSH multiplexing controls.

Additional improvements

  • Improved settings navigation and action-button state handling.
  • Updated bundled service templates.
  • Added broader automated coverage for OIDC, OAuth registration, integration tokens, email providers, server packages, and related settings.

Comparison: main...next

  •  

Waarom Sam Altman graag weerwolft | POM S12E01

19 Augustus 2026 om 06:30

Alexander nam op vakantie alleen een e-ink telefoon mee om van zijn schermverslaving af te komen (alle clichés blijken waar), terwijl Ernst-Jan juist achtervolgd werd door de virale Parro-clip en de woede uit het onderwijs die daaruit voortkwam. Daarna één grote vraag: is insider media de redding van de journalistiek? Alexander tipt The Nord Stream Conspiracy, een waargebeurd James Bond-verhaal over twee Oekraïense officieren die op eigen houtje een pijpleiding opblazen, en Ernst-Jan diept een reality show van Peter Thiels Founders Fund op waarin Sam Altman en Palmer Luckey doodleuk weerwolven spelen. Met de analyse van Anu Atluru in de hand leggen ze uit waarom alle waardevolle media insider media worden, waarom het gezichtsloze middensegment verdampt, en waarom die 22-jarige van nu.nl op TikTok zo raar praat over KLM-broodjes. De ondergang lijkt nabij, tot een taai verhaal over een onbestaande brug over het IJ en een anoniem meme-account uit Amsterdam-Noord laten zien dat hyperlokale journalistiek misschien juist het beste insider medium is dat er bestaat.

Alle artikelen en video’s terugkijken? Abonneer je dan op onze nieuwsbrief via pom.show

Sponsor worden van de podcast? Kijk dan op pom.partners



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.pom.show

πŸ’Ύ

  •  

v4.3.9

18 Augustus 2026 om 23:53

Features

  • Added an instance setting to control forced HTTPS redirects for the dashboard.

Fixes

  • Prevented DNS validation from hanging on unresponsive resolvers by adding five-second query timeouts (#11378, closes #11351).
  • Preserved active deployments when shared SSH multiplexing connections were refreshed or cleaned up (#11377, closes #11372).
  • Restored GitLab push and merge-request deployments that could fail with an HTTP 500 response (#11284, closes #11262).
  • Allowed long-running volume backups to run for up to ten hours while preserving custom timeouts on existing schedules (#11358, closes #11273).
  • Prevented SSL-enabled database containers from being left stopped during certificate ownership repair and container replacement (#11315, #11352, closes #11312).
  • Prevented OAuth provider settings from being erased when OAuth settings were re-seeded (#8210).
  • Enforced team-scoped authorization for scheduled tasks, preventing cross-team access and execution (#11239, closes #11238).
  • Prevented large bind-mounted files and oversized remote output from exhausting memory while services, tasks, logs, volumes, and configuration were read (#10960).
  • Made upgrades recover correctly when status data was temporarily unavailable after restart (#11350, closes #11347).
  • Prevented stuck container removal from blocking deployments; cleanup was deferred and retried instead.
  • Enabled compression for the dashboard over HTTPS (#10828, closes #10802).
  • Corrected S3 error email links so they pointed to the configured instance instead of localhost (#8633).
  • Fixed highlighted-button, spinner, and keyboard-shortcut contrast across custom themes (#11279).
  • Fixed account menus remaining open after clicking outside an expanded Appearance panel (#11374, closes #11373).
  • Centered icon tooltips over their triggers (#11382).

Improvements

  • Surfaced pending proxy configuration and outdated Traefik states with actionable warning indicators.
  • Made server warnings clearer, improved deployment-log scrolling, and corrected spacing in database backup settings.
  • Clarified proxy-label generation choices (#11362).
  • Clarified that saving Sentinel settings restarted Sentinel.
  • Made database and OAuth seed operations transactional to preserve existing data when seeding failed (#11360).

What's Changed

New Contributors

Full Changelog: v4.3.8...v4.3.9

  •  

Stable Channel Update for Desktop

18 Augustus 2026 om 22:13

Β The Stable channel has been updated to 151.0.7922.169/.170 for Windows and Mac and 151.0.7922.169 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 15 security fixes. Please see the Chrome Security Page for more information.


[N/A][534923522] Critical CVE-2026-76034: Buffer overflow in WebGL. Reported by Google on 2026-07-15

[N/A][540087398] Critical CVE-2026-76036: Buffer overflow in Dawn. Reported by Google on 2026-07-28

[N/A][516715010] High CVE-2026-76033: Inappropriate implementation in CORS. Reported by Google on 2026-05-26

[N/A][517612295] High CVE-2026-76037: Link following in CredentialProvider. Reported by Google on 2026-05-28

[N/A][522732244] High CVE-2026-76044: Race condition in USB. Reported by Google on 2026-06-11

[N/A][525167753] High CVE-2026-76039: Incorrect reference resolution in Core. Reported by Google on 2026-06-18

[N/A][534862220] High CVE-2026-76040: Use after free in Browser. Reported by Google on 2026-07-14

[N/A][536439844] High CVE-2026-76035: Inappropriate implementation in Media. Reported by Google on 2026-07-19

[N/A][536460270] High CVE-2026-76042: Use of uninitialized resource in GPU. Reported by Google on 2026-07-19

[N/A][536581050] High CVE-2026-76046: Buffer overflow in ANGLE. Reported by Google on 2026-07-19

[TBD][539350801] High CVE-2026-76043: Incorrect calculation in V8. Reported by Raghav Maheshwari on 2026-07-27

[N/A][540027341] High CVE-2026-76041: Information leak in Skia. Reported by Google on 2026-07-28

[TBD][541251902] High CVE-2026-76047: Type confusion in V8. Reported by ywatanabee on 2026-07-31

[TBD][541926503] High CVE-2026-76038: Type confusion in V8. Reported by un3xploitable && GF on 2026-08-03

[TBD][543082390] High CVE-2026-76045: Use after free in WebGL. Reported by OpenAI Codex Security (amyb) on 2026-08-05


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Extended Stable Update for Desktop

18 Augustus 2026 om 21:28

The Extended Stable channel has been updated to 150.0.7871.250 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

v12.3.0

18 Augustus 2026 om 19:28

⚠️ Potential Breaking Changes

Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076)
exists() now throws when the lookup itself fails, for example on a timeout, a connection error or rejected credentials, instead of also reporting false. Callers that relied on a false result for any failure need to handle the error. Note that S3 answers 403 rather than 404 for a missing object when the credentials cannot list the bucket, so granting s3:ListBucket is needed to keep getting a clean "missing" answer.

Fixed "Update Items" and "Delete Items" operations affecting every item in a collection when given an empty or missing key or query (#27759)
Nothing to target is a no-op

"Update Items" and "Delete Items" operations now return null instead of falling back to every item whenever the configuration doesn't target anything β€” that is, when key is empty or missing (e.g. [], "") and query is empty or missing (e.g. {}). "Update Items" additionally returns null when there is nothing to write, i.e. an empty or missing payload (e.g. {}, or [] for a batch payload). Flows that relied on the previous fallback to every item can use {"limit": -1}.

Contradictory options error

"Update Items" and "Delete Items" operations now throw an error when both key and query are defined. "Update Items" also throws when key or query is combined with a batch payload.

Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111)
The default maximum output dimension is now 6000 px. Users who rely on the previous limit of 3000 px can explicitly configure ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION.

Used the pm2 bundled with @directus/api in the Docker images instead of installing a separate copy, so its dependencies follow the versions pinned by the workspace (#28120)
If you extend the Docker image: it now boots via CMD ["node", "docker-entrypoint.cjs"], which runs the same bootstrap then pm2-runtime sequence as before. pm2-runtime is no longer on the PATH, so a custom CMD that called it directly should hand off to docker-entrypoint.cjs instead. pm2 itself remains on the PATH for docker exec diagnostics.

  • @directus/api
    • Fixed "Update Items" and "Delete Items" operations affecting every item in a collection when given an empty or missing key or query (#27759 by @ComfortablyCoding)
  • @directus/storage-driver-cloudinary
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/storage-driver-s3
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/storage-driver-local
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/storage-driver-supabase
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/sdk
    • Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)

✨ New Features & Improvements

  • @directus/app
    • Added search-first AI tool discovery for chat and MCP tools, with schema pinned as a root chat tool. (#27797 by @bryantgillespie)
    • Added a caption field to the WYSIWYG image drawer, which wraps the image in a figure with a figcaption (#28026 by @alvarosabu)
    • Added the collection name appended to display template in item and drawer headers (#28078 by @AlexGaillard)
  • @directus/api
    • Added search-first AI tool discovery for chat and MCP tools, with schema pinned as a root chat tool. (#27797 by @bryantgillespie)
  • @directus/cli
    • Introduced @directus/cli (d6s / directus-cli) β€” a client-side CLI that syncs schema and configuration between Directus instances through committed JSON files, with sync pull, sync diff, sync push, and an interactive wizard (#27861 by @bryantgillespie)
  • @directus/types
    • Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)

πŸ› Bug Fixes & Optimizations

  • @directus/app
    • Removed unused dependencies across the monorepo (#28049 by @ComfortablyCoding)
    • Removed dead β€œSave and Quit” dropdown row outside the content item view (#28051 by @robluton)
    • Fixed relational items with unsaved nested values, such as newly added translated items in a content version, rendering as -- instead of their display template (#28010 by @alvarosabu)
    • Fixed the repeater interface options showing empty sub-fields, and dropping their key and type on save, when the sub-fields were created through the API without repeating the key and type inside their meta (#28041 by @lazerg)
    • Fixed relational fields showing stale values after a manual flow updated them (#28056 by @AlexGaillard)
    • Fixed the Markdown interface's Edit and Preview buttons not indicating which view is currently active (#28023 by @Aniket-a14)
    • Fixed silent failure of dragging & dropping files with an unrecognized extension into the file library (#28093 by @alvarosabu)
    • Fixed a request for a non-existent item when opening an item whose Many-to-One field references an unsaved parent (#27975 by @sourav-18)
    • Updated outdated type definitions for directus_files, directus_collections, directus_deployments, directus_settings, and directus_users (#27945 by @kheiner)
    • Fixed field configuration appearing to close when selecting related collection that switches interface (#28118 by @robluton)
    • Fixed the translations interface AI translation button only showing for admins (#28089 by @AlexGaillard)
    • Fixed SSO login redirecting to the last visited page instead of the originally requested page (#28080 by @AlexGaillard)
    • Stopped the policy creation modal from writing app access permission rows to the database, matching the policy detail page where app access permissions are applied at runtime instead of stored (#28101 by @alvarosabu)
    • Added block-level custom formats to the WYSIWYG interface, so block, selector and items entries in the Custom Formats option apply classes and attributes to paragraphs, headings and other block nodes from the Formats dropdown (#28044 by @alvarosabu)
    • Fixed WYSIWYG content the editor can't represent being hidden and unrestorable in the comparison modal (#28067 by @alvarosabu)
  • @directus/api
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
    • Added a batch-import regression test pinning that a negative temporary key maps like any other non-existent auto-increment key in merge mode (#27861 by @bryantgillespie)
    • Updated MCP tool descriptions and safety annotations for connector clients. (#28090 by @bryantgillespie)
    • Updated or replaced various dependencies to address GHSA-rgw5-rvv9-x895 (#28050 by @br41nslug)
    • Improved MS SQL Server reliability and performance by optimizing schema introspection and only enabling trigger compatibility when required (#27699 by @br41nslug)
    • Updated various dependencies to address CVEs (#28110 by @br41nslug)
    • Fixed slow extension sync from remote storage during startup. Added EXTENSIONS_STORAGE_MAX_CONCURRENCY to configure the maximum number of concurrent requests to the extensions storage location (#27989 by @dstockton)
    • Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111 by @ComfortablyCoding)
    • Removed unused dependencies across the monorepo (#28049 by @ComfortablyCoding)
    • Fixed TranslationsService.updateMany incorrectly rejecting single-row updates containing both key and language (#28001 by @suhailopensource)
    • Fixed collection names with surrounding whitespace being accepted on creation (#28038 by @lazerg)
    • Fixed WebSocket rate limiting breaking on shared Redis setups where keys must start with a per-project prefix. The WebSocket limiter now accepts RATE_LIMITER_WEBSOCKETS_* values as overrides, including RATE_LIMITER_WEBSOCKETS_KEY_PREFIX to override the Redis key prefix. (#28107 by @AlexGaillard)
  • @directus/storage-driver-azure
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/storage-driver-gcs
    • Fixed storage connections leaking when asset requests were cancelled or a transformation failed, which eventually made every asset request return a permission error until Directus was restarted (#28076 by @dstockton)
  • @directus/release-notes-generator
  • @directus/schema
    • Improved MS SQL Server reliability and performance by optimizing schema introspection and only enabling trigger compatibility when required (#27699 by @br41nslug)
  • @directus/env
    • Fixed slow extension sync from remote storage during startup. Added EXTENSIONS_STORAGE_MAX_CONCURRENCY to configure the maximum number of concurrent requests to the extensions storage location (#27989 by @dstockton)
    • Updated ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION to match ASSETS_TRANSFORM_IMAGE_MAX_DIMENSION (6000 px) (#28111 by @ComfortablyCoding)
  • @directus/extensions-registry
  • @directus/composables
  • @directus/extensions
  • @directus/errors
  • @directus/stores
  • @directus/utils
    • Removed unused dependencies across the monorepo (#28049 by @ComfortablyCoding)
    • Updated ESLint dependencies eslint, @eslint/js, eslint-plugin-vue, and typescript-eslint. Replaced eslint-plugin-import with eslint-plugin-import-x (#28047 by @br41nslug)
  • @directus/sdk
    • Removed unused dependencies across the monorepo (#28049 by @ComfortablyCoding)
    • Fixed an unhandled rejection in the sdk realtime client when the socket errored or closed during the auth handshake (#28009 by @Deluvio)
  • @directus/specs
    • Fixed OpenAPI spec drift, added missing query parameters, and ensured consistent parameter ordering across list endpoints (#27938 by @kheiner)
  • @directus/types
    • Fixed extensions that set sandbox without an enabled flag being rejected as invalid (#28087 by @dstockton)
  • @directus/extensions-sdk
    • Fixed extension validate crashing on extensions with a disabled sandbox due to an invalid findIndex call (#28087 by @dstockton)

πŸ“¦ Published Versions

  • @directus/app@17.1.0
  • @directus/api@39.0.0
  • @directus/cli@12.2.0
  • @directus/composables@11.6.1
  • create-directus-extension@12.1.3
  • @directus/env@6.2.1
  • @directus/errors@2.5.1
  • @directus/extensions@4.0.3
  • @directus/extensions-registry@4.0.3
  • @directus/extensions-sdk@18.0.3
  • @directus/memory@4.0.3
  • @directus/pressure@4.0.3
  • @directus/release-notes-generator@3.0.1
  • @directus/schema@14.0.2
  • @directus/schema-builder@1.0.2
  • @directus/specs@15.1.1
  • @directus/storage-driver-azure@13.0.3
  • @directus/storage-driver-cloudinary@14.0.0
  • @directus/storage-driver-gcs@13.0.3
  • @directus/storage-driver-local@14.0.0
  • @directus/storage-driver-s3@14.0.0
  • @directus/storage-driver-supabase@5.0.0
  • @directus/stores@3.0.1
  • @directus/themes@2.0.3
  • @directus/types@16.2.0
  • @directus/utils@13.5.3
  • @directus/validation@3.0.3
  • @directus/sdk@25.0.0

  •  

South Dakota: Mount Rushmore

Door: David
18 Augustus 2026 om 17:00

Today, we’re taking you on a journey to one of South Dakota’s most recognizable landmarks and a true highlight of the upcoming South Dakota DLC for American Truck Simulator: Mount Rushmore! Set among the rugged beauty of the Black Hills, this iconic monument is also the reason South Dakota is officially known as the β€œMount Rushmore State,” and it’s sure to be one of the most memorable sights you’ll encounter while exploring the state.

Standing high above the surrounding landscape, Mount Rushmore features the monumental granite faces of four U.S. presidents: George Washington, Thomas Jefferson, Theodore Roosevelt, and Abraham Lincoln. Carved into the side of the mountain between 1927 and 1941, the monument has become one of the most famous landmarks in the United States, attracting millions of visitors from around the world each year.

Players will also be able to experience the impressive sight of Mount Rushmore from the roads running through the Black Hills. Nearby, you’ll also find the small town of Keystone, a popular gateway to the monument and the surrounding attractions. With its charming downtown, unique Western-style character, and location surrounded by the Black Hills, Keystone makes for a great stop as you explore this scenic corner of South Dakota. The town is also home to a depot for the historic 1880 Train, a steam-powered excursion railroad connecting Keystone and Hill City along an original late-1800s mining route.

The journey to Mount Rushmore also gives you the opportunity to experience some of the area's scenic roads. US-16, also known as Mount Rushmore Road, connects Keystone with nearby communities and offers beautiful views as it winds through the Black Hills. Along the way, you’ll pass through several tunnels, some of which offer a unique view of Mount Rushmore framed in the distance. For an even more memorable drive, you can take the scenic US-16A, also known as the Iron Mountain Road. With its winding route, forested surroundings, and carefully designed curves, this road is an adventure in itself.

As you make your way through the Black Hills, keep your eyes peeled for the many scenic views and natural landmarks surrounding the roads. The landscape here is quite different from the wide-open plains found elsewhere in South Dakota, with dense forests, rugged rock formations, and curvy mountain roads creating a unique driving experience. The Black Hills are also steeped in motorcycle culture, with the region being a popular destination for riders and enthusiasts. You may spot a few of them parked at some of the area’s parking lots, adding another touch of local character to your journey.

Mount Rushmore is just one of the many highlights waiting for you in our upcoming South Dakota DLC for American Truck Simulator. Whether you’re making a delivery, exploring the Black Hills, or simply taking the scenic route, there will be plenty of opportunities to stop, look around, and enjoy the views!

We can’t wait for you to experience South Dakota for yourself. If you’re excited about this map expansion, be sure to add the South Dakota DLC to your Steam wishlist! Don't forget to follow us on X/Twitter, Facebook, Instagram, TikTok, Bluesky, and YouTube, orΒ sign up for our newsletter.Β Until then, keep your engines running and stay tuned for more news from the Mount Rushmore State!

  •  

Release 2026.08.18

18 Augustus 2026 om 16:09

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.08.18

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.08.18

Changes

  • fix: let the download reach the PO token provider (closes #1064) (f3c464f)
  • feat: carry the SponsorBlock toggle into subscriptions (b10bb61)
  • feat: first-class SponsorBlock toggle (8c2990e)

  •  

UniFi OS Server 5.1.37

Door: UI-Glenn
18 Augustus 2026 om 14:51

Overview


Β 

Bundled Application

Improvements

  • Added the option to disable Remote Access on Fabric-linked UniFi OS Server consoles.
  • Improved Windows updates to prevent them from being blocked by UAC prompts.
  • Improved application backup reliability for large datasets.
  • Improved UniFi OS Server update reliability when downloads stop transferring data.
  • Improved error messages when required ports are already in use or unsupported WSL mirrored networking is enabled.
  • Improved system stability.

Bugfixes

  • Fixed the security issues mentioned in Security Advisory Bulletin 067.
  • Fixed an issue where IP addresses could be missing on Windows.
  • Fixed legacy Network migration on Windows and macOS.
  • Fixed an issue where Identity WiFi could crash due to incomplete Network connectivity settings.
  • Fixed an issue where One-Click WiFi system log events could be missing for some RADIUS usernames.
  • Fixed an issue where Network-managed console devices could disappear from discovery results.
  • Fixed an issue where a stopped application could restart when another application was registered.
  •  

Firefox 154.0

18 Augustus 2026 om 20:00

New

  • Firefox's Local Network Access protections now extend to WebSocket connections. Websites that try to open a WebSocket to a device on the local network will now ask for permission first.

  • In Smart Window, Firefox can now suggest groups of related tabs and propose a name for each group.

    Screenshot of organized tabs in Smart Window

  • Firefox on Windows is now a supported browser for NVIDIA GeForce NOW, letting users stream supported PC games directly in the browser.

  • Local Firefox profile backups are now available on macOS in addition to Windows and Linux, and backups can be restored across all three platforms.

  • Sites can now be exempted from having their cookies and site data cleared on shutdown without also being exempted from tracking protection and other cookie restrictions.

  • The full-page Translations feature now translates <iframe> content.

  • The full-page Translations feature now runs language identification on all page loads, resulting in an improved experience for offering translations to users.

  • Windows users can now choose a different Firefox app icon in Settings. This is not yet available for MSIX installations, macOS, or Linux, but is coming soon.

  • The address bar now includes a Manage AI quick action that opens the AI controls in Settings.

  • Performing a hard reload on a page (holding Shift while clicking the Refresh button) now also clears and updates its cached favicons.

Fixed

  • Fixed an issue on macOS where closing a browser window could leave behind an invisible window that continued to capture mouse clicks over the area where it used to be.

  • Fixed an issue on Windows where an auto-hiding taskbar would not appear until the Firefox window had been minimized and restored after launch.

  • Fixed an issue where the Windows taskbar would appear in front of a full screen Picture-in-Picture window.

  • Fixed the Vertical Tabs sidebar staying visible in full screen mode. It now hides along with the toolbars and reappears when the cursor moves to the edge of the screen.

  • Fixed PDF documents not being scaled correctly in print preview when the Fit to Page Width option is used.

  • Various security fixes.

Changed

  • Video seeking is now significantly faster on all operating systems, making it quicker to jump to a point in a video.

  • Text selected in a PDF is now highlighted the same way as text on a web page, and the highlight color follows operating system settings such as high-contrast mode.

  • Firefox View is moving out of the toolbar by default for new profiles and for profiles where it hasn't been used recently. It can still be opened from List all tabs > View all tabs, or added back from the Customize toolbar menu.

Enterprise

Developer

Web Platform

  • Firefox now supports the text-box-trim and text-box-edge CSS properties, and the associated text-box shorthand. These properties control the leading space above and below text, enabling simpler and more consistent vertical spacing and alignment.

  • Firefox now supports the sibling-index() and sibling-count() CSS functions. These functions allow an element to be styled with calculations that use its index among its siblings and its total count of siblings (including itself), respectively.

  • Added a time picker user interface to <input type="time"> and <input type="datetime-local">, making selecting a time more accessible and intuitive.

  • Added support for the No-Vary-Search HTTP response header for the HTTP disk cache. Servers can now declare which URL query parameters are irrelevant to the response, allowing Firefox to reuse cached resources across parameter variations and improving cache hit rates.

  • Firefox now supports new Iterator.prototype.chunks and Iterator.prototype.windows methods that allow consuming an iterator as either overlapping or non-overlapping subsequences of configurable size.

  • Firefox now supports Iterator.prototype.includes(), allowing developers to check whether an iterator contains a given value without first converting it to an array.

  • Firefox now supports the Iterator.prototype.join method, which allows joining an iterator into a string, similar to Array.prototype.join.

Unresolved

  • For users with vertical tabs enabled, the sidebar may not persist across Firefox restarts. Vertical tabs can be re-enabled after the restart by clicking the sidebar toolbar button. A fix is currently in development. (Bug 2065431)

  • When toolbars are hidden in fullscreen mode (the default on Windows and Linux), the vertical tabs sidebar does not appear when moving the cursor to the left edge of the screen. As a workaround, move the cursor to the top of the screen to reveal both toolbars and sidebar together. Alternatively, you can also right-click the toolbar and uncheck the Hide toolbars option. We are currently working on a fix. (Bug 2064638)

  • Following recent changes to Firefox’s Address Autofill logic, some users may experience autofill failures when auto-filling addresses. (Bug 2065145) Fixed in 154.0.1.

  • Following recent changes to Firefox’s password storage, some users may experience slower performance when Firefox accesses saved passwords. Users with a Primary Password enabled may also see unexpected password prompts, such as when starting Firefox or opening certain content. (Bug 2064411) Fixed in 154.0.1.

Community Contributions

  •  

v1.20.1

18 Augustus 2026 om 14:27

Fixes and improvements

General

  • prevent spamming of 'stream is closed' error during shutdown (#6062)
  • impose a minimum value to clock rate of always-available tracks (#6086) Clock rates below 10 caused the emission of empty samples. Fix the issue by imposing a minimum value of 8khz, that rises to 22khz in case of AAC.
  • fix race condition during sub-stream creation (#6075) (#6095) When a stream with always-available turned on switches from offline to online, or from a publisher to another, the reader mutex was not acquired during writing of codec parameters. This is now fixed.
  • restore ability to run the server in a read-only file system (#6098) This was temporarily lost after the introduction of the native MoQ QUIC listener.
  • fix deadlock when changing configuration through file and API (#6077) (#6101) When changing configuration in parallel by editing the configuration file and calling the API, the server could get into a deadlock that prevented any further action. This is fixed.
  • change default value of authHTTPExclude (#6103) by default, do not exclude any action from HTTP authentication. Old value triggered several security warnings.
  • add destFingerprint parameter (#6106) this allows to validate self-signed certificates of forward destinations.
  • pmp4: fix panic in case of bad input (bluenviron/mediacommon#354) the stsc box was not checked properly. This is now fixed.
  • pmp4: fix panic in case of bad input (bluenviron/mediacommon#355) The parser was not checking that the MP4 was properly sending addresses of samples, resulting in samples with invalid addresses. This is now fixed.
  • pmp4, fmp4: do not emit empty payloads (bluenviron/mediacommon#353)

API

  • redact password in responses (#6110) passwords are not exposed anymore through the API. They can only be set, not read.

Media-Over-QUIC

  • support pulling streams from other servers (#6111)
  • do not accept empty payloads (#6085)
  • limit maximum amount of published tracks (#6087) this prevents clients from consuming an excessive amount of memory.
  • make /moq URL suffix optional (#6107) In order to establish a MoQ session with WebTransport, a /moq suffix was required until now. This is now optional in order to allow connecting to the server with the standard MoQ URL format.
  • impose maximum size on pending reordered bytes (#6112) Decrease the maximum memory that clients can take by imposing a maximum size of 100MB on the pending reordered bytes.

RTSP

  • accept relative digest URI (bluenviron/gortsplib#1118) RFC 2617 section 3.2.2 allows the digest URI to be either an absolute URI or a relative path. Some clients use the latter, which was rejected with "wrong URL" since urlMatches only accepted an exact match against the absolute request URL.
  • send initial RTCP sender report without waiting for a period (bluenviron/gortsplib#1052) (bluenviron/gortsplib#1111) (bluenviron/gortsplib#1120) Reports were emitted only on the ticker, so the first one arrived Period after Initialize (10s by default) and later still when no RTP packet had been sent by that first tick, since report() returns nil until then and the next opportunity is another Period away.
  • ensure that decoders can produce only output that does not crash encoders (bluenviron/gortsplib#1123)
  • discard empty Opus and G722 RTP packets (bluenviron/gortsplib#1131)
  • improve error message when setting read buffer fails (bluenviron/gortsplib#1133)
  • server: fix race condition when recording (bluenviron/gortsplib#1134) state was not protected.

RTMP

  • inform about authentication failures (#5657) (#6072) Reply with NetStream.Play.Failed or NetStream.Publish.Unauthorized when a client is not authorized to play or publish. This makes clients like OBS to stop recreating the connection in case of authentication failures.

  • reader: do not emit empty frames (bluenviron/gortmplib#106)

  • parse video PTS delta as signed (bluenviron/gortmplib#88)
    HLS

  • prefer hls.js on iOS too (#6090) In the embedded HLS reader, use hls.js on iOS, that was previously disabled due to compatibility issues that should have been solved.

  • unlock the session-in-query+iOS combination (#6088) this was previously blocked because the session in query was meant to be dynamic, therefore incompatible with static playlists required by iOS. It is not anymore, so we can support that.

  • stop using cookies with plain HTTP (#6089) in case of plain HTTP, fall back to query parameters, which are safer than HTTP cookies because they are not shared between different pages/domains, although they are visible in the URL.

WebRTC

  • support forwarding streams (#6099)
  • fix warning when IPv6 is disabled (#5733) (#6048)
  • improve performance by ignoring mDNS candidates (#4963) (#6064) mDNS candidates sometimes require a large CPU portion, they are not involved in any connectivity method mentioned in the documentation, they work in local networks only.

SRT

  • apply UDP read buffer size from configuration (#6069) Use upstream datarhei/gosrt's ListenerControl config field (datarhei/gosrt#144) to set SO_RCVBUF on the SRT listener's UDP socket.

RPI Camera

  • fix crash when secondary stream is enabled (#6060) (#6061)
  • prevent invalid MJPEG sizes (#6080) width and height of MJPEG frames must be multiple of 8 and less than 2048, otherwise they cannot be routed with RTP/RTSP.

Dependencies

  • code.cloudfoundry.org/bytefmt updated from v0.83.0 to v0.85.0
  • github.com/alecthomas/kong updated from v1.16.0 to v1.16.1
  • github.com/asticode/go-astits updated from v1.15.0 to v1.16.0
  • github.com/bluenviron/gohlslib/v2 updated from v2.4.2 to v2.4.3
  • github.com/bluenviron/gortmplib updated from v1.0.0 to v1.0.1
  • github.com/bluenviron/gortsplib/v5 updated from v5.6.3 to v5.6.4
  • github.com/bluenviron/mediacommon/v2 updated from v2.9.2 to v2.9.3
  • github.com/datarhei/gosrt updated from v0.11.0 to v0.11.1-0.20260812091715-a77b40bb4b76
  • github.com/pion/ice/v4 updated from v4.4.0 to v4.4.1
  • github.com/pion/transport/v4 updated from v4.0.2 to v4.1.0
  • github.com/stretchr/testify updated from v1.11.1 to v1.12.0
  • golang.org/x/crypto updated from v0.54.0 to v0.55.0
  • golang.org/x/net updated from v0.57.0 to v0.58.0
  • github.com/davecgh/go-spew removed
  • github.com/pion/srtp/v3 updated from v3.0.12 to v3.0.13
  • github.com/pmezard/go-difflib removed
  • golang.org/x/text updated from v0.40.0 to v0.41.0
  • hls.js updated from v1.6.16 to v1.7.0

Security

Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.

Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:

ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx

You can verify checksums of binaries by downloading checksums.sha256 and running:

cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check

  •  
❌