Normale weergave

v0.16.16

2 Augustus 2026 om 20:39

[0.16.16] - 2026-08-02

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

  • JMAP Email Delivery Push Notifications (draft-ietf-jmap-emailpush-03)
  • MTA: Allow System Sieve scripts to access orcpt during the DATA stage.

Changed

  • S3: accessKey can now be read from an environment variable or file.

Fixed

  • Meilisearch: Verify index existence using GET instead of creating a new task which times out on busy servers.
  • Branding: Stalwart logo flashes before the per-tenant logo is loaded on the login page.
  • Calendar: iMIP and alarm notification messages embed the default logo using bare LF line endings, producing a single 4247 octet line that strict SMTP relays reject with line too long.
  • DMARC: Failure reports state Identity-Alignment: none when a mechanism authenticated successfully but against an identity that is not aligned with the From domain.
  • Redis: Task and queue locks are never released after a worker dies, because failed lock attempts refresh the lock expiry.
  • Recovery mode: Download WebUI if missing.
  • Logging: The systemd journal tracer omits the parent span's fields.
  • MTA:
    • BDAT chunks sent without a valid MAIL FROM are answered with 552 5.3.4 Message too big for system instead of 503 5.5.1.
    • A maxMessageSize of 0 rejects every message with 552 5.3.4 Message too big for system instead of disabling the size limit.
  • Windows: Listeners bound to the unspecified IPv6 address ([::]), including all defaults, refuse IPv4 connections such as 127.0.0.1, since IPV6_V6ONLY is enabled by default on Windows.

Check binary attestation here

  •  

Introducing North Dakota

Door: David
2 Augustus 2026 om 17:00

We are excited to continue expanding the world of American Truck Simulator as we head further into the Northern Plains. Our map teams are currently working on bringing another unique state to life, filled with sweeping prairies, vibrant communities, and industries that keep America moving:

North Dakota for American Truck Simulator


Welcome to the Peace Garden State! Bordering Canada to the north, North Dakota is a land of sweeping prairies, fertile farmland, winding rivers, and skies that seem to stretch forever. Whether you're rolling into the capital city of Bismarck, navigating the busy streets of Fargo, or passing through communities such as Pembina and the Devil's Lake region, every stop offers a different glimpse into the character of this northern state.


North Dakota's road network is just as memorable as its destinations. Alongside major highways, you'll travel scenic routes like ND-57 and cruise along parts of the famous Enchanted Highway, where towering metal sculptures line the roadside, creating one of the state's most unique driving experiences. Nature lovers will also enjoy the expansive National Grasslands, whose open prairies perfectly capture the beauty of the Northern Plains.

Of course, no trucking adventure would be complete without plenty of cargo to haul. Agriculture remains the backbone of North Dakota, with vast fields producing crops that supply industries across the country. You'll also service facilities such as the sugar processing plant in Wahpeton and support the state's booming oil industry, ensuring there's always another job waiting just down the road.

As you explore, don't forget to keep an eye out for some of North Dakota's most distinctive landmarks. You may spot the state's highest TV tower rising above the prairie or encounter Wahpper, the World's Largest Catfish in Wahpeton. From famous landmarks to quiet country roads, North Dakota is full of memorable moments waiting to be discovered.

We can't wait to share more locations and information about North Dakota in later blogs! If you're excited to explore the Peace Garden State, be sure to add the North Dakota DLC to your Steam wishlist!

Remember to follow us on X/Twitter, Facebook, Instagram, TikTok, Bluesky, and YouTube for all the latest news about this upcoming American Truck Simulator map expansion, or sign up for our newsletter so you never miss an update. Until next time, we wish you happy travels!

  •  

v0.5.4 - “The Nude Organist”

2 Augustus 2026 om 13:10

0.5.4 (2026-08-02)

  • Improved: [#26560] [Plugin] Scripts can now be used to trigger saving a game (limited to the user save folder).
  • Improved: [#26638] Guests will no longer watch rides while they’re underground.
  • Improved: [#26747] Exporting a sprite file now also outputs a JSON file, allowing for round-trip conversions.
  • Improved: [#26763] The ride colour/appearance tab now visually separates fields using group boxes.
  • Improved: [#26765] The ride operations tab now visually separates fields using group boxes.
  • Improved: [#26839] Magnify picked-up peeps when viewport is in double or quadruple zoom.
  • Fix: [#26288] Land bordering map edges does not blend at certain angles.
  • Fix: [#26610] Player list is not updated automatically when a player joins or leaves.
  • Fix: [#26639] Handymen could begin a task while another handyman was already doing the exact same task.
  • Fix: [#26752] The Cut-away View window doesn’t display negative height values correctly on some platforms.
  • Fix: [#26756] Guests cannot puke or litter on sloped path.
  • Fix: [#26758] [Plugin] IPv6 addresses are reported incorrectly.
  • Fix: [#26775] Maze gets wrong intensity boost from size (0.02 per tile instead of 0.01 per 2 tiles).
  • Fix: [#26805] Park entrance path is sometimes invisible when placed.
  • Fix: [#26826] Invalid ride types can be set when the “Allow arbitrary ride type changes” cheat is enabled.
  • Fix: [#26842] Best staff award doesn’t need one of each staff type.

Release created in https://github.com/OpenRCT2/OpenRCT2/actions/runs/30744228503

SHA256 checksums:

e86b79590e197a4f4a4a5767b86378fa9337889f3320f1f442c4674ad4711c88  ./OpenRCT2-v0.5.4-windows-portable-win32.zip
54fadd030336ea03f2de391822faef396325ceefb76d976b97a30f6064dfd977  ./OpenRCT2-v0.5.4-sha256sums.txt
aec44e248dc88e50ed6c9897226053631f5b94bf99f45ccb85bae56d52e01688  ./OpenRCT2-v0.5.4-linux-x86_64.AppImage
19798ebac741069ef91a8e48dc7bbe56e6edbfa1daa4e99ef4045330b0973d61  ./OpenRCT2-v0.5.4-windows-portable-x64.zip
f1985ec320fb511056f9549e844ab0072a92cb224536ddc2ca8c5f246a7c2498  ./OpenRCT2-v0.5.4-windows-installer-win32.exe
01f27dfa7d4cb534c9710c2fb993df7f202493d1dd178622459e3882623a4e1e  ./OpenRCT2-v0.5.4-windows-symbols-arm64.zip
45ae7057fbd3701c1392430f0cdb619e5ccf153b9c4799bba6a38f0dff8167b2  ./OpenRCT2-v0.5.4-Linux-trixie-x86_64.tar.gz
cb8591e2e252444c2fef60b0a9553d3c5cda0d38d51142fdeb7f3e5dc52393ac  ./OpenRCT2-v0.5.4-windows-symbols-win32.zip
9b50ea372a41e1335600e8f4e8b81a6b035d461a59df20d32f3ac989172612f5  ./OpenRCT2-v0.5.4-Linux-bookworm-x86_64.tar.gz
67eb59e88df0ae3a6cc869100a9f3a8aa132df12dc3cf64a0f1999a68f0b0037  ./OpenRCT2-v0.5.4-Linux-resolute-x86_64.tar.gz
d063d00ba809cbae3f3ba9725b6259b4702d84735358d9a599af891bde5726eb  ./OpenRCT2-v0.5.4-android.apk
9c32dde9a23aa07e5249e20a02dd87efdd0e7806f390b70d5d992df1e52d069e  ./OpenRCT2-v0.5.4-Linux-noble-x86_64.tar.gz
7a518d35a76d39c783bb20de4f6fbdb01bd989fe08b3bda616cbfc477a8366b1  ./OpenRCT2-v0.5.4-windows-symbols-x64.zip
c9381c0cf753a1f60a5012a280aad28403a6e8cc5536bfd200b30a03d6512cac  ./OpenRCT2-v0.5.4-windows-portable-arm64.zip
ac6cd0bf3df54db546a6b5aa54f1038c538d05ddb82cfb55b70acd571dbc14d1  ./OpenRCT2-v0.5.4-windows-installer-arm64.exe
32e635854e028b365a28ebef879fa8fa2bdf2e5bf238f094f89da813b6b02620  ./OpenRCT2-v0.5.4-windows-installer-x64.exe
f52fec44e34d3d0094b94f1ff1d5d90f220f9a8ce32c99b2723fb513d2fe1e14  ./OpenRCT2-v0.5.4-macos-universal.zip

  •  

BSD Release: NetBSD 11.0

1 Augustus 2026 om 21:09
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The NetBSD project has announced the release of NetBSD 11.0, the 19th major release of the highly portable operating system. The new version includes a port to the RISC-V architecture, better Linux compatibility, and a virt68k port. "New port to the RISC-V processor architecture. NetBSD 11.0 is the....
  •  

Distribution Release: Archcraft 2026.08.01

1 Augustus 2026 om 20:09
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Aditya Shakya has announced the release of Archcraft 2026.08.01, the latest stable release of the project's Arch-based lightweight and fast Linux distribution. This release adds the Sway Wayland compositor as the new desktop choice in live mode (beside the Openbox and bspwm window managers): "August 2026 ISO image....
  •  

Distribution Release: 4Mlinux 52.0

1 Augustus 2026 om 03:25
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The 4MLinux minimal distribution has published a new release, version 52.0. The new version includes several key package updates, simplified wireless network configuration, better support for legacy graphics cards, and a new game. The release announcement states: "The status of the 4MLinux 52.0 series has been changed to....
  •  

HWMonitor 1.67

31 Juli 2026 om 20:20
  • Corsair HX1000i/HX1200i/HX1500i PSUs.
  • NZXT Kraken Z, Kraken Plus and Kraken Elite AIOs.
  • AMD Radeon RX 9050 (Navi 44).
  • NVIDIA GPUs Crossbar clock.
  •  

ATS Road Trip: 1967 Ford Mustang Gameplay Preview

Door: Alex
31 Juli 2026 om 17:00

Ready to hit the open road behind the wheel of a true American legend? Today, we're excited to share a new gameplay preview from our upcoming Road Trip module for American Truck Simulator, featuring the iconic 1967 Ford Mustang Fastback, which is a part of the Ford Car Pack DLC.


Join us as we go behind the wheel of this timeless muscle car for your very first look at it in action in American Truck Simulator. From its unmistakable fastback styling to its powerful performance, the '67 Mustang embodies the spirit of American driving like few vehicles ever have.

And what better place to take this American legend for a spin than in the West Coast of the U.S! We'll be cruising from Carson City, Nevada and into Yosemite National Park, where we'll not only take in the breathtaking scenery and winding roads, but also put the car through its paces, showcasing its performance and driving dynamics. Along the way, you'll also get a first look at one of the new exploration mechanics coming with the Road Trip, so be sure to watch the whole video!



We're still hard at work on the Ford Car Pack, so please keep in mind that everything shown in this gameplay preview is still very much a work in progress. This includes the vehicle sounds and driving behaviour, all of which will continue to be refined before release. 

We hope you enjoyed this preview of the 1967 Ford Mustang in American Truck Simulator. If you did, be sure to leave a like and a comment on the video, as our team would love to hear your first impressions. Don't forget to add the Ford Car Pack to your Steam Wishlist to be notified when it launches. We thank you for all your support, and we'll see you on the road!

  •  

A big win for Android interoperability

31 Juli 2026 om 02:00

Something big just happened. As the Open Home Foundation’s Android developer for Home Assistant, I was invited by the European Commission to consult on Android interoperability. On July 16, 2026, the Commission adopted a decision requiring Alphabet to open up eleven Android features — including always-on wake word detection, ambient sensor access, and screen automation — to all assistants, on equal terms.

  •  

South Dakota: Sioux Falls

Door: Alex
30 Juli 2026 om 17:00

Today, we're taking a closer look at Sioux Falls, the largest city in South Dakota and one of the highlights of our upcoming South Dakota DLC for American Truck Simulator. Whether you're delivering cargo or simply enjoying the drive, this city offers plenty of memorable sights and destinations to explore. Let's take a closer look!


Located in the southeastern corner of South Dakota, Sioux Falls is the state's largest city. Built around the Big Sioux River, the city has grown from a small historic settlement into a bustling city in the Midwest, while still retaining many of its historic landmarks. Our map team has worked to recreate many of the locations that make Sioux Falls instantly recognisable, giving drivers plenty to discover as they travel through the city.


Upon arriving in the city, you'll be greeted by the Welcome to Sioux Falls sign, and no visit would be complete without seeing Falls Park, where the city's famous waterfalls can be found. These cascading falls on the Big Sioux River are not only the inspiration behind the city's name but also one of South Dakota's top attractions.


Heading into Downtown Sioux Falls, you'll find a vibrant mix of historic architecture, modern businesses, and bustling streets. Keep an eye out for the beautifully recreated Minnehaha County Courthouse, an impressive quartzite building that has stood proudly in the city for well over a century. Nearby, you'll also pass the local bus station, where players can spot a colourful mural that celebrates the city's artistic culture and community spirit.


Through the heart of the city, you'll be able to spot several local landmarks, which include the Arc of Dreams sculpture and Fawick Park. History enthusiasts may also recognise the USS South Dakota Battleship Memorial, dedicated to the crew of the famous WWII battleship. The memorial features one of the ship's original main gun barrels alongside displays commemorating those who served aboard the vessel.


Beyond its landmarks, Sioux Falls is a bustling centre of industry, offering plenty of opportunities for hard-working truckers. From delivering to a food processing plant, warehouse, construction site, and rail supply depot, to transporting cargo for a metalworks, wind turbine factory, recreation vehicle dealership, and truck dealership, there's no shortage of work.


You'll also be able to haul materials & equipment to and from the city's impressive quarry, a nod to the region's long-standing quarrying industry that helped shape many of Sioux Falls' historic buildings.


Whether you're making deliveries or admiring its historic downtown, Sioux Falls is a fantastic destination to explore in our upcoming South Dakota DLC for American Truck Simulator. If you like what you've seen here today, be sure to add it to your Steam Wishlist! We look forward to sharing more from this work-in-progress map expansion in the future. Until next time, keep on truckin'!

  •  

Making our web analytics open source with Plausible

29 Juli 2026 om 02:00

The Open Home Foundation fights for privacy, choice, and sustainability. These principles are at the heart of everything we do, including how we handle website analytics. Our position is clear: we reject tools that track individuals across the web to monetize their data. Instead, we want aggregated, anonymized analytics that show how our websites are performing overall — without identifying who our visitors are, or compromising their privacy.

  •  

Distribution Release: NethSecurity 8.8.0

30 Juli 2026 om 03:30
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Davide Marini has announced the release of NethSecurity 8.8.0, a major update of the project's OpenWRT-based firewall distribution, with MultiWAN, deep packet inspection, VPNs and threat protection features. It is designed primarily for small and medium-sized businesses: "We are pleased to announce the release of NethSecurity 8.8.0. This....
  •  

Stable Channel Update for Desktop

30 Juli 2026 om 02:03

 The Stable channel has been updated to 151.0.7922.71/.72 for Windows and Mac and 151.0.7922.71 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 370 security fixes. Please see the Chrome Security Page for more information.

[N/A][514442821] Critical CVE-2026-17650: Use after free in Compositing. Reported by Google on 2026-05-18

[N/A][517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-28

[N/A][519262990] Critical CVE-2026-17652: Use after free in Views. Reported by Google on 2026-06-02

[N/A][520514458] Critical CVE-2026-17653: Use after free in Skia. Reported by Google on 2026-06-05

[N/A][522314940] Critical CVE-2026-17654: Race in Updater. Reported by Google on 2026-06-10

[N/A][522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-06-11

[N/A][523725277] Critical CVE-2026-17656: Use after free in Ozone. Reported by Google on 2026-06-14

[$36000][502293787] High CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-14

[$1000][523030583] High CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on 2026-06-12

[N/A][495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google on 2026-03-23

[N/A][497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-29

[N/A][497451790] High CVE-2026-17661: Use after free in Loader. Reported by Google on 2026-03-29

[N/A][497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google on 2026-03-29

[N/A][500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-07

[N/A][500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google on 2026-04-08

[N/A][511277457] High CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08

[N/A][511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google on 2026-05-10

[N/A][513043537] High CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513134019] High CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-14

[N/A][513228974] High CVE-2026-17670: Use after free in Views. Reported by Google on 2026-05-14

[N/A][513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14

[N/A][513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-15

[N/A][513735177] High CVE-2026-17673: Integer overflow in QUIC. Reported by Google on 2026-05-16

[N/A][513791232] High CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google on 2026-05-16

[N/A][513920258] High CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google on 2026-05-17

[N/A][513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][515452019] High CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google on 2026-05-21

[N/A][516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google on 2026-05-25

[N/A][516486611] High CVE-2026-17680: Heap buffer overflow in Color. Reported by Google on 2026-05-25

[N/A][516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google on 2026-05-26

[N/A][516837126] High CVE-2026-17682: Integer overflow in ANGLE. Reported by Google on 2026-05-26

[N/A][516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-26

[N/A][516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26

[N/A][516910278] High CVE-2026-17685: Use after free in Autofill. Reported by Google on 2026-05-27

[N/A][516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-27

[N/A][516985726] High CVE-2026-17687: Type Confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517016413] High CVE-2026-17688: Use after free in Input. Reported by Google on 2026-05-27

[N/A][517045160] High CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google on 2026-05-27

[N/A][517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google on 2026-05-27

[N/A][517321292] High CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517350808] High CVE-2026-17692: Use after free in DataTransfer. Reported by Google on 2026-05-28

[N/A][517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google on 2026-05-28

[N/A][517511796] High CVE-2026-17694: Use after free in DOM. Reported by Google on 2026-05-28

[N/A][517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-28

[N/A][517550034] High CVE-2026-17696: Side-channel information leakage in Media. Reported by Google on 2026-05-28

[N/A][517575864] High CVE-2026-17697: Type Confusion in ANGLE. Reported by Google on 2026-05-28

[N/A][517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-29

[N/A][517785292] High CVE-2026-17699: Use after free in Views. Reported by Google on 2026-05-29

[N/A][517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google on 2026-05-29

[N/A][517972648] High CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google on 2026-05-29

[N/A][517973093] High CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google on 2026-05-29

[N/A][518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][519259107] High CVE-2026-17704: Use after free in ANGLE. Reported by Google on 2026-06-02

[TBD][519665978] High CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia on 2026-06-04

[N/A][519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-03

[N/A][519701233] High CVE-2026-17707: Uninitialized Use in Media. Reported by Google on 2026-06-03

[N/A][519738647] High CVE-2026-17708: Use after free in Audio. Reported by Google on 2026-06-04

[N/A][519981494] High CVE-2026-17709: Race in Downloads. Reported by Google on 2026-06-04

[N/A][519991712] High CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google on 2026-06-04

[N/A][519996040] High CVE-2026-17711: Race in Downloads. Reported by Google on 2026-06-04

[N/A][520535595] High CVE-2026-17712: Race in Skia. Reported by Google on 2026-06-05

[N/A][520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-06-06

[N/A][521293438] High CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google on 2026-06-08

[N/A][521491778] High CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521866061] High CVE-2026-17716: Use after free in Updater. Reported by Google on 2026-06-09

[N/A][522063116] High CVE-2026-17717: Integer overflow in ANGLE. Reported by Google on 2026-06-10

[N/A][522079372] High CVE-2026-17718: Use after free in ANGLE. Reported by Google on 2026-06-10

[N/A][522304853] High CVE-2026-17719: Use after free in Input. Reported by Google on 2026-06-10

[N/A][522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-11

[N/A][523495723] High CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google on 2026-06-13

[N/A][523592755] High CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13

[N/A][523718303] High CVE-2026-17723: Use after free in Media. Reported by Google on 2026-06-14

[N/A][523720739] High CVE-2026-17724: Race in Chrome for iOS. Reported by Google on 2026-06-14

[TBD][528501127] High CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022 on 2026-06-27

[N/A][529867799] High CVE-2026-17726: Integer overflow in WebGL. Reported by Google on 2026-06-30

[N/A][529932631] High CVE-2026-17727: Out of bounds write in WebGL. Reported by Google on 2026-07-01

[$10000][461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P on 2025-11-16

[$5000][503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl) on 2026-04-18

[$2000][476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001) on 2026-01-17

[$500][520656237] Medium CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff on 2026-06-07

[N/A][40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26

[TBD][463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25

[N/A][495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google on 2026-03-24

[N/A][496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google on 2026-03-25

[N/A][496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google on 2026-03-26

[N/A][496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-03-27

[N/A][498000415] Medium CVE-2026-17737: Use after free in Bluetooth. Reported by Google on 2026-03-31

[N/A][498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-03-31

[N/A][498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-31

[N/A][498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google on 2026-04-02

[N/A][498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-04-02

[N/A][499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google on 2026-04-02

[N/A][499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google on 2026-04-03

[N/A][500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google on 2026-04-07

[N/A][500172224] Medium CVE-2026-17745: Out of bounds read in Skia. Reported by Google on 2026-04-07

[N/A][500390256] Medium CVE-2026-17746: Use after free in GPU. Reported by Google on 2026-04-07

[N/A][500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-07

[N/A][500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google on 2026-04-08

[N/A][500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-08

[N/A][500560234] Medium CVE-2026-17750: Use after free in ANGLE. Reported by Google on 2026-04-08

[N/A][501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google on 2026-04-11

[N/A][501619207] Medium CVE-2026-17752: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google on 2026-04-11

[N/A][501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google on 2026-04-11

[N/A][501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google on 2026-04-12

[N/A][501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google on 2026-04-13

[N/A][502351526] Medium CVE-2026-17757: Uninitialized Use in Skia. Reported by Google on 2026-04-14

[N/A][504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google on 2026-04-20

[N/A][506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google on 2026-04-25

[N/A][508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google on 2026-05-10

[N/A][511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google on 2026-05-10

[N/A][511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google on 2026-05-10

[N/A][511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google on 2026-05-10

[N/A][511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10

[N/A][512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google on 2026-05-13

[N/A][513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513103345] Medium CVE-2026-17770: Out of bounds read in Media. Reported by Google on 2026-05-14

[N/A][513160525] Medium CVE-2026-17771: Uninitialized Use in Skia. Reported by Google on 2026-05-14

[N/A][513197846] Medium CVE-2026-17772: Out of bounds read in WebGL. Reported by Google on 2026-05-14

[N/A][513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google on 2026-05-14

[N/A][513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google on 2026-05-15

[N/A][513404032] Medium CVE-2026-17776: Policy bypass in Receiver. Reported by Google on 2026-05-15

[N/A][513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google on 2026-05-15

[N/A][513467993] Medium CVE-2026-17778: Use after free in Extensions. Reported by Google on 2026-05-15

[N/A][513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google on 2026-05-15

[N/A][513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-05-15

[N/A][513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google on 2026-05-15

[N/A][513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-15

[N/A][513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google on 2026-05-15

[N/A][513694032] Medium CVE-2026-17784: Use after free in Audio. Reported by Google on 2026-05-16

[N/A][513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google on 2026-05-16

[N/A][513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google on 2026-05-16

[N/A][513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-16

[N/A][513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-17

[N/A][514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17

[N/A][514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google on 2026-05-17

[N/A][514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-05-17

[TBD][514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau on 2026-05-18

[N/A][514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google on 2026-05-18

[N/A][514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google on 2026-05-19

[N/A][514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google on 2026-05-19

[N/A][514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google on 2026-05-19

[N/A][514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google on 2026-05-19

[N/A][514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google on 2026-05-19

[N/A][515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google on 2026-05-21

[N/A][515448947] Medium CVE-2026-17804: Use after free in Media. Reported by Google on 2026-05-21

[N/A][516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google on 2026-05-25

[N/A][516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-25

[N/A][516763884] Medium CVE-2026-17807: Use after free in V8. Reported by Google on 2026-05-26

[N/A][516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google on 2026-05-26

[N/A][516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-26

[N/A][516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google on 2026-05-26

[N/A][516954622] Medium CVE-2026-17811: Use after free in ANGLE. Reported by Google on 2026-05-27

[N/A][517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google on 2026-05-27

[N/A][517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-05-27

[N/A][517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google on 2026-05-28

[N/A][517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google on 2026-05-28

[N/A][517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google on 2026-05-28

[N/A][517466133] Medium CVE-2026-17818: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google on 2026-05-28

[N/A][517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-28

[N/A][517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google on 2026-05-28

[N/A][517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google on 2026-05-29

[N/A][517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-29

[N/A][517723319] Medium CVE-2026-17832: Use after free in ANGLE. Reported by Google on 2026-05-29

[N/A][517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[TBD][517972812] Medium CVE-2026-17836: Use after free in V8. Reported by yupyon.itome on 2026-05-30

[N/A][517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-29

[N/A][518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google on 2026-05-30

[N/A][518088219] Medium CVE-2026-17841: Race in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-30

[N/A][518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518121320] Medium CVE-2026-17846: Inappropriate implementation in Media. Reported by Google on 2026-05-30

[N/A][518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-30

[TBD][518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K on 2026-05-31

[N/A][518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-01

[TBD][519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-06-02

[N/A][519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google on 2026-06-02

[N/A][519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google on 2026-06-03

[TBD][519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-06-03

[N/A][519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google on 2026-06-03

[N/A][519982572] Medium CVE-2026-17855: Race in DevTools. Reported by Google on 2026-06-04

[N/A][519991751] Medium CVE-2026-17856: Inappropriate implementation in Network. Reported by Google on 2026-06-04

[N/A][520186620] Medium CVE-2026-17857: Inappropriate implementation in Network. Reported by Google on 2026-06-05

[N/A][520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google on 2026-06-05

[N/A][520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google on 2026-06-05

[N/A][520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-06-05

[N/A][520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-05

[N/A][520426287] Medium CVE-2026-17862: Use after free in Tracing. Reported by Google on 2026-06-05

[N/A][520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google on 2026-06-05

[N/A][520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google on 2026-06-05

[N/A][520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google on 2026-06-05

[N/A][520525732] Medium CVE-2026-17866: Type Confusion in Tab. Reported by Google on 2026-06-05

[N/A][520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05

[TBD][520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon on 2026-06-06

[N/A][521759269] Medium CVE-2026-17869: Out of bounds read in WebXR. Reported by Google on 2026-06-09

[N/A][521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-09

[N/A][521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google on 2026-06-09

[N/A][521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google on 2026-06-09

[N/A][522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522299155] Medium CVE-2026-17875: Use after free in PDFium. Reported by Google on 2026-06-10

[N/A][522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google on 2026-06-10

[N/A][522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google on 2026-06-10

[N/A][522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google on 2026-06-11

[N/A][522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google on 2026-06-11

[N/A][523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google on 2026-06-12

[N/A][523477987] Medium CVE-2026-17881: Use after free in WebXR. Reported by Google on 2026-06-13

[N/A][523637452] Medium CVE-2026-17882: Policy bypass in Extensions. Reported by Google on 2026-06-13

[N/A][523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google on 2026-06-13

[N/A][523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google on 2026-06-13

[N/A][523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google on 2026-06-13

[N/A][523715964] Medium CVE-2026-17886: Use after free in Enterprise. Reported by Google on 2026-06-14

[N/A][523717010] Medium CVE-2026-17887: Use after free in TabStrip. Reported by Google on 2026-06-14

[N/A][523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-06-14

[N/A][523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google on 2026-06-14

[N/A][524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-15

[N/A][524639223] Medium CVE-2026-17891: Use after free in ANGLE. Reported by Google on 2026-06-16

[N/A][524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google on 2026-06-17

[N/A][524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-17

[N/A][524825209] Medium CVE-2026-17894: Use after free in Views. Reported by Google on 2026-06-17

[TBD][524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io on 2026-06-17

[N/A][525331547] Medium CVE-2026-17896: Use after free in DevTools. Reported by Google on 2026-06-18

[TBD][527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode on 2026-06-25

[$3000][506193577] Low CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse on 2026-04-24

[$1000][375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine on 2024-10-28

[N/A][496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google on 2026-03-25

[N/A][496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google on 2026-03-25

[N/A][497251066] Low CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google on 2026-03-28

[N/A][497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-03-28

[N/A][497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google on 2026-03-29

[N/A][497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29

[N/A][497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google on 2026-03-30

[N/A][497837927] Low CVE-2026-17907: Side-channel information leakage in Network. Reported by Google on 2026-03-30

[N/A][499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google on 2026-04-02

[N/A][501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google on 2026-04-11

[N/A][501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-11

[N/A][502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google on 2026-04-14

[N/A][504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][506377118] Low CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google on 2026-04-25

[N/A][506390325] Low CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google on 2026-04-25

[TBD][510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino on 2026-05-07

[N/A][511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10

[N/A][513127137] Low CVE-2026-17918: Use after free in Sync. Reported by Google on 2026-05-14

[N/A][513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google on 2026-05-14

[N/A][513413942] Low CVE-2026-17920: Use after free in V8. Reported by Google on 2026-05-15

[N/A][513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-15

[N/A][513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15

[N/A][513612928] Low CVE-2026-17923: Policy bypass in Enterprise. Reported by Google on 2026-05-15

[N/A][513714124] Low CVE-2026-17924: Use after free in DNS. Reported by Google on 2026-05-16

[N/A][513719671] Low CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google on 2026-05-16

[N/A][513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-16

[N/A][513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-16

[N/A][513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-16

[N/A][513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513819157] Low CVE-2026-17932: Use after free in DataTransfer. Reported by Google on 2026-05-16

[N/A][513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google on 2026-05-16

[N/A][513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google on 2026-05-16

[N/A][513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google on 2026-05-17

[N/A][514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google on 2026-05-17

[N/A][514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google on 2026-05-17

[N/A][514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-18

[N/A][514406198] Low CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google on 2026-05-18

[N/A][514424283] Low CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google on 2026-05-18

[N/A][514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-19

[N/A][514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google on 2026-05-19

[N/A][515437522] Low CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google on 2026-05-21

[N/A][515438256] Low CVE-2026-17947: Use after free in WebSockets. Reported by Google on 2026-05-21

[N/A][516849257] Low CVE-2026-17948: Type Confusion in V8. Reported by Google on 2026-05-26

[N/A][517000034] Low CVE-2026-17949: Uninitialized Use in GPU. Reported by Google on 2026-05-27

[N/A][517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-27

[N/A][517316174] Low CVE-2026-17952: Inappropriate implementation in V8. Reported by Google on 2026-05-28

[N/A][517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-28

[N/A][517383492] Low CVE-2026-17954: Policy bypass in MHTML. Reported by Google on 2026-05-28

[N/A][517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-28

[N/A][517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google on 2026-05-28

[N/A][517476342] Low CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google on 2026-05-28

[N/A][517538206] Low CVE-2026-17958: Inappropriate implementation in Views. Reported by Google on 2026-05-28

[N/A][517607890] Low CVE-2026-17959: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517700791] Low CVE-2026-17961: Inappropriate implementation in Session. Reported by Google on 2026-05-29

[N/A][517757268] Low CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google on 2026-05-29

[N/A][517759257] Low CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google on 2026-05-29

[N/A][518025103] Low CVE-2026-17964: Incorrect security UI in UI. Reported by Google on 2026-05-29

[N/A][518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518058990] Low CVE-2026-17966: Inappropriate implementation in Views. Reported by Google on 2026-05-30

[N/A][518243858] Low CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518337516] Low CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google on 2026-05-31

[N/A][518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google on 2026-06-01

[N/A][518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-01

[N/A][518815075] Low CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google on 2026-06-01

[N/A][519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-02

[N/A][519230894] Low CVE-2026-17973: Inappropriate implementation in Views. Reported by Google on 2026-06-02

[N/A][519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google on 2026-06-02

[N/A][519233776] Low CVE-2026-17975: Inappropriate implementation in IME. Reported by Google on 2026-06-02

[N/A][519455164] Low CVE-2026-17976: Policy bypass in Extensions. Reported by Google on 2026-06-03

[N/A][519603552] Low CVE-2026-17977: Policy bypass in CSS. Reported by Google on 2026-06-03

[N/A][519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google on 2026-06-03

[N/A][519664497] Low CVE-2026-17979: Race in V8. Reported by Google on 2026-06-04

[N/A][519710361] Low CVE-2026-17980: Inappropriate implementation in UI. Reported by Google on 2026-06-03

[N/A][519719512] Low CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google on 2026-06-03

[N/A][519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-04

[N/A][519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google on 2026-06-04

[N/A][519978460] Low CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google on 2026-06-04

[N/A][519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-04

[N/A][519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-06-04

[N/A][519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google on 2026-06-04

[N/A][520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-06-04

[N/A][520017306] Low CVE-2026-17989: Type Confusion in V8. Reported by Google on 2026-06-04

[N/A][520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google on 2026-06-04

[N/A][520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google on 2026-06-04

[N/A][520506316] Low CVE-2026-17992: Uninitialized Use in Skia. Reported by Google on 2026-06-05

[N/A][520532191] Low CVE-2026-17993: Race in Updater. Reported by Google on 2026-06-05

[N/A][520663771] Low CVE-2026-17994: Inappropriate implementation in Media. Reported by Google on 2026-06-06

[TBD][520972775] Low CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 on 2026-06-07

[N/A][521473427] Low CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google on 2026-06-08

[N/A][521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521601450] Low CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google on 2026-06-09

[N/A][521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google on 2026-06-09

[N/A][521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google on 2026-06-09

[N/A][521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google on 2026-06-09

[N/A][521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google on 2026-06-09

[N/A][521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-09

[N/A][522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-10

[N/A][522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google on 2026-06-10

[N/A][522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google on 2026-06-10

[N/A][522404101] Low CVE-2026-18007: Inappropriate implementation in Input. Reported by Google on 2026-06-10

[N/A][522412676] Low CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google on 2026-06-10

[N/A][522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-10

[N/A][522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google on 2026-06-10

[N/A][522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-11

[N/A][522938824] Low CVE-2026-18012: Use after free in PDFium. Reported by Google on 2026-06-11

[N/A][523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-12

[N/A][523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-12

[N/A][523698428] Low CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google on 2026-06-13

[N/A][523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-13

[N/A][523731236] Low CVE-2026-18017: Use after free in Dawn. Reported by Google on 2026-06-14

[N/A][524467747] Low CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google on 2026-06-16

[N/A][525691898] Low CVE-2026-18019: Side-channel information leakage in Media. Reported by Google on 2026-06-19

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Krishna Govind

Google Chrome


  •  

NVIDIA Driver 610.88

28 Juli 2026 om 00:00
Release Highlights:
Although GeForce Game Ready Drivers and NVIDIA Studio Drivers can be installed on supported notebook GPUs, the original equipment manufacturer (OEM) provides certified drivers for your specific notebook on their website. NVIDIA recommends that you check with your notebook OEM for recommended software updates for your notebook.

Game Ready for Halo: Campaign Evolved & Gears of War: E-Day Beta
This new Game Ready Driver provides the best gaming experience for the latest new games supporting DLSS and RTX technologies including Halo: Campaign Evolved, Gears of War: E-Day Multiplayer Beta, and Mistfall Hunter.

Fixed Gaming Bugs
  • [Halo: Campaign Evolved]: Resolved game crashes observed on RTX 50 Series GPUs with R610 drivers. [6259837]
  • Path of Exile 2: Fixed intermittent long pauses that could occur after extended gameplay sessions in DX12 mode [5090018]
  • Silent Hill F: Gaming stability improvements [6432954]
  • [Strange Brigade/Zombie Army 4:Dead War]: Game may crash when exiting if NVIDIA App In-Game Overlay is enabled [6392324]
  • Improves frame pacing in certain DX11 games when Smooth Motion is used while G-SYNC is enabled [6300603]

Fixed General Bugs
  • RTX Dynamic Vibrance is incorrectly applied to Wallpaper Engine [6244021]
  • Paint.NET may crash during launch when NVIDIA Surround is enabled [5366537]

Learn more in our Game Ready Driver article here.

Game Ready Driver

  •  

v12.2.0

29 Juli 2026 om 20:43

⚠️ Potential Breaking Changes

Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996)
The minimal app permissions now grant read access to only a subset of directus_settings fields. This applies to new policies, existing policies are untouched.

Replaced the TinyMCE editor powering the WYSIWYG with Tiptap... (#27754)
The WYSIWYG interface now runs on Tiptap instead of TinyMCE

  • tinymceOverrides no longer has any effect. Stored values are kept and a console warning is logged, but the editor ignores them. Use the fontsize/fontfamily toolbar menus and customFormats instead.
  • TinyMCE is no longer bundled with the app, so anything depending on it (custom plugins, skins, content CSS, the global tinymce object) no longer applies.
  • Existing content that contains markup the editor would normalize now locks the field read-only until the warning dialog is confirmed. Editing and autosave are blocked while locked, including raw-value editing.

Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide (#27816)
The DeploymentProjectsService.readByExternalId method now takes the deployment ID as its first argument (i.e. readByExternalId(deploymentId, externalId))

Added support for multi-collection flat data imports (#27984)
Import file size is now capped by default
A new IMPORT_MAX_FILE_SIZE environment variable (default: 50mb) limits the size of uploaded import files and schema snapshots. Previously, imports were effectively unrestricted, allowing files larger than 50mb to be processed. With this change, imports exceeding the configured limit will be rejected. Increase IMPORT_MAX_FILE_SIZE to restore the previous behavior.

Updated background query flag handling for POST /utils/import/:collection
The background query flag now treats a valueless indicator (i.e. ?background) as true. If you previously relied on a valueless background flag being interpreted as false, pass an explicit value instead (i.e. ?background=false).

Added a mode parameter and partial snapshot support to the schema diff endpoint (#27984)
The SDK schemaDiff command now takes its options as an object (schemaDiff(snapshot, { force, mode }))

Added support for restricting image transformation output size via ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995)
Image transformation output is now restricted
Image transformations that project an output larger than ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (default 3000 px) on either axis are now rejected with an IllegalAssetTransformationError.

  • @directus/app
    • Replaced the TinyMCE editor powering the WYSIWYG with Tiptap (#27754 by @alvarosabu)

      To avoid data loss, the editor preserves attributes (class, id, title, role, lang, dir, data-*, aria-*) and non-schema semantic tags. If stored HTML still contains markup the editor would normalize, the field is locked read-only with a warning dialog, so no edit or autosave can rewrite it before you confirm; raw-value editing is disabled while locked so the warning can't be bypassed.

  • @directus/api
    • Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
    • Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide (#27816 by @MahinAnowar)
    • Added support for multi-collection flat data imports (#27984 by @ComfortablyCoding)
    • Added support for restricting image transformation output size via ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995 by @br41nslug)
  • @directus/sdk

✨ New Features & Improvements

  • @directus/app
    • Added JSON path filtering to Studio filters. (#27918 by @robluton)
    • Added search to the collection selection in relationship configuration (#27950 by @baguse)
    • Added global setting for default save action (#27993 by @robluton)
    • Added LICENSE_KEY_MANAGEMENT_ENABLED to control license key management (#27779 by @AlexGaillard)
  • @directus/api
  • @directus/composables
  • @directus/system-data
  • @directus/types
  • @directus/env
    • Added LICENSE_KEY_MANAGEMENT_ENABLED to control license key management (#27779 by @AlexGaillard)
    • Added support for multi-collection flat data imports (#27984 by @ComfortablyCoding)
    • Added support for restricting image transformation output size via ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995 by @br41nslug)
  • @directus/sdk
  • @directus/specs
  • @directus/errors

🐛 Bug Fixes & Optimizations

  • @directus/app
    • Fixed the translations split view hiding the second language when resizing the window (#27681 by @valerkahere)
    • Fixed geometry fields losing their subtype on schema changes (#27828 by @rajkumar0932)
    • Fixed stale dynamic permission presets after editing current account (#27899 by @scarab-systems)
    • Fixed a type error in the module bar default configuration (#27944 by @kheiner)
    • Amended app's save-as-copy logic to not create new items when only adjusting order on relationals (#27871 by @AlexGaillard)
    • Fixed the auth module registering a permanent cookie polling interval (#27851 by @dstockton)
    • Fixed presentation fields allowing required and/or readonly to be set (#27688 by @sourav-18)
    • Fixed missing translations for the Datetime display timezone options (#28000 by @lazerg)
    • Fixed dropdown menus shifting position when flipped above their trigger. (#27958 by @Harshith-muddasani)
    • Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
    • Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement (#27934 by @JamesW1)
    • Fixed live preview requesting a draft version before it exists, which caused a forbidden error (#27848 by @dstockton)
    • Fixed issue causing singleton primary key mismatch (#27919 by @robluton)
    • Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
    • Fixed many-to-one fields to display the saved key when the referenced item is inaccessible due to permissions (#27899 by @scarab-systems)
    • Fixed a Forbidden error when publishing an itemless content version without delete permission on directus_versions (#27892 by @alex-hsieh)
  • @directus/api
    • Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)

    • Added global setting for default save action (#27993 by @robluton)

    • Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)

    • Restricted license key previews to administrators after initial project setup (#27886 by @ComfortablyCoding)

    • Stopped logging the missing custom IP header warning on /server/ping and /server/info, which are commonly hit directly (health checks) (#27903 by @dstockton)

    • Updated axios, sharp, liquidjs, js-yaml, minimatch, adm-zip, brace-expansion, linkify-it, fast-xml-parser and tar to address CVEs (#27990 by @br41nslug)

    • Fixed parsing of the deep query parameter, GraphQL nested arguments, and CSV import headers so keys dont collide with built-in object property names (#27992 by @br41nslug)

    • Fixed schema apply ignoring configured license (#27869 by @ComfortablyCoding)

    • Fixed aliased relational fields returning null in GraphQL when nested inside a Many-to-Any field (#27864 by @apoorva-01)

    • Fixed IP denylist not enforced for AI chat file downloads (#27994 by @br41nslug)

    • Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)

      Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.

    • Fixed requests referencing duplicate primary keys resulting in forbidden error (#27882 by @lazerg)

    • Fixed manual flows triggerable by non authenticated users (#27997 by @br41nslug)

    • Fixed count, countAll, and PK counts being inflated when filtering across relations (#27926 by @ComfortablyCoding)

    • Fixed TUS uploads not respecting FILES_MIME_TYPE_ALLOW_LIST (#27793 by @amitmishra11)

    • Fixed WebSocket handlers not validating query parameters (#27845 by @tsushanth)

    • Fixed unnecessary schema cache rebuilds on permission-related changes (#27876 by @dstockton)

  • @directus/sdk
    • Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
    • Fixed nested filters on relational fields losing type inference, so filtering a related collection's field (e.g. filter: { o2m: { id: { _eq: 5 } } }) is now type-checked instead of silently accepting any value (#27815 by @MahinAnowar)
    • Removed phantom timestamp from directus_operations (#27942 by @kheiner)
    • Fixed an unhandled rejection in the sdk realtime client when the connection closed during a heartbeat ping (#27846 by @apoorva-01)
  • @directus/specs
    • Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)

    • Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)

    • Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)

      Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.

    • Added missing /users registration and 2FA endpoint openapi specs (#27857 by @kheiner)

    • Removed OpenAPI query parameters that the underlying controllers never honor (#27922 by @kheiner)

    • Added missing id path parameter to the /comments/{id} OpenAPI spec (#27884 by @kheiner)

  • @directus/constants
    • Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement (#27934 by @JamesW1)
  • @directus/system-data
    • Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996 by @br41nslug)
  • @directus/env
    • Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)

      Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.

  • @directus/utils
    • Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)

      Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.

  • @directus/schema
    • Fixed MSSQL schema introspection reporting the byte size as max_length for non-character types (#27825 by @BIGSUS24)
  • @directus/storage-driver-cloudinary
    • Fixed Cloudinary uploads failing when the configured root contains whitespace (#27841 by @itsabhay1)

📦 Published Versions

  • @directus/app@17.0.0
  • @directus/api@38.0.0
  • @directus/composables@11.6.0
  • @directus/constants@14.4.1
  • create-directus-extension@12.1.2
  • @directus/env@6.2.0
  • @directus/errors@2.5.0
  • @directus/extensions@4.0.2
  • @directus/extensions-registry@4.0.2
  • @directus/extensions-sdk@18.0.2
  • @directus/memory@4.0.2
  • @directus/pressure@4.0.2
  • @directus/schema@14.0.1
  • @directus/schema-builder@1.0.1
  • @directus/specs@15.1.0
  • @directus/storage-driver-azure@13.0.2
  • @directus/storage-driver-cloudinary@13.0.2
  • @directus/storage-driver-gcs@13.0.2
  • @directus/storage-driver-s3@13.0.2
  • @directus/storage-driver-supabase@4.0.2
  • @directus/system-data@4.6.0
  • @directus/themes@2.0.2
  • @directus/types@16.1.0
  • @directus/utils@13.5.2
  • @directus/validation@3.0.2
  • @directus/sdk@24.0.0

  •  

Distribution Release: MakuluLinux 2026-07-28

29 Juli 2026 om 20:29
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Jacque Montague Raymer has announced the availability of a major new release of MakuluLinux, a Debian-based desktop Linux distribution with deeply integrated artificial intelligence features: "Every other Linux distro gives you an AI plugin. A chatbox. A sidebar widget. Something you open, use once, and close. AI-OS is....
  •  

Soul of Anatolia: New Assets to Build the World With

Door: Petr
29 Juli 2026 om 17:00

Today, we'd like to give you a glimpse of our work on the Soul of Anatolia DLC for Euro Truck Simulator 2 by showcasing some of the new assets we've been creating to make this map expansion unique!

Because the DLC is still very much a work in progress, it's not quite the right time to start previewing specific locations, as our map designers are still bringing them to life. Instead, we'd like to share a selection of the 3D models that our assets team has been hard at work creating, displayed in a placeholder setting for now.

Keep in mind that the assets we're showcasing today are just a glimpse of what's still to come. The assets team continues making new models throughout the entire development process, so what you're seeing here represents only a fraction of what will eventually make its way into the final product.

Based on our research team and close collaboration between our map and assets teams, these models are created to reflect the architecture and character of the region. In this map expansion, you will encounter plenty of different cities, each with its own unique architecture, so we need to capture a wide spectrum of buildings, from the big and small, modern and older city buildings to rural houses you would see when visiting the western part of Türkiye in real life.

Over time, they are being integrated into the map by the team working on this DLC, helping shape its towns, cities, and other locations across the map expansion. In total, we plan to create around 300 new generic assets, similar to the ones you see here, as well as our usual landmark assets, which are created for more significant buildings to make them instantly recognizable. You can look forward to seeing these in future blog posts.

If you are excited to be cruising in this map expansion, don't forget to support us by adding the Soul of Anatolia DLC to your Steam wishlist.

Also, remember to give our X/Twitter, Instagram, Facebook, Bluesky, and TikTok a follow, as you'll receive updates from our games straight to your feed. Or subscribe to our newsletter to stay informed. Until next time, we wish you safe travels!

  •  

v5.51.1

29 Juli 2026 om 12:15

5.51.1 (2026-07-29)

🔥 Bug fix

  • respect field length constraints in AI localizations and isolate… (#26880)
  • wording and merging sort options (844c8d625d)
  • preserve sorting on view change (6ed616ab9a)
  • admin: scope audit logs user filter to log authors (#27047)
  • content-manager: homepage recent-documents dates serialize as empty objects (#27066)
  • core: enforce required media and relations via api.documents.strictRelations (#27028)
  • database: return [] for empty morphMany on read (#27090)
  • strapi: prevent duplicate public assets in Vite builds (#27089)

⚙️ Chore

  • admin: allow RFC 6265 control-char regex under develop eslint rules (e8338bb6ba)
  • ci: remove admin bundle-size workflow (#27070)
  • deps: bump brace-expansion from 1.1.14 to 1.1.16 (#27071)
  • deps: bump shell-quote from 1.8.4 to 1.10.0 (#27072)
  • deps: bump body-parser from 1.20.4 to 1.20.6 (#27094)
  • deps: bump dompurify from 3.4.11 to 3.4.12 (#27095)
  • deps: bump fast-uri from 3.1.2 to 3.1.4 (#27098)
  • deps: bump use-context-selector from 1.4.1 to 1.4.4 (#27061)
  • deps: bump cropperjs from 1.6.1 to 1.6.2 (#27060)
  • deps: upgrade handlebars, axios, tar, and related transitive deps (#27091)
  • deps: bump @radix-ui/react-toolbar from 1.0.4 to 1.1.11 (#27059)
  • email-nodemailer: migrate unit tests from jest to vitest (#27074)
  • email-sendmail: migrate unit tests from jest to vitest (#27075)
  • upload-local: migrate unit tests from jest to vitest (#27073)

❤️ Thank You

  •  

BookStack v26.05.3

29 Juli 2026 om 12:02

Security Release

This is a security release to address a range of vulnerabilities:

  • External Authentication Use (OIDC/SAML2/LDAP) could potentially mismatch external authentication system users to BookStack users upon login, where unique IDs are very similar (same ID text but different casing, or accented characters).
  • The login form could be abused to use timing to gain information about if a user exists in the system. This was already limited by request rate-limits, but could still have assisted targeted scenarios.
  • Certain editor content could be used to load interactive content over file links when exported, which could then pose a risk after being exported in Windows environments which use NTLM.
  • API errors could include debug details by default, and therefore potentially expose some system details like file paths.
  • With our default PDF rendering option, certain content could be used to access/check for files on the BookStack host beyond the scope of what we'd expect.

Upgrading is generally advised, but more so for instances using OIDC, SAML2 or LDAP authentication.

Thanks to Tanner Marks (GitHub), Gurmandeep Deol (LinkedIn) and whale120 (Blog, X, Working with DEVCORE Internship Program) for responsibly reporting issues addressed in this release.

Full List of Changes

  • Updated PHP package versions.
  • Updated translations with the latest Crowdin changes.
  • Updated login with fake hash and random delay on failed login.
  • Updated allow list content filter to force the use of schemes.
  • Updated allow list content filter with smarter srcset attribute parsing.
  • Updated user external authentication ID queries, and database column collation, to ensure an exact match.
  • Updated API exception handler to follow a more controlled error message approach.
  • Fixed image delete API endpoint to avoid an error scenario.

  •  
❌