Released at 2026-09-29
Update note: the /internal/force_merge, /internal/force_flush, /internal/log_new_streams and /internal/partition/* HTTP endpoints now require the POST method. Update any scripts or automation calling these endpoints via GET to use POST.
-
SECURITY: Single-node VictoriaTraces and vtselect in VictoriaTraces cluster: restrict the
/delete/run_taskendpoint to thePOSTmethod only in order to prevent some SSRF-based log deletion attacks. See this issue #225. Thank @Vandit1604 for the pull request #236. -
SECURITY: require the
POSTmethod for the/internal/force_merge,/internal/force_flush,/internal/log_new_streamsand/internal/partition/*HTTP endpoints in order to prevent GET-based SSRF attacks. See this issue #225. Thank @Vandit1604 for the pull request #236. -
FEATURE: Single-node VictoriaTraces and vtselect in VictoriaTraces cluster: provide built-in trace explore UI (VTUI). The existing log-based UI (VLUI) is replaced. Raw spans/logs can be queried via the LogSQL APIs. Thank @AndrewChubatiuk for the pull request #248.
-
FEATURE: Single-node VictoriaTraces and vtselect in VictoriaTraces cluster: apply the latency offset (
-search.latencyOffset, default30s) to most of the LogsQL APIs except the live-tailing API. Previously, only the Jaeger and Tempo APIs had this latency offset. The latency offset for LogsQL APIs can be disabled via thedisable_latency_offset=truequery argument. -
BUGFIX: Single-node VictoriaTraces and vtselect in VictoriaTraces cluster: return
startTimeUnixNanoas a JSON string in the Tempo/api/searchresponse. Previously it was a JSON number, which broke clients that decode the field as a string. Thank @clain23 for the pull request #256. -
BUGFIX: vtselect in VictoriaTraces cluster: apply
-search.allowPartialResponsefor Tempo and Jaeger query APIs. Previously the flag affected only LogsQL query handlers, so Tempo and Jaeger requests still failed when a queriedvtstoragenode was unavailable. See this issue #157.