Changelog
This is a patch release for v2.45.
Bug fixes and improvements
Server
- IMPORTANT: fix a bug in the mssql backend that could in certain cases allow an authenticated user to observe data they were not authorized for. All MS SQL Server users are encouraged to upgrade. More details to be released.
- event trigger names now undergo stricter validation, and must only contain alphanumeric, underscore and hyphen characters. Formerly this was only a warning on
replace_metadata. Server upgrades over metadata containing non-conforming names should continue to work, but names must be fixed before the nextreplace_metadata. - Improve the performance of
order_by ...asc_nulls_firstand...desc_nulls_lastin the MSSQL backend (contributed by Behzad Fattahi)
Data Connector
- super-connector: upgraded the Quarkus platform (3.33.1.1 -> 3.33.2.1, for
quarkus-vertx-http) to remediate CVE-2026-50559 (HIGH: authorization bypass in HTTP path-based policies via encoded characters) flagged by the container image scan. (Enterprise/cloud only)
Build
- Upgraded frontend/console npm dependencies to remediate HIGH/CRITICAL security advisories (axios, semver, and transitive packages via Yarn resolutions). No user-facing behaviour change.
- cli-migrations-v3: add the
HASURA_GRAPHQL_DISALLOW_INCONSISTENT_METADATAenvironment variable to the enable--disallow-inconsistent-metadatafor themetadata applycommand. - Fixed Postgres SSL connection failures for the self-hosted Ubuntu image when
running on FIPS-enabled hosts. Since v2.49.5 (Ubuntu Noble base), OpenSSL tried
to load a FIPS provider that is not shipped in the container, causing libpq SSL
context initialization to fail (could not create SSL context: could not load the shared library) and fall back to a rejected cleartext connection. The
image now setsOPENSSL_FORCE_FIPS_MODE=0(upstream-documented workaround for
Ubuntu bug LP#2141933) so it boots and negotiates TLS to Postgres on FIPS hosts.
This is a container bootability fix and is not a FIPS certification claim.