What's Changed
Important: Security Fix
Fixed GHSA-r8vq-5875-cq97: Privileged access to read $all enables arbitrary file read and GET-only SSRF
Fixed
- [DB-2085] Fix three JintProjectionStateHandler correctness bugs by @alexeyzimarev in #5610
- [v26.1] Fixed secondary-index related stats in the UI by @timothycoleman in #5651
- [release/v26.1] [DB-2153] Fix projections v2 processing link to scavenged event by @github-actions[bot] in #5657
- [release/v26.1] [DB-2154] Reject property values with no type set at the API boundary by @github-actions[bot] in #5659
- [DB-2156] Populate position fields for unresolved link-to events in HTTP API by @timothycoleman in #5660
Changed
- [DEV-1700] Update Surge and Connectors packages by @w1am in #5620
- [release/v26.1] [DEV-1719] Upgrade surge for CVE-2026-44788 by @github-actions[bot] in #5629
- [v26.1][DB-2144] Workaround GHSA-2m69-gcr7-jv3q (#5646) by @timothycoleman in #5649
- [DB-2158] Add TruncateParked API for persistent subscriptions by @timothycoleman in #5665
- [release/v26.1] [DB-2160] Make gRPC response compression level configurable by @github-actions[bot] in #5670
Full Changelog: v26.1.0...v26.1.1