v2.4.40 (2026-08-17)
Security in v2.4.40
- GHSA-x69f-q4wj-vx72 - Fixed missing object-level permission enforcement on the legacy
/api/dcim/console-connections/,/api/dcim/power-connections/, and/api/dcim/interface-connections/REST API endpoints. - #9360 - Updated dependency
cryptographyto^50.0.0to mitigate CVE-2026-69247. - #9360 - Updated dependency
GitPythonto~3.1.58to mitigate multiple security vulnerabilities.
Fixed in v2.4.40
- #9282 - Fixed an
AttributeErrorraised when editing an Interface belonging to a Module that has no parent Device while its 802.1Q mode was set to "Tagged". - #9368 - Fixed an
AttributeErrorfrom the legacy/api/dcim/interface-connections/REST API endpoint when an Interface was cabled to a non-Interface endpoint such as a CircuitTermination.
Documentation in v2.4.40
- #9324 - Enhanced the "Permissions" administrator guide with guidance about which permissions should be restricted to highly-trusted users, which permissions are generally safe to grant to all users, etc.
- #9378 - Updated documentation for Secrets and Security to clarify the potential for privilege escalation when granting users permission to create or edit Secrets.
Contributors
Full Changelog: v2.4.39...v2.4.40