Dev Release Radar — September 27, 2026: PostgreSQL Patches Five CVEs, RabbitMQ Fixes a JWKS DoS Flaw

This week's audit turned up an unusually dense cluster of security releases across the data layer — PostgreSQL, Redis, RabbitMQ, and Kubernetes all shipped fixes for high-severity bugs within a few days of each other, alongside routine but notable feature releases across the frontend and backend ecosystem.
Executive Summary
- PostgreSQL shipped a coordinated security release (18.6/17.11/16.15/15.19/14.24) fixing five CVEs, three of them CVSS 8.8 and capable of arbitrary code execution via
pg_dump,psql \unrestrict, or cursorCLOSE/DECLAREsequences. - RabbitMQ patched CVE-2026-67409 (CVSS 8.2), a flaw in its OAuth2/JWKS key-fetch logic that lets a malicious or misbehaving key server wipe all cached signing keys and knock out every OAuth2-authenticated client.
- Kubernetes fixed CVE-2026-2270, a confused-deputy bug in
kube-controller-managerthat let a namespace-scoped user with StatefulSet/ControllerRevision write access trigger pod creation in a different namespace. - Next.js 16.3.6 / 15.5.26 closed a remote code execution hole in
next/og'sImageResponse(GHSA-vcvr-r3jv-pc5j). - Keycloak 26.7.4 closed six CVEs including a realm-admin impersonation bug, but two new unpatched bypasses (step-up/ACR cookie bypass, delegated-admin password reset bypass) were disclosed days later.
- Redis, NestJS, Docker Desktop, and MongoDB all shipped security fixes in the same window — see the breakdown below for upgrade guidance.
- On the feature side: Supabase CLI added a one-command
pullfor full local environment setup (with a breaking change to the logs API), Motion shipped a newAnimateViewcomponent built on React 19.3 view transitions, and Astro, Vue, Hono, and Laravel all pushed incremental releases.
Security-Critical Patches to Apply Now
PostgreSQL: five CVEs, three of them CVSS 8.8
The PostgreSQL Global Development Group's September security release covers 18.6, 17.11, 16.15, 15.19, and 14.24. The headline issues:
- CVE-2026-19385 — heap buffer overflow in
pg_dump, exploitable for arbitrary code execution (CVSS 8.8). - CVE-2026-18408 —
psql's\unrestrictmeta-command lets a hostile server get a superuser'spsqlclient to execute arbitrary code (CVSS 8.8). - CVE-2026-16239 — type confusion when a cursor is closed and redeclared, again reaching arbitrary code execution (CVSS 8.8).
- CVE-2026-18024 — out-of-bounds read in
ascii(). - CVE-2026-16241 — integer underflow crash in ECPG.
Because three of the five are client-side and RCE-class, this is a "patch the tooling, not just the server" release — anyone running pg_dump/psql against untrusted or compromised servers should update immediately.
# Debian/Ubuntu
sudo apt-get update && sudo apt-get install postgresql-client-16 postgresql-16
# Confirm the patched minor version
psql --versionFull details: PostgreSQL Security Information
RabbitMQ: OAuth2 JWKS key-fetch DoS (CVE-2026-67409)
The uaajwt.erl module that fetches OAuth2/JWKS signing keys doesn't validate the HTTP status code of the response. A JWKS endpoint returning a 4xx/5xx with valid-looking JSON but no "keys" field silently wipes RabbitMQ's cached signing keys, locking out every OAuth2/JWT-authenticated client (CVSS 8.2). It affects 3.13.0 through 4.3.2/4.2.8/4.1.13/4.0.22, fixed in 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18.
Several lower-severity advisories landed in the same window: STOMP consumers retaining OAuth queue access after JWT expiry, an MQTT retained-message store with no size cap, and two low-severity vhost/stream disclosure issues.
Details: RabbitMQ Security Advisories
Kubernetes: cross-namespace pod creation (CVE-2026-2270)
A confused-deputy flaw in kube-controller-manager: a user with write access to StatefulSets and ControllerRevisions in *their own* namespace could manipulate the controller into creating pods in a namespace they don't have access to. Fixed in 1.34.12, 1.35.9, 1.36.5, and 1.37.1.
kubectl version --short
# upgrade if control-plane version is below 1.34.12 / 1.35.9 / 1.36.5 / 1.37.1Coverage: Kubernetes cross-namespace pod CVE-2026-2270
Next.js: RCE via next/og ImageResponse
Next.js 16.3.6 and 15.5.26 patch GHSA-vcvr-r3jv-pc5j, a remote code execution vulnerability in the next/og ImageResponse API used for dynamic Open Graph image generation. Any app generating OG images from user-influenced input should upgrade immediately:
npm i [email protected] # or [email protected] on the 15.x lineRelease notes: next.js.org releases v16.3.6
Keycloak: six CVEs closed, two new bypasses still open
Keycloak 26.7.4 fixed six CVEs, the most serious being CVE-2026-17526 (a user with the impersonation role could impersonate a realm admin) and CVE-2026-79651 (unauthenticated DoS via unbounded locale caching). Release notes: keycloak.org — 26.7.4 released.
Separately, Red Hat disclosed two additional issues days later with no fixed release yet: CVE-2026-97176 (a step-up/ACR bypass via the Cookie authenticator) and CVE-2026-97177 (a delegated-admin password-reset bypass). If your realm relies on step-up authentication or delegated admin roles, track this advisory writeup for the fix.
Also patched: Redis, NestJS, Docker Desktop, MongoDB
- Redis 8.10.2 (plus 8.8.3/8.6.7/8.4.7/8.2.10) fixed six issues, several of them use-after-free/invalid-memory bugs in
RESTORE, the CMSketch module, and Lua scripting with potential for RCE. Redis releases - NestJS 12.1.0 and 11.2.6 bumped
multerto patch CVE-2026-88932 in@nestjs/platform-express, and fixed bad upload field names returning 500 instead of 400. Release v11.2.6 - Docker Desktop 4.92.0 bumped containerd to v2.3.5, closing CVE-2026-53495, alongside fixes for unreachable published ports and Kubernetes cluster init failures. Docker Desktop release notes
- MongoDB Server 8.0.x: CVE-2026-82067 (CVSS 8.1) — a case-sensitivity handling bug in configuration validation could leave the authorization subsystem disabled at startup, letting an unauthenticated network attacker run arbitrary admin operations. Advisory AV26-945
Also Shipping This Week
- Supabase CLI 2.118.0 adds a single
supabase pullcommand for full local project setup, experimental stack-management commands, and Docker-free type generation. Separately, the Management API'slogs.allendpoint was removed in favor of a ClickHouse-backed endpoint — a breaking change for anyone scripting log queries. Supabase CLI releases · Supabase changelog - ClickHouse pushed a fresh round of stable/LTS patch releases (26.9.3.38-stable, 26.8.12.53-lts, 26.7.15.52-stable, 26.3.34.136-lts, 26.9.2.8-stable) — routine fixes, no CVEs called out. ClickHouse releases
- Motion (Framer Motion) kept up a rapid patch cadence (v13.4.1–v13.4.3) fixing Suspense replay, drag-constraint scaling, and SVG CSS variable bugs, on top of v13.4.0's new
AnimateViewcomponent built on React 19.3'sViewTransitionAPI. Motion changelog - Vue.js 3.5.43 landed ~13 bug fixes (compiler CSS-var parsing, hydration, suspense, reactivity), with 3.6.0-rc.9 continuing in parallel. Vue core changelog
- Svelte 5.57.1 and SvelteKit 3.0.0-next.29 continue toward a SvelteKit 3 release candidate, with breaking changes to form-action navigation and adapter plugin ordering. Svelte September update
- Astro 7.3.5 adds a
renderComponent()container function for rendering Astro components with inlined styles/scripts via the experimental Container API. Astro releases - Hono 4.13.9 patches the 4.13 line that added first-class HTTP
QUERYmethod support and roughly 1.25x faster request handling; ElysiaJS 2.0.0-beta.19 continues beta development ahead of general availability. Hono releases - Laravel
laravel/framework13.33.0 shipped worker/job-timeout handling changes, an auth session password-hash timing fix, and tagged-cache/Postgres/Valkey improvements. Laravel v13.33.0 - Vercel platform changes: direct pushes to Vercel Container Registry from GitHub Actions via OIDC, memory-usage observability for Vercel Sandbox, unlimited Blob stores (now billed per-operation), and Sandbox Drives entering public beta with up to 16 TiB of persistent storage. Vercel changelog
- Railway now supports building on a free VM without an account, plus cross-service request tracing. Railway changelog
- shadcn/ui moved the shared
cnutility into its own dedicated package instead of a project-locallib/utilshelper — runshadcn migrate cnto update. shadcn/ui changelog
On the Radar
- Auth0: three CVEs (unauthenticated localhost admin panel, stored XSS, local privilege escalation) were disclosed in the AD/LDAP Connector; check for the connector update if you use LDAP federation. Auth0 community security digest
- DuckDB 2.0 "Cyanoptera" alpha preview is out, with a new PEG-based SQL parser and revised C extension API; general availability is targeted for the second half of October 2026. Try DuckDB 2.0 alpha
- Prisma ORM 8 is in release candidate (8.0.0-rc.15), with a new
@prisma/prisma7compatibility package for running Prisma 7 and 8 side by side ahead of an expected October GA. Prisma changelog
What This Means for Your Team
The data layer had the roughest week: PostgreSQL, Redis, RabbitMQ, MongoDB, and Kubernetes all shipped security fixes within days of each other, and three of the PostgreSQL bugs plus two of the Redis bugs are RCE-class. If your stack touches any of those five, prioritize patching in this order:
- PostgreSQL client tooling (
psql,pg_dump) wherever it touches untrusted or third-party servers. - Redis if you run
RESTORE, Lua scripting, or the TimeSeries/probabilistic modules against untrusted input. - RabbitMQ if OAuth2/JWT authentication is enabled — a flaky JWKS endpoint can now cause a full authentication outage.
- Kubernetes control plane if multiple teams share a cluster with namespace-scoped RBAC.
- Next.js if
next/oggenerates images from any user-influenced input.
Keycloak users should also watch for a fix to the newly disclosed ACR/cookie bypass — it currently has no patched release.
Comments
Share your thoughts and join the conversation
