Skip to content
Oday Bakkour
Back to Knowledge Hub

Dev Release Radar — September 27, 2026: PostgreSQL Patches Five CVEs, RabbitMQ Fixes a JWKS DoS Flaw

Oday Bakkour profile photo
Oday Bakkour
7 min read
Share
Dev Release Radar — September 27, 2026: PostgreSQL Patches Five CVEs, RabbitMQ Fixes a JWKS DoS Flaw

This week's audit turned up an unusually dense cluster of security releases across the data layer — PostgreSQL, Redis, RabbitMQ, and Kubernetes all shipped fixes for high-severity bugs within a few days of each other, alongside routine but notable feature releases across the frontend and backend ecosystem.

Executive Summary

  • PostgreSQL shipped a coordinated security release (18.6/17.11/16.15/15.19/14.24) fixing five CVEs, three of them CVSS 8.8 and capable of arbitrary code execution via pg_dump, psql \unrestrict, or cursor CLOSE/DECLARE sequences.
  • RabbitMQ patched CVE-2026-67409 (CVSS 8.2), a flaw in its OAuth2/JWKS key-fetch logic that lets a malicious or misbehaving key server wipe all cached signing keys and knock out every OAuth2-authenticated client.
  • Kubernetes fixed CVE-2026-2270, a confused-deputy bug in kube-controller-manager that let a namespace-scoped user with StatefulSet/ControllerRevision write access trigger pod creation in a different namespace.
  • Next.js 16.3.6 / 15.5.26 closed a remote code execution hole in next/og's ImageResponse (GHSA-vcvr-r3jv-pc5j).
  • Keycloak 26.7.4 closed six CVEs including a realm-admin impersonation bug, but two new unpatched bypasses (step-up/ACR cookie bypass, delegated-admin password reset bypass) were disclosed days later.
  • Redis, NestJS, Docker Desktop, and MongoDB all shipped security fixes in the same window — see the breakdown below for upgrade guidance.
  • On the feature side: Supabase CLI added a one-command pull for full local environment setup (with a breaking change to the logs API), Motion shipped a new AnimateView component built on React 19.3 view transitions, and Astro, Vue, Hono, and Laravel all pushed incremental releases.

Security-Critical Patches to Apply Now

PostgreSQL: five CVEs, three of them CVSS 8.8

The PostgreSQL Global Development Group's September security release covers 18.6, 17.11, 16.15, 15.19, and 14.24. The headline issues:

  • CVE-2026-19385 — heap buffer overflow in pg_dump, exploitable for arbitrary code execution (CVSS 8.8).
  • CVE-2026-18408 — psql's \unrestrict meta-command lets a hostile server get a superuser's psql client to execute arbitrary code (CVSS 8.8).
  • CVE-2026-16239 — type confusion when a cursor is closed and redeclared, again reaching arbitrary code execution (CVSS 8.8).
  • CVE-2026-18024 — out-of-bounds read in ascii().
  • CVE-2026-16241 — integer underflow crash in ECPG.

Because three of the five are client-side and RCE-class, this is a "patch the tooling, not just the server" release — anyone running pg_dump/psql against untrusted or compromised servers should update immediately.

bash.txt
# Debian/Ubuntu
sudo apt-get update && sudo apt-get install postgresql-client-16 postgresql-16

# Confirm the patched minor version
psql --version

Full details: PostgreSQL Security Information

RabbitMQ: OAuth2 JWKS key-fetch DoS (CVE-2026-67409)

The uaajwt.erl module that fetches OAuth2/JWKS signing keys doesn't validate the HTTP status code of the response. A JWKS endpoint returning a 4xx/5xx with valid-looking JSON but no "keys" field silently wipes RabbitMQ's cached signing keys, locking out every OAuth2/JWT-authenticated client (CVSS 8.2). It affects 3.13.0 through 4.3.2/4.2.8/4.1.13/4.0.22, fixed in 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18.

Several lower-severity advisories landed in the same window: STOMP consumers retaining OAuth queue access after JWT expiry, an MQTT retained-message store with no size cap, and two low-severity vhost/stream disclosure issues.

Details: RabbitMQ Security Advisories

Kubernetes: cross-namespace pod creation (CVE-2026-2270)

A confused-deputy flaw in kube-controller-manager: a user with write access to StatefulSets and ControllerRevisions in *their own* namespace could manipulate the controller into creating pods in a namespace they don't have access to. Fixed in 1.34.12, 1.35.9, 1.36.5, and 1.37.1.

bash.txt
kubectl version --short
# upgrade if control-plane version is below 1.34.12 / 1.35.9 / 1.36.5 / 1.37.1

Coverage: Kubernetes cross-namespace pod CVE-2026-2270

Next.js: RCE via next/og ImageResponse

Next.js 16.3.6 and 15.5.26 patch GHSA-vcvr-r3jv-pc5j, a remote code execution vulnerability in the next/og ImageResponse API used for dynamic Open Graph image generation. Any app generating OG images from user-influenced input should upgrade immediately:

bash.txt
npm i [email protected]   # or [email protected] on the 15.x line

Release notes: next.js.org releases v16.3.6

Keycloak: six CVEs closed, two new bypasses still open

Keycloak 26.7.4 fixed six CVEs, the most serious being CVE-2026-17526 (a user with the impersonation role could impersonate a realm admin) and CVE-2026-79651 (unauthenticated DoS via unbounded locale caching). Release notes: keycloak.org — 26.7.4 released.

Separately, Red Hat disclosed two additional issues days later with no fixed release yet: CVE-2026-97176 (a step-up/ACR bypass via the Cookie authenticator) and CVE-2026-97177 (a delegated-admin password-reset bypass). If your realm relies on step-up authentication or delegated admin roles, track this advisory writeup for the fix.

Also patched: Redis, NestJS, Docker Desktop, MongoDB

  • Redis 8.10.2 (plus 8.8.3/8.6.7/8.4.7/8.2.10) fixed six issues, several of them use-after-free/invalid-memory bugs in RESTORE, the CMSketch module, and Lua scripting with potential for RCE. Redis releases
  • NestJS 12.1.0 and 11.2.6 bumped multer to patch CVE-2026-88932 in @nestjs/platform-express, and fixed bad upload field names returning 500 instead of 400. Release v11.2.6
  • Docker Desktop 4.92.0 bumped containerd to v2.3.5, closing CVE-2026-53495, alongside fixes for unreachable published ports and Kubernetes cluster init failures. Docker Desktop release notes
  • MongoDB Server 8.0.x: CVE-2026-82067 (CVSS 8.1) — a case-sensitivity handling bug in configuration validation could leave the authorization subsystem disabled at startup, letting an unauthenticated network attacker run arbitrary admin operations. Advisory AV26-945

Also Shipping This Week

  • Supabase CLI 2.118.0 adds a single supabase pull command for full local project setup, experimental stack-management commands, and Docker-free type generation. Separately, the Management API's logs.all endpoint was removed in favor of a ClickHouse-backed endpoint — a breaking change for anyone scripting log queries. Supabase CLI releases · Supabase changelog
  • ClickHouse pushed a fresh round of stable/LTS patch releases (26.9.3.38-stable, 26.8.12.53-lts, 26.7.15.52-stable, 26.3.34.136-lts, 26.9.2.8-stable) — routine fixes, no CVEs called out. ClickHouse releases
  • Motion (Framer Motion) kept up a rapid patch cadence (v13.4.1–v13.4.3) fixing Suspense replay, drag-constraint scaling, and SVG CSS variable bugs, on top of v13.4.0's new AnimateView component built on React 19.3's ViewTransition API. Motion changelog
  • Vue.js 3.5.43 landed ~13 bug fixes (compiler CSS-var parsing, hydration, suspense, reactivity), with 3.6.0-rc.9 continuing in parallel. Vue core changelog
  • Svelte 5.57.1 and SvelteKit 3.0.0-next.29 continue toward a SvelteKit 3 release candidate, with breaking changes to form-action navigation and adapter plugin ordering. Svelte September update
  • Astro 7.3.5 adds a renderComponent() container function for rendering Astro components with inlined styles/scripts via the experimental Container API. Astro releases
  • Hono 4.13.9 patches the 4.13 line that added first-class HTTP QUERY method support and roughly 1.25x faster request handling; ElysiaJS 2.0.0-beta.19 continues beta development ahead of general availability. Hono releases
  • Laravel laravel/framework 13.33.0 shipped worker/job-timeout handling changes, an auth session password-hash timing fix, and tagged-cache/Postgres/Valkey improvements. Laravel v13.33.0
  • Vercel platform changes: direct pushes to Vercel Container Registry from GitHub Actions via OIDC, memory-usage observability for Vercel Sandbox, unlimited Blob stores (now billed per-operation), and Sandbox Drives entering public beta with up to 16 TiB of persistent storage. Vercel changelog
  • Railway now supports building on a free VM without an account, plus cross-service request tracing. Railway changelog
  • shadcn/ui moved the shared cn utility into its own dedicated package instead of a project-local lib/utils helper — run shadcn migrate cn to update. shadcn/ui changelog

On the Radar

  • Auth0: three CVEs (unauthenticated localhost admin panel, stored XSS, local privilege escalation) were disclosed in the AD/LDAP Connector; check for the connector update if you use LDAP federation. Auth0 community security digest
  • DuckDB 2.0 "Cyanoptera" alpha preview is out, with a new PEG-based SQL parser and revised C extension API; general availability is targeted for the second half of October 2026. Try DuckDB 2.0 alpha
  • Prisma ORM 8 is in release candidate (8.0.0-rc.15), with a new @prisma/prisma7 compatibility package for running Prisma 7 and 8 side by side ahead of an expected October GA. Prisma changelog

What This Means for Your Team

The data layer had the roughest week: PostgreSQL, Redis, RabbitMQ, MongoDB, and Kubernetes all shipped security fixes within days of each other, and three of the PostgreSQL bugs plus two of the Redis bugs are RCE-class. If your stack touches any of those five, prioritize patching in this order:

  1. PostgreSQL client tooling (psql, pg_dump) wherever it touches untrusted or third-party servers.
  2. Redis if you run RESTORE, Lua scripting, or the TimeSeries/probabilistic modules against untrusted input.
  3. RabbitMQ if OAuth2/JWT authentication is enabled — a flaky JWKS endpoint can now cause a full authentication outage.
  4. Kubernetes control plane if multiple teams share a cluster with namespace-scoped RBAC.
  5. Next.js if next/og generates images from any user-influenced input.

Keycloak users should also watch for a fix to the newly disclosed ACR/cookie bypass — it currently has no patched release.

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED
PostgreSQL and RabbitMQ Ship Critical Security Patches | Oday Bakkour