Portainer
Open-source container management platform for Docker, Kubernetes, and edge environments
Portainer replaces kube-apiserver proxy calls with native K8s APIs while closing a Docker authorization bypass that let non-admins reach the daemon directly.
◆Recent moves
- 11d ago
Portainer 2.45.1: SSRF transport hardened across all outbound operations
This patch extends the SSRF-aware transport introduced in 2.45.0 to cover Helm chart resolution and Git HTTP/HTTPS operations, and tightens enforcement so an aliased import can no longer slip past the check. Multiple critical CVEs in the kubectl shell image are cleared, including two rated Critical (CVE-2026-63073 and CVE-2026-75803), plus nine High and eleven Medium findings.
View source ↗ - 11d ago
Portainer 2.39.8: Go toolchain CVE maintenance backport
A dependency-only maintenance release for the 2.39 LTS stream: Go toolchain bumped from 1.25.12 to 1.25.14, clearing the same CVE batch addressed in 2.45.1. One functional fix: the updater no longer marks a container healthy before its health-check command has completed, preventing a failed upgrade from silently skipping rollback.
View source ↗ - 1mo ago
Portainer 2.45.0: native K8s API surface debuts, Docker proxy auth bypass closed
⚡ SPARKThe headline architectural move is replacing direct kube-apiserver proxy calls with native Portainer-owned APIs for secrets, configmaps, deployments, and PVCs. A critical Docker proxy authorization bypass — malformed version prefixes in the URL path skipped access control entirely — and a Kubernetes shell flaw where caller-supplied query params could override pod targets were both closed in the same release.
View source ↗ - 1mo ago
Portainer 2.39.7: Critical Docker proxy auth bypass backported to LTS
A targeted security backport of the Docker proxy authorization bypass fix and broadened bind-mount restrictions from 2.45.0 into the 2.39 LTS stream, for operators unwilling to move to the 2.45 line. Two distinct authorization control gaps are addressed with no other changes — a narrowly scoped patch.
View source ↗ - 1mo ago
Portainer 2.39.6: SSRF protection added to LTS, Swarm path traversal fixed
The 2.39.6 LTS patch backports the configurable SSRF allow-list (off/audit/enforce modes) from the STS track — a real feature arriving on the stable line, not just a bug fix. A path traversal in the Swarm compose deployer where config/secret file paths could escape the project root is also closed, along with multiple CVE dependency bumps.
View source ↗ - 2mo ago
Portainer 2.44.0: Workflow details screen, GPU visibility, BuildKit upgrade
STS 2.44.0 adds a workflow details screen and persistent source/workflow/artifact state tracking, making the GitOps pipeline inspectable for the first time. GPU visibility in Environment Details and a BuildKit upgrade to v0.31.2 (with SLSA v1.0 attestations replacing v0.2) round out the feature work. A wide range of bug fixes address stack deployment failures, dark mode issues, and RBAC edge cases.
View source ↗