Skip to main content

Release v3.9.14

· 6 min read

What Changed

8
New Features
Bug Fixes
Security: Next.js 16.3.8 and sharp 0.35.5 in the Web and Enterprise Frontend imagesBoth the community Web image and the Enterprise Frontend image now build on Next.js 16.3.8 and sharp 0.35.5. This fixes a critical remote-code-execution advisory in next/og ImageResponse (attacker-controlled SVG content), an SSRF in Image Optimization via allow-listed remote URLs, several use cache / ISR cache-poisoning and origin-validation issues, and a heap overflow in the libheif library bundled with sharp.
Security: Python dependency updates in the API imagePicked up the dependency fixes landed on the community lts/1.13.x branch: urllib3 2.7.0 → 2.8.0, pypdf 6.16.1 → 6.19.0, fsspec 2025.10.0 → 2026.6.0, a 9-package group bump (including pyjwt 2.15.1, starlette 1.7.0, sentry-sdk 2.71.0, markdown 3.11 and unstructured), and a 10-package bump of the storage SDKs (boto3, azure-identity, azure-storage-blob, google-cloud-storage, opendal, supabase, tos, cos, bce and OBS).
Security Notes
Security: build tooling removed from the API, sandbox, Web and Enterprise Frontend runtime imagesThe runtime stage of these images now starts from a minimal Wolfi base and installs only what the service needs at runtime. uv, npm / pnpm / corepack / yarn, git and the base image's system pip no longer ship in the API, API-insecure, Web and Enterprise Frontend images, and uv / git no longer ship in the sandbox (which keeps pip and a C toolchain so Python dependencies can still be installed, including from source). The images are also substantially smaller. This removes every finding that came from those tools, including http-cache-semantics (CVE-2026-93748) in the Web and Enterprise Frontend images and the uv-bundled crates in the API and sandbox images. The Web and Enterprise Frontend images now report no known vulnerabilities.
Security: pip SBOM false positives on the plugin images (urllib3, msgpack)CVE-2026-97687 / 97689 (urllib3 2.7.0), CVE-2026-57585 and GHSA-6v7p-g79w-8964 (msgpack 1.1.2) are reported against the plugin daemon (local) and plugin build base images. The scanner reads a stale SBOM (pip/_vendor/bom.cdx.json) shipped in Chainguard's py3.x-pip-26.2.1-r2 package. The vendored code actually shipped is urllib3 2.8.0 and msgpack 1.2.1. Chainguard has since published py3.x-pip-26.2.1-r3 with a corrected SBOM. The sandbox image already uses it, so these findings are gone there, and the plugin images will pick it up in a follow-up release. Until then, these advisories are covered by pip-vendored.openvex.json.
Security: setuptools finding is not exploitableCVE-2025-47273 (path traversal in setuptools 70.3.0) is reported against the sandbox, plugin daemon (local) and plugin build base images, also from the pip SBOM. pip only vendors pkg_resources, so setuptools.package_index, where the issue lives, is not present in the image. This is covered by pip-vendored.openvex.json.
Security: block-buffer bundled in uv on the plugin images is not exploitableThe plugin daemon (local) and plugin build base images still need uv at runtime to install plugin dependencies (Wolfi package uv-0.12.24-r0). The block-buffer 0.10.4 statement (sonatype-2026-003895, GHSA-qwgh-2vcv-g2f7) is kept for these images: uv is built with panic = "abort", so the caught-panic precondition of the advisory cannot occur. This is covered by uv-vendored.openvex.json.
Security: advisories without an upstream fixCVE-2026-81726 (path traversal in nltk ≤ 3.10.3) still has no fixed release upstream and is still reported against the API image. It will be picked up as soon as a fixed release is available.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Review the manifest changes before applying: helm diff upgrade dify dify-ee/dify --version 3.9.14 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.14 -f values.yaml and compare it against helm get manifest dify
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up the database and review the manifest diff first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.14

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 22 High CVE across all container images
ScannerDocker Scout
Scanned
Oct 09, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
TTFE – Time To First Event (ms)
AVG
161.1
MIN
128
MAX
548
P50
148
P90
174
P95
189
Connections
Max Concurrent
18
Avg Active
17.27
Empty Workflow QPS
Max QPS
38
Avg QPS
36.1
Avg Duration (ms)
178.54

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.13.0

· 9 min read

What Changed

28
New Features
Improvements
RBAC: Granular Agent PermissionsThe single workspace-level agent.manage permission is replaced by agent.create and per-Agent permissions for previewing, editing, testing and running, releasing and managing versions, viewing and managing access points, viewing and managing logs, monitoring, configuring access, importing and exporting DSL, and deleting Agents.
Helm: Per-Site Gateway Response HeadersSupports customizing Gateway HTTP response headers per site via Helm while preserving default header behavior.
Bug Fixes
Admin API RBAC Binding SyncFixed an issue where RBAC permission bindings were not updated when adding or removing workspace members via the Admin API.
Knowledge Base Permission Check 403 ErrorsFixed an issue where 403 errors were incorrectly triggered by legacy permission checks even when knowledge base access was granted.
Workspace Owner Transfer Role SyncFixed an issue where the previous owner role processing and enterprise dashboard display became out of sync after transferring workspace ownership.
SSO Outbound Request Proxy ConfigurationFixed an issue where outbound requests initiated by SSO ignored HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables.
Open in Explore for SSO-Restricted AppsThe Open in Explore action is now hidden for apps restricted to authenticated external users. Previously, this action failed with a misleading "App is not yet published" message.
Web App SAML Authentication Callback RedirectionFixed an issue where completing SAML authentication callbacks in web applications incorrectly redirected users to the console.
SSO: Admin Login with Expired LicensesFixed an issue where expired licenses or exceeded seat limits blocked enterprise dashboard SSO logins, preventing administrators from accessing the system for activation.
Imported Workflow Persistence After PublishingFixed an issue where refreshing the page after successfully publishing an imported workflow caused the workflow to disappear.
Human Input Test Email Modal StatusFixed an issue where opening the test email modal a second time in Human Input nodes falsely displayed the email as sent when it was not.
Prompt Generator: Model Parameter ConfigurationFixed an issue where the prompt generator ignored user-configured model parameters, causing execution errors when using models such as Qwen.
Agent: Duplicate Tool ResultsFixed an issue where tools returning both JSON and text formats caused Agents to receive duplicate results.
User Feedback and Prompt Generation MetricsFixed an issue where metrics related to user feedback and prompt generation were missing from monitoring telemetry.
Workflow Node Execution Metrics and TracingFixed an issue where workflow node execution metrics and trace tracking data were missing.
Unconfigured Tracing Provider HandlingFixed an issue where querying unconfigured providers returned 500 errors when optional tracing SDKs were missing.
Plugin Pod Graceful TerminationFixed an issue where plugin Pods failed to terminate gracefully during shutdown.
Invalid UUID Parameter Response CodeFixed an issue where passing invalid UUID parameters returned a 500 internal server error code instead of 400 bad request.
Pre-installed spaCy Model for Offline Email ExtractionFixed an issue where MSG/email parsing failed in offline environments due to a missing spaCy English model by pre-installing the model in the container image.
Application Deletion Audit LogsFixed an issue where audit log entries were missing during application deletion due to incomplete or missing resource associations.
Helm: Squid Startup Out-of-Memory ErrorsFixed an issue where Squid crashed with out-of-memory errors on startup when host file descriptor limits were set too high, resolved by capping file descriptors via Helm.
Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. The assessment covers four advisories (CVE-2026-57585, GHSA-6v7p-g79w-8964, CVE-2025-47273, CVE-2026-59890); see the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full details.
Security: nltk path-traversal advisory has no upstream fixCVE-2026-81726 (path traversal in nltk ≤ 3.10.3) is still reported against the API image and has no fixed release upstream. It is the only high-severity finding in the default dify-ee-api image that is not covered by the VEX document; we are tracking the upstream fix and will ship it as soon as one is published.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
If your deployment uses ChromaDB, review the known vulnerabilities before selecting the dify-ee-api-insecure:3.13.0 image
Confirm Kubernetes cluster has sufficient resources for rolling update
Schedule a maintenance window; after upgrading, run flask rbac-migrate-agent-permissions (dry run by default), then rerun with --apply (see Migration Notes)
Review the migration requirements of earlier releases when upgrading across multiple versions
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.13.0

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 28 High CVE across all container images
ScannerDocker Scout
Scanned
Sep 29, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
TTFE – Time To First Event (ms)
AVG
412.64
MIN
242
MAX
1441
P50
271
P90
701.1
P95
966.5
Connections
Max Concurrent
3
Avg Active
2.9
Empty Workflow QPS
Max QPS
19.6
Avg QPS
17.63
Avg Duration (ms)
590.45

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.9.13

· 5 min read

What Changed

6
Bug Fixes
Security: Python dependency updates in the API imagePicked up the dependency fixes landed on the community lts/1.13.x branch: anyio 4.11.0 → 4.14.2, which clears the critical improper-certificate-validation advisory (CVE-2026-63374) and the unbounded process-pool stderr allocation (CVE-2026-64847); gitpython 3.1.59 → 3.1.62 (CVE-2026-87817 / 87818 / 87819); pypdf 6.15.0 → 6.16.1 (CVE-2026-84309 / 84310 / 84311); soupsieve 2.8.4 → 2.9 (CVE-2026-85999 / 86000); pygments 2.19.2 → 2.20.0; plus a 15-package group bump covering starlette, sentry-sdk, unstructured, numpy, pandas, gevent, pyjwt, yarl, charset-normalizer and others. The default dify-ee-api image now scans with zero critical findings.
Security: Next.js upgraded to 16.3.6 in the Web imageThe community Web image now builds on Next.js 16.3.6 (up from 16.3.4), keeping the LTS line on the current patched framework release. No configuration change is required.
Security: OS-level CVEs cleared by a base-image refreshAll images were rebuilt on refreshed Chainguard base layers, which picks up the fixed zlib (CVE-2026-85091), node-gyp (CVE-2026-84890 / 84933 / 84961), wget (CVE-2026-16599) and glibc (CVE-2026-18374) packages. The Enterprise, Gateway, Audit, Collector, Enterprise Frontend, Web, Plugin Manager, Connector, Controller, Shader and Plugin Daemon images now report no critical and no high findings.
Security Notes
Release scope: dependency and base-image updates onlyThis is a security-maintenance release. The Enterprise services (0.16.x), Enterprise Frontend, plugin daemon and sandbox are built from the same source commits as 3.9.12 — only the community application (lts/1.13.x) moved forward, and only for dependency upgrades. There are no functional changes, no database migrations and no configuration changes in this release.
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. The assessment is unchanged from 3.9.12 and covers the same three advisories; see the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full details.
Security: nltk path-traversal advisory has no upstream fixCVE-2026-81726 (path traversal in nltk ≤ 3.10.3) is still reported against the API image and has no fixed release upstream. It is the only high-severity finding in the default dify-ee-api image that is not covered by the VEX document; we are tracking the upstream fix and will ship it as soon as one is published.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Review the manifest changes before applying: helm diff upgrade dify dify-ee/dify --version 3.9.13 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.13 -f values.yaml and compare it against helm get manifest dify
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up the database and review the manifest diff first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.13

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 19 High CVE across all container images
ScannerDocker Scout
Scanned
Sep 23, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
161.19
MIN
127
MAX
519
P50
145
P90
159
P95
164.8
Connections
Max Concurrent
11
Avg Active
9.8
Empty Workflow QPS
Max QPS
28
Avg QPS
26.85
Avg Duration (ms)
408.15

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.9.12

· 6 min read

What Changed

10
New Features
Bug Fixes
Studio: Creating an app from a template returns 404Creating an app from a template on the Studio page navigated to /console/api/apps/null and failed with a 404, because the pending template import was not carried over from the app list. Template imports are now handled correctly and app creation succeeds. (ENG-827)
Plugins: Scheduled auto-upgrade silently failsThe plugin auto-upgrade task called the daemon's upgrade endpoint directly without downloading the new package from the marketplace and uploading it first, so the daemon could not find the package and the upgrade failed silently while the task reported success. Auto-upgrade now uses the same download → upload → upgrade path as the console "Upgrade" button. (ENG-829)
SSO: OIDC login fails when userinfo returns no emailOIDC sign-in failed for providers whose userinfo endpoint does not return an email claim. The login flow now falls back to reading the email from the id_token. (ENG-832)
Knowledge Base: Postgres deadlock under concurrent retrievalConcurrent retrieval requests updating overlapping document_segments hit counts could acquire row locks in different orders and fail with a PostgreSQL deadlock (SQLSTATE 40P01). Target rows are now locked in a consistent order and the retrieval-statistics transaction is retried on deadlock; retrieval results and ranking are unchanged. (ENG-834)
Knowledge Base: Attachment files left in storage after segment deletionDeleting an indexed segment from a multimodal knowledge base removed the database records and vector entry but left the physical attachment object in the storage backend, silently consuming space. Attachment objects are now deleted from storage after the database transaction commits, while attachments still referenced by another segment are preserved. (ENG-835)
Weaviate: Vectors overwriting each other and orphaned objects left behindWeaviate object UUIDs were derived from the page content, so segments with identical content overwrote one another, and deletions keyed by index_node_id left orphaned vectors behind. New writes now use doc_id as the canonical object UUID, and a backward-compatible cleanup pass removes legacy content-derived objects on delete. No migration is required. (ENG-836)
Tencent VectorDB: Summary generation fails and blocks a workerTencent VectorDB rejects boolean values in JSON metadata, so the is_summary marker made summary vector upserts fail; the failure path then opened a second database session against a row still locked by the caller, leaving the task stuck and occupying a worker slot. The marker is now stored as an integer for Tencent VectorDB only, and vectorization errors are recorded in the caller-owned session.
Security: Dependency updates across API, Web and Enterprise imagesBumped transformers, unstructured, gitpython, nltk and sharp in the community images, Next.js to 16.3.4 in the Enterprise frontend, and gRPC to 1.83.2 plus x/crypto to 0.56.0 in the Enterprise services, resolving the associated CVEs. See the Security & CVE section below for the current scan results.
Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. The assessment is unchanged from 3.9.11 and covers the same three advisories; see the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full details.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Review the manifest changes before applying: helm diff upgrade dify dify-ee/dify --version 3.9.12 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.12 -f values.yaml and compare it against helm get manifest dify
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up the database and review the manifest diff first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.12

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.1 Critical · 45 High CVE across all container images
ScannerDocker Scout
Scanned
Sep 21, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
152
MIN
121
MAX
506
P50
135
P90
146
P95
153.5
Connections
Max Concurrent
12
Avg Active
10.5
Empty Workflow QPS
Max QPS
25.4
Avg QPS
23.95
Avg Duration (ms)
208.22

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.9.11

· 6 min read

What Changed

10
Bug Fixes
Content Moderation: Chat hangs indefinitely when moderation is triggeredWhen content moderation flagged a message, the streamed response could hang forever with no way to stop it, blocking further questions. Workflow execution error handling was fixed so the response now terminates cleanly on a moderation hit. (ENG-764)
HTTP Node: Garbled non-ASCII (e.g. Chinese) response textThe HTTP Request node auto-detected the response encoding and could misread UTF-8 payloads, garbling Chinese characters even when a charset was set. It now honors the charset declared in the response Content-Type header before falling back to detection. (ENG-767)
LLM Node: Model search returns no resultsSearching for a model in the LLM node settings returned empty results because the keyword had to match both the provider and the model name simultaneously. The filter now matches when the keyword hits either field. (ENG-772)
Conversations: "Annotated" filter returns 500Filtering conversations by annotation_status=annotated triggered a PostgreSQL error ("could not identify an equality operator for type json") because the query attempted a full-row DISTINCT over a JSON column. The query was corrected so the annotated filter now works. (ENG-776)
Workflow: Variable Aggregator group toggle not clickableClicking the "aggregate groups" switch in the Variable Aggregator node did nothing and logged "Cannot read properties of undefined (reading 'groups')" when advanced_settings was empty. The node now handles the empty case so the toggle works. (ENG-785)
Workflow: Runs stuck permanently "running" after a Redis blipA transient broker/Redis disconnect during stop checks raised a broken-pipe error, leaving the Workflow Run and its node in "running" forever while the Celery task reported success. Broken-pipe errors during workflow and app stop checks are now ignored so runs converge to a terminal state. (ENG-787)
Knowledge Base: Search fails with "cannot extract elements from a scalar"Knowledge base retrieval could fail with a "cannot extract elements from a scalar" error. The upstream fix has been backported to the LTS line, restoring normal search. (ENG-804)
Document Extraction: .msg files fail to parse in offline environmentsParsing .msg files required the en_core_web_sm spaCy model, which the API image downloaded from GitHub at first use — failing with a timeout in air-gapped or restricted-network deployments. The model is now preinstalled in the image via the Dockerfile, so .msg extraction works offline without any additional network access. (ENG-768)
Explore: App details page errors out for trial appsOpening an app's details from the Explore section could throw an error for trial (TRIAL_APP) apps, breaking the page. The details button is now hidden so the erroring page can no longer be reached. (ENG-773)
Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. See the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full exploitability assessment.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.11

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 18 High CVE across all container images
ScannerDocker Scout
Scanned
Aug 27, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
TTFE – Time To First Event (ms)
AVG
153.79
MIN
116
MAX
557
P50
133
P90
150.8
P95
159.5
Connections
Max Concurrent
18
Avg Active
17.4
Empty Workflow QPS
Max QPS
38.6
Avg QPS
37.88
Avg Duration (ms)
106.53

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.12.1

· 8 min read

What Changed

15
New Features
Bug Fixes
Security: Plugin Installation Policy Could Be Bypassed by RetryingUnder a restricted Allowed Plugins policy, upgrading an already-installed plugin was rejected on the first attempt and succeeded on the second. The scope check ran only after the package had been fetched, so the first attempt populated a cache that the second attempt then used to skip validation entirely. Every install and upgrade path now validates the installation scope before the package is fetched.
Security: CVE Remediation Across Enterprise ImagesDependency updates and a Go toolchain bump across the enterprise images clear the advisories that could be remediated at build time, including Go standard library, go-git, gRPC and golang.org/x/text issues. A small number remain where no upstream fix has yet been published. The Security & CVE section below is generated from the release scan and lists the current per-image results.
Knowledge Base: Inconsistent Default Access When Created With a DocumentWith RBAC enabled, a knowledge base created together with its first document defaulted to private, while one created empty defaulted to "All members" — so the same action produced different access depending on how it was started. Both paths now default to "All members". Existing knowledge bases are unaffected.
Knowledge Base: External Knowledge Base Creation FailsConnecting an external knowledge base failed with "Missing dataset_id or pipeline_id in request path". The enterprise permission check required a knowledge base ID that cannot exist while one is being created. Creation now succeeds.
Agent: Attachments Dropped on Models Without Vision SupportFiles attached in the Agent preview were silently discarded before the request reached the agent whenever the selected model had no vision support. The upload appeared to succeed but the agent never received the file. Affected all file types, including spreadsheets, PDFs, and documents.
RBAC: Owner Role Displayed an Incomplete Permission ListThe workspace Owner rendered as holding 6 of 16 application permissions in the console. The Owner has always had full access — only the displayed permission set was wrong. All 16 are now listed.
Workspace: Ownership Transfer Could Leave Two OwnersTransferring workspace ownership appended the owner role to the recipient rather than replacing their existing roles, leaving them with a mix of roles. Transfers made through the admin API did not update RBAC at all, which could leave the previous owner still holding the owner role and block every later transfer. Both paths now leave exactly one owner.
Plugin Credentials: Fields Cleared When Switching Plugin VersionChanging the version of a configured credential plugin cleared every field in the form. Required fields had to be re-entered, and optional ones such as endpoint URL were lost on save without warning. Saved values are now preserved across a version switch.
Helm: Redis Connection String Exposed in ConfigMapsThe composed Redis connection string, which contains the password, was rendered as plaintext into the gateway Caddyfile ConfigMap and the enterprise collector ConfigMap. Both now read it from a Secret, keeping the credential out of anything that can read ConfigMaps and out of GitOps diffs.
Helm: Redis Usernames Containing URL Delimiters Failed to AuthenticateThe Celery broker URL encoded the password but not the username, so a username containing a character such as a colon, slash, hash, or question mark was misparsed — silently authenticating as a different user or as none at all. Usernames are now encoded correctly.
License: Expiry Badge Wording and Remaining DaysThe admin dashboard license badge now shows the days remaining directly instead of only on hover. In Japanese, an expiring license and an already-expired one both displayed as 期限切れ, making them indistinguishable; they now read differently and the remaining-days string renders as a proper sentence.
Observability: Continuous OpenTelemetry Context Detach ErrorsWith ENABLE_OTEL turned on, the API logged "Failed to detach context" continuously under concurrent load, caused by a known defect in the OpenTelemetry Flask instrumentation detaching the same context token twice. Requests were never affected; trace context is now recorded correctly and the log noise is gone.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
No migration or manual step is required — this release can be applied directly on top of 3.12.0
If your Redis username contains a colon, slash, hash, or question mark, it was previously misparsed; confirm the account it authenticates as after upgrading
On clusters that drop Linux capabilities, Code nodes need sandbox.securityContext with SYS_CHROOT added — see New Features
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.12.1

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 31 High CVE across all container images
ScannerDocker Scout
Scanned
Aug 14, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
350.92
MIN
161
MAX
1679
P50
177
P90
497.6
P95
1031.1
Connections
Max Concurrent
18
Avg Active
17.5
Empty Workflow QPS
Max QPS
23.2
Avg QPS
20.6
Avg Duration (ms)
564.66

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.9.10

· 5 min read

What Changed

5
Bug Fixes
Form: Markdown form field names support more fullwidth charactersRemoved hard-coded punctuation from the field-name allowlist and added the self-hosted NEXT_PUBLIC_MARKDOWN_FORM_FIELD_NAME_EXTRA_CHARS setting so operators can opt in additional characters such as ()!*&-。.;;+=—. Also fixes a Streamdown issue where a stray trailing * was appended when form attributes contained punctuation. (ESQ1-226)
Form: Workspace custom brand logo ignored on human-input formThe HITL/form page hard-coded the Dify logo and ignored the workspace-configured "Powered by" brand image. It now reads the workspace branding configuration and renders the custom logo. (ESQ1-238)
Model: Credential fields cleared when switching model typesCredential schemas can reuse the same variable (e.g. context_size, video_support) across multiple model types. A stale timer from a hidden schema entry could delete the value used by the currently visible sibling, leaving fields empty after switching model types. Values are now preserved per visible schema and video_support consistently restores its default. (ESQ1-242)
OSS: Built-in object storage ignored HTTP Range, breaking plugin installs >5MBThe built-in object storage (server/pkg/oss, used when persistence.type != s3) ignored the Range header and always returned the full object. Kaniko downloads plugin build contexts via parallel ranged GETs (5MB parts), so every part received the full body and corrupted objects larger than one part — plugin installs >5MB failed with EOF. Single-range requests are now handled per RFC 9110 (206/416), restoring normal plugin installation. (ESQ1-234)
Security Notes
Security: CVEs from pip-vendored setuptools / msgpack are non-runtimeThe setuptools and msgpack CVEs flagged in this release's scan are introduced by the latest pip version as vendored dependencies. They cannot be fixed on our side without forking pip. They are not related to runtime behavior — pip does not import pip._vendor.setuptools at runtime. Per the pip maintainers (pypa/pip#14031): "A security issue in a vendored library does not necessarily represent a security issue in pip." These findings are accepted as non-actionable.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.10

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 18 High CVE across all container images
ScannerDocker Scout
Scanned
Aug 13, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
148.5
MIN
119
MAX
571
P50
132
P90
160.1
P95
162
Connections
Max Concurrent
18
Avg Active
17.2
Empty Workflow QPS
Max QPS
41.4
Avg QPS
39.71
Avg Duration (ms)
154.89

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.12.0

· 5 min read

What Changed

7
New Features
Bug Fixes
Plugin Daemon: Fixed Declaration Cache Deadlock Causing Full Plugin OutageFixed a bug in the plugin declaration cache's eviction logic where a size-accounting drift could spin the eviction loop forever while holding its lock, blocking every plugin-related API call (install, list, credential validation) until the daemon was restarted.
Admin Console: RBAC Fixes for Owner Transfer & InvitationsFixed several admin console RBAC issues around workspace owner transfer and join/email invitation guards.
Plugin Management: Backend-Assigned Plugins Not VisibleFixed a bug where plugins assigned to a workspace from the admin backend did not appear when configuring credentials in that workspace until the plugin was also installed from the front end.
Security: CVE Dependency RemediationBumped vulnerable dependencies across components (starlette, soupsieve, cryptography, wandb, grpc, sharp) to close CVEs identified in the pre-release Docker Scout scan.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for the rolling update
This version cannot be skipped: it seeds a new agent.manage RBAC permission automatically on startup (no manual action needed)
If you plan to use Kubernetes Agent Sandbox, install the agent-sandbox controller and CRDs BEFORE upgrading, then set sandboxGateway.enabled: true (see Migration Notes) — otherwise the upgrade will fail creating SandboxTemplate/SandboxWarmPool resources
To lock down public webapp access, set enterprise.webappPublicAccessEnabled: false
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.12.0

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.2 Critical · 23 High CVE across all container images
ScannerDocker Scout
Scanned
Jul 31, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
171.42
MIN
152
MAX
194
P50
170.5
P90
185.5
P95
189.6
Connections
Max Concurrent
1
Avg Active
1
Empty Workflow QPS
Max QPS
42
Avg QPS
39.89
Avg Duration (ms)
221.52

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.9.9

· 4 min read

What Changed

4
Bug Fixes
Annotation Reply: remove 0.8 score threshold lower boundRemoved the arbitrary 0.8 lower-bound UI limit on the Annotation Reply score threshold, so the value can now be configured across the full 0.00–1.00 range as intended.
Datasource: API-key modal hidden behind settings panelFixed an incorrect z-index on the datasource API-key modal that caused it to be obscured by the settings panel. The modal now renders correctly above the panel.
Security Fixes
Security: SSRF bypass in API tool schema fetchThe API tool schema fetch endpoint used raw httpx.get() instead of ssrf_proxy.get(), bypassing the Squid SSRF proxy and allowing authenticated users to reach internal URLs (cloud metadata, Redis, Postgres). All fetches now route through the SSRF proxy. (GHSA-gfmc-xc6g-q7g2)
Security: CVE remediationRemediated one high-severity CVE (CVE-2026-40898) and two medium-severity CVEs (CVE-2026-6993, CVE-2026-41178) affecting the plugin-daemon, gateway, enterprise, and enterprise-audit images. See the Security CVE section below for detailed scan results.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.9

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 0 High CVE across all container images
ScannerDocker Scout
Scanned
Jul 29, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
158.14
MIN
121
MAX
531
P50
141
P90
159.6
P95
189.8
Connections
Max Concurrent
12
Avg Active
10.7
Empty Workflow QPS
Max QPS
26.2
Avg QPS
25.02
Avg Duration (ms)
243.44

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0

Release v3.11.1

· 6 min read

What Changed

7
New Features
Bug Fixes
Security: SQL Injection HardeningHardened SQL query construction and added metadata key validation to close SQL injection vectors inherited from the Community Edition base.
Security: CVE Dependency RemediationBumped vulnerable dependencies (python-socketio, python-engineio, soupsieve) and upgraded the plugin-daemon Go builder to clear outstanding standard-library CVEs. See the Security & CVE section below for the full scan results.
RBAC: Editor Permission CorrectionsFixed several editor-role permission issues: editors no longer attempt member management, editors can now view application logs, and changing trace configuration now correctly requires edit access. A new app created by a member is now accessible by default to all members holding the corresponding role.
Plugin Management StabilityFixed integration marketplace install callbacks, debug-mode plugin permission settings that did not apply, plugin external user ID resolution in backwards invocations, and kept provider credential refreshes single-flight to avoid redundant work. Also enabled HTTP Range requests on the built-in object storage, fixing install failures for plugins larger than 5MB.
Workflow and API StabilityResolved "Working outside of application context" errors, corrected chunked workflow failure-tracking data, guarded against an infinite loop during batched record deletion, and wired a dedicated timeout into inner RBAC requests.
UI and Authentication FixesFixed main navigation item states, dataset creation layout height, app card overflow, dark-mode rendering with no plugins installed, the Human-in-the-Loop input save button visibility, toasts blocking page clicks, OAuth error display, a duplicated auth prefix, and broken pagination on the admin members page after filtering by group.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for the rolling update
If upgrading from a version earlier than 3.11.0: schedule a maintenance window — the RBAC migrations below are mandatory and the application is unusable until they complete (skip this entire block if you are already on 3.11.0)
Then run flask rbac-migrate-member-roles (mandatory from <3.11.0; members have no access until this finishes)
Then run flask rbac-migrate-dataset-permissions --apply (mandatory from <3.11.0; dataset access is incorrect under RBAC until this finishes)
Then run flask backfill-plugin-auto-upgrade (mandatory from <3.11.0) before restoring traffic
To enable Workflow Collaboration, set collaboration.enabled and deploy the websocket service (see Migration Notes)
Expect a brief reconnect of active workflow editing sessions during the rolling update
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.11.1

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 14 High CVE across all container images
ScannerDocker Scout
Scanned
Jul 16, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
176.85
MIN
131
MAX
506
P50
153
P90
170.8
P95
305.6
Connections
Max Concurrent
3
Avg Active
2.9
Empty Workflow QPS
Max QPS
42.2
Avg QPS
38.84
Avg Duration (ms)
163.65

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.