Release v3.9.14
What Changed
8ARCHIVE_STORAGE_ADDRESS_STYLE setting (path, virtual or auto) controls how the archive storage S3 client builds request and presigned URLs. Previously the client always used path-style addressing, which broke S3-compatible providers that only accept virtual-hosted-style URLs. The default stays path, so existing deployments are unaffected.next/og ImageResponse (attacker-controlled SVG content), an SSRF in Image Optimization via allow-listed remote URLs, several use cache / ISR cache-poisoning and origin-validation issues, and a heap overflow in the libheif library bundled with sharp.lts/1.13.x branch: urllib3 2.7.0 → 2.8.0, pypdf 6.16.1 → 6.19.0, fsspec 2025.10.0 → 2026.6.0, a 9-package group bump (including pyjwt 2.15.1, starlette 1.7.0, sentry-sdk 2.71.0, markdown 3.11 and unstructured), and a 10-package bump of the storage SDKs (boto3, azure-identity, azure-storage-blob, google-cloud-storage, opendal, supabase, tos, cos, bce and OBS).uv, npm / pnpm / corepack / yarn, git and the base image's system pip no longer ship in the API, API-insecure, Web and Enterprise Frontend images, and uv / git no longer ship in the sandbox (which keeps pip and a C toolchain so Python dependencies can still be installed, including from source). The images are also substantially smaller. This removes every finding that came from those tools, including http-cache-semantics (CVE-2026-93748) in the Web and Enterprise Frontend images and the uv-bundled crates in the API and sandbox images. The Web and Enterprise Frontend images now report no known vulnerabilities.pip/_vendor/bom.cdx.json) shipped in Chainguard's py3.x-pip-26.2.1-r2 package. The vendored code actually shipped is urllib3 2.8.0 and msgpack 1.2.1. Chainguard has since published py3.x-pip-26.2.1-r3 with a corrected SBOM. The sandbox image already uses it, so these findings are gone there, and the plugin images will pick it up in a follow-up release. Until then, these advisories are covered by pip-vendored.openvex.json.pkg_resources, so setuptools.package_index, where the issue lives, is not present in the image. This is covered by pip-vendored.openvex.json.uv at runtime to install plugin dependencies (Wolfi package uv-0.12.24-r0). The block-buffer 0.10.4 statement (sonatype-2026-003895, GHSA-qwgh-2vcv-g2f7) is kept for these images: uv is built with panic = "abort", so the caught-panic precondition of the advisory cannot occur. This is covered by uv-vendored.openvex.json.nltk ≤ 3.10.3) still has no fixed release upstream and is still reported against the API image. It will be picked up as soon as a fixed release is available.Upgrade Guide
helm diff upgrade dify dify-ee/dify --version 3.9.14 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.14 -f values.yaml and compare it against helm get manifest dify# Back up the database and review the manifest diff first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.14
$ helm rollback dify 0
Security & CVE
api-insecure image is excluded from the CVE table above.