v3.9.11
LTS
Released Aug 27, 2026·Supported until Sep 30, 2027·Community 1.13.x·Community commit 9eb23f5·Enterprise 0.16.x·Helm chart·Docker Compose
Breaking
1 to verify
Security
Issues
Changes
0F · 10B
Downtime
Zero
Upgrade Impact
Breaking:The default Enterprise API image excludes the ChromaDB vector store from this version (to fix a critical CVE), along with Weights & Biases tracing and ClickZetta, which remain excluded as before; use the `-insecure` API image if you still need any of them.
API image: ChromaDB, W&B tracing and ClickZetta excluded from default buildThe default
dify-ee-api image excludes the ChromaDB vector store from this version to fix a critical CVE in the ChromaDB dependency, as well as Weights & Biases (`wandb`) tracing and the ClickZetta vector database, which remain excluded as in previous versions. If your deployment relies on any of them, use the docker.io/langgenius/dify-ee-api-insecure:3.9.11 image tag, which includes these integrations at the cost of the additional known vulnerabilities listed in the CVE report below.CVEs for the opt-in
api-insecure image is excluded from the aggregate counts above.What Changed
10Bug Fixes
Content Moderation: Chat hangs indefinitely when moderation is triggeredWhen content moderation flagged a message, the streamed response could hang forever with no way to stop it, blocking further questions. Workflow execution error handling was fixed so the response now terminates cleanly on a moderation hit. (ENG-764)
HTTP Node: Garbled non-ASCII (e.g. Chinese) response textThe HTTP Request node auto-detected the response encoding and could misread UTF-8 payloads, garbling Chinese characters even when a charset was set. It now honors the charset declared in the response Content-Type header before falling back to detection. (ENG-767)
LLM Node: Model search returns no resultsSearching for a model in the LLM node settings returned empty results because the keyword had to match both the provider and the model name simultaneously. The filter now matches when the keyword hits either field. (ENG-772)
Conversations: "Annotated" filter returns 500Filtering conversations by annotation_status=annotated triggered a PostgreSQL error ("could not identify an equality operator for type json") because the query attempted a full-row DISTINCT over a JSON column. The query was corrected so the annotated filter now works. (ENG-776)
Workflow: Variable Aggregator group toggle not clickableClicking the "aggregate groups" switch in the Variable Aggregator node did nothing and logged "Cannot read properties of undefined (reading 'groups')" when advanced_settings was empty. The node now handles the empty case so the toggle works. (ENG-785)
Workflow: Runs stuck permanently "running" after a Redis blipA transient broker/Redis disconnect during stop checks raised a broken-pipe error, leaving the Workflow Run and its node in "running" forever while the Celery task reported success. Broken-pipe errors during workflow and app stop checks are now ignored so runs converge to a terminal state. (ENG-787)
Knowledge Base: Search fails with "cannot extract elements from a scalar"Knowledge base retrieval could fail with a "cannot extract elements from a scalar" error. The upstream fix has been backported to the LTS line, restoring normal search. (ENG-804)
Document Extraction: .msg files fail to parse in offline environmentsParsing .msg files required the en_core_web_sm spaCy model, which the API image downloaded from GitHub at first use — failing with a timeout in air-gapped or restricted-network deployments. The model is now preinstalled in the image via the Dockerfile, so .msg extraction works offline without any additional network access. (ENG-768)
Explore: App details page errors out for trial appsOpening an app's details from the Explore section could throw an error for trial (TRIAL_APP) apps, breaking the page. The details button is now hidden so the erroring page can no longer be reached. (ENG-773)
Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. See the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full exploitability assessment.
Upgrade Guide
Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Zero-downtime rolling upgrade supported
Upgrade Command
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.11
Rollback
$ helm rollback dify 0
Security & CVE
Security vulnerabilities found in this release.0 Critical · 18 High CVE across all container images
Image
critical
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
low
6
1
1
2
0
2
5
5
5
1
2
2
7
1
1
7
0
Status
FAIL
PASS
PASS
PASS
PASS
PASS
FAIL
FAIL
FAIL
PASS
PASS
PASS
FAIL
PASS
PASS
FAIL
PASS
ScannerDocker Scout
Scanned
Aug 27, 2026
Data Source
Docker
CVEs for the opt-in
api-insecure image is excluded from the CVE table above.VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
Benchmark Report
TTFE – Time To First Event (ms)
AVG
153.79
MIN
116
MAX
557
P50
133
P90
150.8
P95
159.5
Connections
Max Concurrent
18
Avg Active
17.4
Empty Workflow QPS
Max QPS
38.6
Avg QPS
37.88
Avg Duration (ms)
106.53
License Compliance
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0