v3.9.12
LTS
Released Sep 10, 2026·Supported until Sep 30, 2027·Community 1.13.x·Community commit fd2ea38·Enterprise 0.16.x·Helm chart·Docker Compose
Breaking
1 to verify
Security
Issues
Changes
1F · 9B
Downtime
Zero
Upgrade Impact
Breaking:The default Enterprise API image still excludes the ChromaDB vector store, Weights & Biases tracing and ClickZetta, unchanged from 3.9.11; use the `-insecure` API image if you still need any of them.
API image: ChromaDB, W&B tracing and ClickZetta remain excluded from the default buildThe default
dify-ee-api image continues to exclude the ChromaDB vector store (an unfixed critical CVE in the ChromaDB dependency), Weights & Biases (`wandb`) tracing and the ClickZetta vector database. The set of excluded integrations is unchanged from 3.9.11. If your deployment relies on any of them, use the docker.io/langgenius/dify-ee-api-insecure:3.9.12 image tag, which includes these integrations at the cost of the additional known vulnerabilities listed in the CVE report below.CVEs for the opt-in
api-insecure image is excluded from the aggregate counts above.What Changed
10New Features
Web App: Configurable Markdown form field name lengthThe Markdown form field-name length limit was hard-coded to 128 characters, which rejected longer field names in generated forms. It is now configurable through
MARKDOWN_FORM_FIELD_NAME_MAX_LENGTH (Docker) / NEXT_PUBLIC_MARKDOWN_FORM_FIELD_NAME_MAX_LENGTH (Web), still defaulting to 128 with the existing character validation intact. (CUS-1603)Bug Fixes
Studio: Creating an app from a template returns 404Creating an app from a template on the Studio page navigated to
/console/api/apps/null and failed with a 404, because the pending template import was not carried over from the app list. Template imports are now handled correctly and app creation succeeds. (ENG-827)Plugins: Scheduled auto-upgrade silently failsThe plugin auto-upgrade task called the daemon's upgrade endpoint directly without downloading the new package from the marketplace and uploading it first, so the daemon could not find the package and the upgrade failed silently while the task reported success. Auto-upgrade now uses the same download → upload → upgrade path as the console "Upgrade" button. (ENG-829)
SSO: OIDC login fails when userinfo returns no emailOIDC sign-in failed for providers whose
userinfo endpoint does not return an email claim. The login flow now falls back to reading the email from the id_token. (ENG-832)Knowledge Base: Postgres deadlock under concurrent retrievalConcurrent retrieval requests updating overlapping
document_segments hit counts could acquire row locks in different orders and fail with a PostgreSQL deadlock (SQLSTATE 40P01). Target rows are now locked in a consistent order and the retrieval-statistics transaction is retried on deadlock; retrieval results and ranking are unchanged. (ENG-834)Knowledge Base: Attachment files left in storage after segment deletionDeleting an indexed segment from a multimodal knowledge base removed the database records and vector entry but left the physical attachment object in the storage backend, silently consuming space. Attachment objects are now deleted from storage after the database transaction commits, while attachments still referenced by another segment are preserved. (ENG-835)
Weaviate: Vectors overwriting each other and orphaned objects left behindWeaviate object UUIDs were derived from the page content, so segments with identical content overwrote one another, and deletions keyed by
index_node_id left orphaned vectors behind. New writes now use doc_id as the canonical object UUID, and a backward-compatible cleanup pass removes legacy content-derived objects on delete. No migration is required. (ENG-836)Tencent VectorDB: Summary generation fails and blocks a workerTencent VectorDB rejects boolean values in JSON metadata, so the
is_summary marker made summary vector upserts fail; the failure path then opened a second database session against a row still locked by the caller, leaving the task stuck and occupying a worker slot. The marker is now stored as an integer for Tencent VectorDB only, and vectorization errors are recorded in the caller-owned session.Security: Dependency updates across API, Web and Enterprise imagesBumped transformers, unstructured, gitpython, nltk and sharp in the community images, Next.js to 16.3.4 in the Enterprise frontend, and gRPC to 1.83.2 plus
x/crypto to 0.56.0 in the Enterprise services, resolving the associated CVEs. See the Security & CVE section below for the current scan results.Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. The assessment is unchanged from 3.9.11 and covers the same three advisories; see the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full details.
Upgrade Guide
Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Review the manifest changes before applying:
helm diff upgrade dify dify-ee/dify --version 3.9.12 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.12 -f values.yaml and compare it against helm get manifest difyZero-downtime rolling upgrade supported
Upgrade Command
# Back up the database and review the manifest diff first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.12
Rollback
$ helm rollback dify 0
Security & CVE
Security vulnerabilities found in this release.1 Critical · 45 High CVE across all container images
Image
low
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
Status
FAIL
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
PASS
ScannerDocker Scout
Scanned
Sep 21, 2026
Data Source
Docker
CVEs for the opt-in
api-insecure image is excluded from the CVE table above.Benchmark Report
TTFE – Time To First Event (ms)
AVG
152
MIN
121
MAX
506
P50
135
P90
146
P95
153.5
Connections
Max Concurrent
12
Avg Active
10.5
Empty Workflow QPS
Max QPS
25.4
Avg QPS
23.95
Avg Duration (ms)
208.22
License Compliance
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0