v3.9.14
LTSRecommended
Released Oct 9, 2026·Supported until Sep 30, 2027·Community 1.13.x·Community commit 9f9c495·Enterprise 0.16.x·Helm chart·Docker Compose
Breaking
1 to verify
Security
Issues
Changes
1F · 7B
Downtime
Zero
Upgrade Impact
Breaking:The default Enterprise API image still excludes the ChromaDB vector store, Weights & Biases tracing and ClickZetta, unchanged from 3.9.12; use the `-insecure` API image if you still need any of them.
API image: ChromaDB, W&B tracing and ClickZetta remain excluded from the default buildThe default
dify-ee-api image continues to exclude the ChromaDB vector store (an unfixed critical CVE in the ChromaDB dependency), Weights & Biases (`wandb`) tracing and the ClickZetta vector database. The set of excluded integrations is unchanged from 3.9.12. If your deployment relies on any of them, use the docker.io/langgenius/dify-ee-api-insecure:3.9.14 image tag, which includes these integrations at the cost of the additional known vulnerabilities listed in the CVE report below.CVEs for the opt-in
api-insecure image is excluded from the aggregate counts above.What Changed
8New Features
Archive Storage: Configurable S3 addressing styleA new
ARCHIVE_STORAGE_ADDRESS_STYLE setting (path, virtual or auto) controls how the archive storage S3 client builds request and presigned URLs. Previously the client always used path-style addressing, which broke S3-compatible providers that only accept virtual-hosted-style URLs. The default stays path, so existing deployments are unaffected.Bug Fixes
Security: Next.js 16.3.8 and sharp 0.35.5 in the Web and Enterprise Frontend imagesBoth the community Web image and the Enterprise Frontend image now build on Next.js 16.3.8 and sharp 0.35.5. This fixes a critical remote-code-execution advisory in
next/og ImageResponse (attacker-controlled SVG content), an SSRF in Image Optimization via allow-listed remote URLs, several use cache / ISR cache-poisoning and origin-validation issues, and a heap overflow in the libheif library bundled with sharp.Security: Python dependency updates in the API imagePicked up the dependency fixes landed on the community
lts/1.13.x branch: urllib3 2.7.0 → 2.8.0, pypdf 6.16.1 → 6.19.0, fsspec 2025.10.0 → 2026.6.0, a 9-package group bump (including pyjwt 2.15.1, starlette 1.7.0, sentry-sdk 2.71.0, markdown 3.11 and unstructured), and a 10-package bump of the storage SDKs (boto3, azure-identity, azure-storage-blob, google-cloud-storage, opendal, supabase, tos, cos, bce and OBS).Security Notes
Security: build tooling removed from the API, sandbox, Web and Enterprise Frontend runtime imagesThe runtime stage of these images now starts from a minimal Wolfi base and installs only what the service needs at runtime.
uv, npm / pnpm / corepack / yarn, git and the base image's system pip no longer ship in the API, API-insecure, Web and Enterprise Frontend images, and uv / git no longer ship in the sandbox (which keeps pip and a C toolchain so Python dependencies can still be installed, including from source). The images are also substantially smaller. This removes every finding that came from those tools, including http-cache-semantics (CVE-2026-93748) in the Web and Enterprise Frontend images and the uv-bundled crates in the API and sandbox images. The Web and Enterprise Frontend images now report no known vulnerabilities.Security: pip SBOM false positives on the plugin images (urllib3, msgpack)CVE-2026-97687 / 97689 (urllib3 2.7.0), CVE-2026-57585 and GHSA-6v7p-g79w-8964 (msgpack 1.1.2) are reported against the plugin daemon (local) and plugin build base images. The scanner reads a stale SBOM (
pip/_vendor/bom.cdx.json) shipped in Chainguard's py3.x-pip-26.2.1-r2 package. The vendored code actually shipped is urllib3 2.8.0 and msgpack 1.2.1. Chainguard has since published py3.x-pip-26.2.1-r3 with a corrected SBOM. The sandbox image already uses it, so these findings are gone there, and the plugin images will pick it up in a follow-up release. Until then, these advisories are covered by pip-vendored.openvex.json.Security: setuptools finding is not exploitableCVE-2025-47273 (path traversal in setuptools 70.3.0) is reported against the sandbox, plugin daemon (local) and plugin build base images, also from the pip SBOM. pip only vendors
pkg_resources, so setuptools.package_index, where the issue lives, is not present in the image. This is covered by pip-vendored.openvex.json.Security: block-buffer bundled in uv on the plugin images is not exploitableThe plugin daemon (local) and plugin build base images still need
uv at runtime to install plugin dependencies (Wolfi package uv-0.12.24-r0). The block-buffer 0.10.4 statement (sonatype-2026-003895, GHSA-qwgh-2vcv-g2f7) is kept for these images: uv is built with panic = "abort", so the caught-panic precondition of the advisory cannot occur. This is covered by uv-vendored.openvex.json.Security: advisories without an upstream fixCVE-2026-81726 (path traversal in
nltk ≤ 3.10.3) still has no fixed release upstream and is still reported against the API image. It will be picked up as soon as a fixed release is available.Upgrade Guide
Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Review the manifest changes before applying:
helm diff upgrade dify dify-ee/dify --version 3.9.14 -f values.yaml (helm-diff plugin), or render with helm template dify dify-ee/dify --version 3.9.14 -f values.yaml and compare it against helm get manifest difyZero-downtime rolling upgrade supported
Upgrade Command
# Back up the database and review the manifest diff first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.14
Rollback
$ helm rollback dify 0
Security & CVE
Security vulnerabilities found in this release.0 Critical · 22 High CVE across all container images
Image
critical
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
low
0
10
7
11
0
11
4
4
4
7
10
9
13
6
7
6
0
Status
FAIL
PASS
PASS
PASS
PASS
PASS
FAIL
FAIL
FAIL
PASS
PASS
PASS
FAIL
PASS
PASS
FAIL
PASS
ScannerDocker Scout
Scanned
Oct 09, 2026
Data Source
Docker
CVEs for the opt-in
api-insecure image is excluded from the CVE table above.VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
Benchmark Report
TTFE – Time To First Event (ms)
AVG
161.1
MIN
128
MAX
548
P50
148
P90
174
P95
189
Connections
Max Concurrent
18
Avg Active
17.27
Empty Workflow QPS
Max QPS
38
Avg QPS
36.1
Avg Duration (ms)
178.54
License Compliance
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0