Skip to main content

v3.9.9

LTS
Released Jul 29, 2026·Supported until Dec 31, 2026·Community 1.13.x·Community commit 82365d0·Enterprise 0.16.x·Helm chart·Docker Compose
Breaking
None
Security
Clean
Changes
0F · 4B
Downtime
Zero

Upgrade Impact

0 features · 4 fixes
Non-breaking:Security fixes and bug fixes. No breaking changes.

What Changed

4
Bug Fixes
Annotation Reply: remove 0.8 score threshold lower boundRemoved the arbitrary 0.8 lower-bound UI limit on the Annotation Reply score threshold, so the value can now be configured across the full 0.00–1.00 range as intended.
Datasource: API-key modal hidden behind settings panelFixed an incorrect z-index on the datasource API-key modal that caused it to be obscured by the settings panel. The modal now renders correctly above the panel.
Security Fixes
Security: SSRF bypass in API tool schema fetchThe API tool schema fetch endpoint used raw httpx.get() instead of ssrf_proxy.get(), bypassing the Squid SSRF proxy and allowing authenticated users to reach internal URLs (cloud metadata, Redis, Postgres). All fetches now route through the SSRF proxy. (GHSA-gfmc-xc6g-q7g2)
Security: CVE remediationRemediated one high-severity CVE (CVE-2026-40898) and two medium-severity CVEs (CVE-2026-6993, CVE-2026-41178) affecting the plugin-daemon, gateway, enterprise, and enterprise-audit images. See the Security CVE section below for detailed scan results.

Upgrade Guide

Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
Confirm Kubernetes cluster has sufficient resources for rolling update
Zero-downtime rolling upgrade supported
Upgrade Command

# Back up database first, then:

$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.9

Rollback

$ helm rollback dify 0

Security & CVE

Full CVE report →
Security vulnerabilities found in this release.0 Critical · 0 High CVE across all container images
ScannerDocker Scout
Scanned
Jul 29, 2026
Data Source
Docker
CVEs for the opt-in api-insecure image is excluded from the CVE table above.
TTFE – Time To First Event (ms)
AVG
158.14
MIN
121
MAX
531
P50
141
P90
159.6
P95
189.8
Connections
Max Concurrent
12
Avg Active
10.7
Empty Workflow QPS
Max QPS
26.2
Avg QPS
25.02
Avg Duration (ms)
243.44

License Compliance

Full license report →
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.