# June 2026 monthly release

**URL:** https://meta.discourse.org/t/june-2026-monthly-release/406435
**Category:** Announcements
**Tags:** release-notes
**Created:** [June 30, 2026, 2:34pm UTC](https://meta.discourse.org/t/june-2026-monthly-release/406435 "2026-06-30T14:34:28Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![loic](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/loic/32/105621_2.png) [@loic](https://meta.discourse.org/u/loic)
#### Post date: [June 30, 2026, 2:34pm UTC](https://meta.discourse.org/t/june-2026-monthly-release/406435/1 "2026-06-30T14:34:28Z")

</div>

For more information on all the changes released in 2026.6, check out:

> **[v2026.6.0 Changelog | Discourse Releases](https://releases.discourse.org/changelog/v2026.6.0/)**
>
> Featured changes and detailed commit history for Discourse 'v2026.6.0'.

Patch releases for other supported versions have also been released:

- [v2026.1.5 Changelog | Discourse Releases](https://releases.discourse.org/changelog/v2026.1.5)
- [v2026.4.2 Changelog | Discourse Releases](https://releases.discourse.org/changelog/v2026.4.2)
- [v2026.5.1 Changelog | Discourse Releases](https://releases.discourse.org/changelog/v2026.5.1)

---

<div class="post-metadata">

### Author: ![elmuerte](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elmuerte/32/456517_2.png) [@elmuerte](https://meta.discourse.org/u/elmuerte)
#### Post date: [July 2, 2026, 5:58am UTC](https://meta.discourse.org/t/june-2026-monthly-release/406435/2 "2026-07-02T05:58:03Z")

</div>

The mentioned CVEs in the security fixes do not appear to be related toe Discourse.

Take for example this one:

> CVE-2026-46413 Regular users can route multipart uploads into the admin backup store

Which links to this GHSA entry: [Regular users can route multipart uploads into the admin backup store · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7)

But CVE-2026-46413 is about an issue in BUFFALO Wi-Fi router: [NVD - CVE-2025-46413](https://nvd.nist.gov/vuln/detail/CVE-2025-46413)

> CVE-2026-49256 Hidden tag names leaked via category serializers

GHSA entry: [Hidden tag names leaked via category serializers · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-mwp7-572g-6qpx)

But CVE-2026-49256 is about an bug in PillarJS’ path-to-regexp: [NVD - CVE-2026-4926](https://nvd.nist.gov/vuln/detail/CVE-2026-4926)

Which is used by Discourse, but the bug talks about something on the Ruby side.

> CVE-2026-44787 Signup-time primary\_group\_id assignment grants whisperer access

GHSA entry: [Signup-time primary\_group\_id assignment grants whisperer access · Advisory · discourse/discourse · GitHub](https://github.com/discourse/discourse/security/advisories/GHSA-vmwq-jvxx-jwfx)

But CVE-2026-44787 is about Apache APISIX: [NVD - CVE-2026-44087](https://nvd.nist.gov/vuln/detail/CVE-2026-44087)

---

<div class="post-metadata">

### Author: ![loic](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/loic/32/105621_2.png) [@loic](https://meta.discourse.org/u/loic)
#### Post date: [July 2, 2026, 8:19am UTC](https://meta.discourse.org/t/june-2026-monthly-release/406435/3 "2026-07-02T08:19:16Z")

</div>

Your links are actually all wrong (they’re pointing to different numbers). I guess our CVEs are not propagated yet?

---

<div class="post-metadata">

### Author: ![elmuerte](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elmuerte/32/456517_2.png) [@elmuerte](https://meta.discourse.org/u/elmuerte)
#### Post date: [July 2, 2026, 4:41pm UTC](https://meta.discourse.org/t/june-2026-monthly-release/406435/4 "2026-07-02T16:41:02Z")

</div>

oh ffs… useless google search. My bad, I could have sworn searching like that used to work. (And I probably needed a bit more coffee)
