Skip to content

fix(pgadmin): bump to 9.16 (chart 1.65.0) for critical CVE RCE fixes#264

Open
othillo wants to merge 1 commit into
developer-overheid-nl:mainfrom
othillo:fix/pgadmin-9.16-cve-rce
Open

fix(pgadmin): bump to 9.16 (chart 1.65.0) for critical CVE RCE fixes#264
othillo wants to merge 1 commit into
developer-overheid-nl:mainfrom
othillo:fix/pgadmin-9.16-cve-rce

Conversation

@othillo

@othillo othillo commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the runix pgadmin4 chart from 1.29.0 to 1.65.0 in apps/auth/base/pgadmin.yaml, moving pgAdmin from appVersion 8.11 to 9.16.

Patches:

⚠️ Requires human review before merge. This is a large chart jump (1.29.0 → 1.65.0) that reflects the pgAdmin 8 → 9 major upgrade. A human must review the chart values-schema and pgAdmin 9 breaking changes (config/DB/storage migration, deprecated values keys) before merging — this PR only changes the pinned chart version and does not adjust any values.

Scope: single change in the shared base; affects both tn-don-auth-prod and tn-don-auth-test. Kustomize builds validated for both overlays (rendered HelmRelease shows version: 1.65.0).

Bumps the runix pgadmin4 chart 1.29.0 -> 1.65.0, which ships pgAdmin
appVersion 8.11 -> 9.16, patching CVE-2026-12046 (unauthenticated pickle
deserialization RCE, CVSS 9.5) plus CVE-2025-2945 and CVE-2025-12762.
Affects both prod and test overlays via the shared base.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant