Signals

2026-07-01 / OpenHands

OpenHands shipped its dependency-CVE fixes on the cloud channel; the OSS 1.8.0 line is frozen and a new CVE already sits untagged on main

Edited by Michael Ruescher

What this changes for operators

  • Last window's unreleased dependency-CVE batch reached tags this window -- but only on the CLOUD channel: cloud-1.39.0 (2026-06-24, ~16-item CVE/dependency batch) and cloud-1.40.0 (2026-06-26, a 4-item CVE/GHSA batch). The OSS line got NO new tag; the newest non-cloud release is still 1.8.0 (2026-06-10).
  • It is worse than merged-vs-shipped: it is now cloud-vs-self-host. A managed OpenHands Cloud tenant is patched; a self-hoster on the 1.8.0 tag is not, with no fixed OSS tag to move to. And a fresh authlib CVE (CVE-2026-44681 -- an unauthenticated open redirect in Authlib's OIDC grant, CWE-601, phishing-grade at CVSS 6.1; commit e6fe505) already sits on main after cloud-1.40.0 -- untagged again.
  • Determine your channel and act on it: on Cloud, you are covered; on the OSS 1.8.0 tag, you are unpatched for this batch and must either run a build from main (inheriting all its churn) or wait for an OSS tag that has not come for three windows.

Signal metadata

Source findings

Featured in

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-openhands-cve-fixes-cloud-only-oss-frozen

Research evidence and publication history are open in the repository.