Fixed issues
Citrix SecurSpaces™ 2026.9 includes the following fixed issues
| Release Date | Version | Category | Description |
|---|---|---|---|
| October 06, 2026 | 2026.9.4 | New features | Added support for upgrading internal Percona MongoDB deployments from Percona Operator 1.20.1 to 1.23.0 with an installer-provided upgrade kit. The updated chart also exposes Percona backup configuration for storage targets, schedules, retention, point-in-time recovery, and the database service account used by backup agents. |
| New features | Added support for keyless Google Cloud Storage backups for internal Percona MongoDB on Google Kubernetes Engine using Workload Identity Federation. | ||
| Security | Updated the workspace sidecar image base packages and containerd to address high-severity vulnerabilities. | ||
| Security | Updated the NetScaler CPX ingress controller chart from 4.1.17 to 4.2.26 to address known ingress controller vulnerabilities. | ||
| September 29, 2026 | 2026.9.3 | New features | Added support for stable specification_id values in Citrix SecurSpaces Flex managed tier definitions. A managed tier version can now keep the same identifier across tenants when Citrix pins the value in deployment values. |
| General | Resolved an issue where successful Citrix SecurSpaces Flex managed tier availability changes and bulk tier-version updates were missing from the audit log. The audit log now records who performed the action, when it happened, and the result. | ||
| General | Resolved an issue where the outbound SSH guidance shown in workspaces pointed to the previous documentation URL. The guidance now opens the current SecurSpaces external services documentation. | ||
| September 28, 2026 | 2026.9.2 | New features | Added Citrix SecurSpaces Flex support for Citrix-managed workspace specification tiers, including managed tier versions, lifecycle labels, workspace update prompts, and bulk tier-version updates. |
| New features | Added REST API support for managing VSCode versions at platform, organization, and project scope. The API can list, import, rename, delete, and set defaults for versions, and manage platform-level VSCode registries. | ||
| General | Resolved an issue where Helm upgrades with the internal Percona MongoDB deployment could regenerate database passwords and leave platform services unable to authenticate. Server-side upgrades now reuse existing passwords unless an operator sets a new value, and credential changes roll the services that consume them. | ||
| General | Resolved an issue where a workspace could stay on an old sidecar image after a platform upgrade without showing an update prompt. Workspaces now show an update when the stored sidecar image differs from the version shipped by the deployment. | ||
| General | Resolved an issue where project People > More details could open the wrong user details route or show the wrong organization in breadcrumbs. The project user details flow now keeps the project and organization context aligned. | ||
| General | Resolved an issue where release service images could have different manifest digests depending on the regional registry used. Future release images now use consistent compressed layers across release regions. | ||
| General | Resolved an issue where concurrent Kubernetes updates could cause workspace start, restart, or edit operations to fail with a StatefulSet conflict. StatefulSet updates now retry on conflicts. | ||
| September 21, 2026 | 2026.9.1 | General | Resolved an issue where a workspace stopped for exceeding its memory limit reported Reason: Unknown and advised updating the workspace image. The failure is now reported as OOMKilled, with memory-specific guidance. |
| General | Resolved an issue where SCIM provisioning stored a user’s email address as both the given name and the family name. name.givenName and name.familyName now map to the user’s name. |
||
| General | Resolved an issue where marketplace extensions preconfigured in a workspace template were not installed. | ||
| General | Resolved an issue where a searchable multi-select list cleared the search text while the user was typing. | ||
| General | Updated the default workspace image to 2.3.9. |
||
| August 13, 2026 | 2026.9.0 | Security | Updated dependencies and images to address known vulnerabilities. |
| Security | Resolved an issue where some role-protected API requests could bypass access checks. | ||
| Security | Resolved an issue where some flows could accept the wrong token type. | ||
| Security | Resolved an issue where user-management actions could affect users outside the caller’s scope. | ||
| Security | Resolved an issue where local secrets could be copied without verifying container ownership. | ||
| Security | Resolved an issue where sidecar file streaming could expose unintended workspace files. | ||
| Security | Resolved an issue where sidecar Git handling could accept unsafe command arguments. | ||
| Security | Resolved an issue where workspace Docker access was broader than required. | ||
| Security | Resolved an issue where the image builder ran with more privilege than required. It now uses rootless BuildKit. | ||
| Security | Removed test license keys from production images. | ||
| Security | Rotated credentials that had been committed to the repository, and added operator recovery guidance. | ||
| Security | Hardened the AWS Mount Point lifecycle, including attach, update, and delete. | ||
| Security | Hardened mount point handling: storage classes without TLS are hidden, deletion from the recycle bin is blocked, and error messages no longer disclose internal detail. | ||
| Security | Hardened the documentation served from the control plane at /docs/. |
||
| New features | Added AWS Mount Point support for Amazon EFS and Amazon S3 Files storage. | ||
| New features | Added a redesigned IDE extension sidebar with repositories, mount points, and workspace apps. | ||
| New features | Added connection quality monitoring in the IDE status bar. | ||
| New features | Added user, project, and workspace metadata on AI requests forwarded to an AI Gateway. | ||
| New features | Added AI Gateway health checking with a configurable fail-open behavior. | ||
| New features | Added a sample Grafana dashboard for AI usage and token consumption reporting. | ||
| New features | Added desired state configuration tracking of the template version used by each workspace. | ||
| New features | Added template version status indicators and an Associated Workspaces window with CSV export. | ||
| New features | Added a workspace update flow that aligns a workspace with the default template version. | ||
| New features | Added archive and restore for workspace templates that still have associated workspaces. | ||
| New features | Added dot files in Profile > Configuration for personal workspace setup. | ||
| New features | Added a Setup Checklist on project pages for guided onboarding. | ||
| New features | Added deleted workspace recovery during the configured retention period. | ||
| New features | Added Helm support for applying a platform license during deploy or upgrade. | ||
| New features | Added HAProxy ingress support and optional cert-manager Certificate rendering. | ||
| New features | Added GitHub Copilot support for workspaces behind an AI Gateway. | ||
| General | Updated the product interface and email templates to use the Citrix SecurSpaces product name. | ||
| General | Resolved an issue where data bucket uploads could start from ineligible workspaces. | ||
| General | Resolved an issue where data bucket upload status could be misleading. | ||
| General | Resolved an issue where the data bucket upload modal could show stale bucket data. | ||
| General | Resolved an issue where image import could use the wrong credential or image URL. | ||
| General | Resolved an issue where a failed image import could become the default image tag. | ||
| General | Resolved an issue where workspaces could start with the wrong container image tag. | ||
| General | Resolved an issue where reused image tags could leave stale workspace image content. | ||
| General | Resolved an issue where VSCode version settings could be lost in workspace flows. | ||
| General | Resolved an issue where a private VSCode registry URL could remain stale. | ||
| General | Resolved an issue where signed Git operations could fail with commit.gpgsign=true. |
||
| General | Resolved an issue where workspace startup could stall during system startup scripts. | ||
| General | Resolved an issue where workspaces could stay in Pending because of storage settings. |
||
| General | Resolved an issue where a stale sidecar IPC socket could cause CrashLoopBackOff. |
||
| General | Resolved an issue where workspace schedules with a 00:00 start time did not save. |
||
| General | Resolved an issue where manual Run actions were not counted as activity. | ||
| General | Resolved an issue where Profile page SSH addresses could omit the workspace region. | ||
| General | Resolved an issue where organization role checks did not apply to protected pages. | ||
| General | Resolved an issue where disabled role references could disrupt project loading. | ||
| General | Resolved an issue where the Disable Role modal showed -1 instead of a placeholder. |
||
| General | Resolved an issue where Connect to GitHub did not start OAuth for new users. | ||
| General | Resolved an issue where workspace template version drafts could sort unpredictably. | ||
| General | Resolved an issue where create-from-existing showed incorrect specification values. | ||
| General | Resolved an issue where HTTP and SSH connected service selections did not persist. | ||
| General | Resolved an issue where workspace specification template restrictions could be lost. | ||
| General | Resolved an issue where workspace update actions appeared when no update was available. | ||
| General | Resolved an issue where template lifecycle actions could leave orphaned workspace state. | ||
| General | Resolved an issue where Add to Favorite stayed open after selection. | ||
| General | Resolved an issue where the audit page Select All filter option did not apply. | ||
| General | Resolved an issue where AI dashboard token totals were inconsistent. | ||
| General | Resolved an issue where AI traffic from SSH workspaces lacked observability metadata. | ||
| General | Resolved an issue where 1-click demo deployment could fail in common retry scenarios. | ||
| General | Resolved an issue where read-only AWS mount points could not be mounted. | ||
| General | Resolved an issue where Azure Files mount points had several defects affecting attach and update. | ||
| General | Resolved an issue where a workspace could briefly report a DESTROYED state while it was being created. |
||
| General | Resolved an issue where the workspace wizard could become stuck after Discard. | ||
| General | Resolved an issue where editing a workspace specification did not reach running workspaces, pods, and templates. | ||
| General | Resolved an issue where replacing a specification template could write outside its intended scope. | ||
| General | Resolved an issue where Community Edition license activation could fail. | ||
| General | Resolved an issue where the Insights resource usage chart showed gaps, unstable colors, and an inaccurate tooltip. | ||
| General | Resolved an issue where updating workspace properties could cause a backend error. | ||
| General | Resolved an issue where the workspace update dialog showed the wrong state for a template version. | ||
| General | Resolved an issue where authorizing an SSH key did not list workspaces the user owns without the manage permission. | ||
| General | Resolved an issue where invalid repositories were included in the duplicate path check. | ||
| General | Resolved an issue where searching for users responded slowly. | ||
| General | Resolved an issue where image build logs could not be streamed. | ||
| General | Resolved an issue where image builds could fail when the cluster used an external proxy. | ||
| General | Resolved an issue where the platform did not recover promptly after losing its leader election lock. |
Citrix SecurSpaces 2026.4 includes the following fixed issues
| Release Date | Version | Category | Description |
|---|---|---|---|
| August 24, 2026 | 2026.4.10 | Security | Updated Helm chart security contexts to disallow privilege escalation for platform service containers and the syslog permissions init container. |
| General | Resolved an issue where SCIM user responses did not include group membership and SCIM group list responses omitted members unless a specific group was requested. /Users now returns direct group membership and /Groups list responses include members. |
||
| August 14, 2026 | 2026.4.9 | New features | Added HAProxy ingress support. |
| General | Resolved an issue where project creation could fail after the Project Owner role was disabled. | ||
| General | Resolved an issue where Azure 1-click demo deployment could fail and leave incomplete network rules. | ||
| General | Resolved an issue where NetScaler ingress could fail on Google Cloud. | ||
| General | Resolved an issue where Google Kubernetes Engine 1.35 probes could time out too quickly. | ||
| July 20, 2026 | 2026.4.8 | Security | Updated dependencies and images to address known vulnerabilities. |
| New features | Added REST API support for managing workspace template Quickstart links. | ||
| New features | Added REST API support for Custom Access Items on workspaces and templates. | ||
| General | Resolved an issue where template REST API responses omitted setup scripts. | ||
| General | Resolved an issue where VSCode registry records could be missed or left stale. | ||
| July 2, 2026 | 2026.4.7 | Security | Updated dependencies to address known vulnerabilities. |
| New features | Added SecurSpaces documentation served from the control plane at /docs/ for air-gapped deployments. |
||
| New features | Added IDE extension API support for personal workspace endpoints and VSCode version fields. | ||
| General | Resolved signed Git commit failures when commit.gpgsign=true was set. |
||
| General | Resolved JFrog artifact repository access failures for users without a configured token. | ||
| General | Resolved an issue where CPU and memory resource limits could be lost after workspace edit operations. | ||
| General | Resolved an issue where Create Workspace API responses could miss expected fields. | ||
| General | Resolved an issue where attached repositories were missing from personal workspace API responses. | ||
| General | Resolved an issue where IDE extension quick-link sign-in did not redirect to non-project routes. | ||
| June 9, 2026 | 2026.4.6 | Security | Updated the Go runtime and build toolchain to address known vulnerabilities. |
| New features | Added AI Gateway routing support via Helm values for selected AI service domains. | ||
| New features | Added X.509 certificate authentication for SecurSpaces connections to external MongoDB deployments. | ||
| General | Resolved outbound SSH connections closing without explanation when no SSH method was configured. | ||
| General | Resolved an issue where the add icon on the empty home page create card appeared flattened. | ||
| General | Resolved an issue where Pendo in-app guide sessions could continue after logout. | ||
| June 4, 2026 | 2026.4.5 | Security | Resolved JFrog anonymous tokens accepted during OAuth sign-in. |
| General | Resolved a nil panic in the OAuth client secret rotation job when no OAuth application was configured. | ||
| General | Resolved an issue where the auto-delete action used an incorrect workspace last-used time. | ||
| General | Resolved GPU configuration options being hidden for the security officer role in workspace templates. | ||
| New features | Added workspace Docker registry mirror support via workspaceDockerRegistryMirrors Helm value. |
||
| May 29, 2026 | 2026.4.4 | Security | Upgraded Go and Docker toolchain versions to address known vulnerabilities. |
| Security | Updated the MongoDB container image to address known vulnerabilities. | ||
| Security | Bumped the default workspace image to 2.3.6 to address known vulnerabilities. |
||
| General | Resolved an issue where the “update available” icon persisted after a workspace update completed. | ||
| General | Resolved non-deterministic color assignment in Resource Allocation charts. Colors now sort by region. | ||
| General | Resolved an issue where Custom Actions conditions were not applied correctly. | ||
| General | Resolved an issue where the Profile page showed an error on refresh for Developer role users. | ||
| General | Resolved incorrect units for memory and disk when editing resource limits. | ||
| General | Resolved workspace status records not initialized for cloned or template-created workspaces. | ||
| General | Resolved the Advanced dropdown appearing empty for some roles in workspace settings. | ||
| May 12, 2026 | 2026.4.3 | General | Resolved a Kubernetes cluster cost issue caused by warm node pre-provisioning. |
| General | Resolved an image pod caching issue by re-aligning node anti-affinity to kubernetes.io/hostname. |
||
| New features | Added a platform setting to configure a custom upstream URL for the VS Code Extensions Gallery. | ||
| New features | Increased the maximum configurable workspace specification limits for CPU, GPU, memory, and disk. |
SecurSpaces 2025.10 includes the following fixed issues
| Release Date | Version | Category | Description |
|---|---|---|---|
| April 30, 2026 | 2025.10.21 | Security | Resolved an issue where a rejected workspace SSH approval still authorized the presented public key, allowing a later connection with the same key to succeed. SSH keys are now authorized only when the approval request is accepted. |
| Security | Tightened file and directory permissions in the installer. Generated directories, Terraform variable files, and the CA certificate bundle are now created with owner-only access to address Mend SAST findings (CWE-732). | ||
| Security | Updated the MongoDB container image to address known vulnerabilities reported by Mend. | ||
| Security | Bumped the default workspace image to 2.3.6 to address known vulnerabilities. |
||
| General | Resolved slow query performance for ip_pod_assignment and workspaces_v5 collections that could lead to proxy OOMKilled events. Added a compound index on (ip, region_id) for ip_pod_assignment and a team_id index on workspaces_v5. |
||
| General | Resolved a delay when switching to the Workspaces tab in the user interface. | ||
| General | Resolved an issue where the table component did not show its loading state on initial data fetch. | ||
| General | Resolved an issue where the copy-to-clipboard tooltip did not appear on the first hover or copy action. | ||
| General | Resolved an issue where opening a terminal session from the dropdown launched a duplicate window instead of focusing the existing one. | ||
| April 23, 2026 | 2025.10.20 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| Security | Updated the Go language runtime to version 1.25.9 and resolved frontend CVEs reported by Mend. | ||
| General | Resolved an issue where workspace setup scripts were lost when a workspace was created through the REST API. Setup scripts are now preserved on create. | ||
| General | Resolved a UI issue where the workspace access item icon appeared taller than expected. | ||
| April 14, 2026 | 2025.10.19 | General | Resolved an issue where 1-Click VM provisioning failed when targeting an existing Azure Resource Group. |
| April 13, 2026 | 2025.10.18 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| General | Resolved an issue in the OAuth2 authentication flow where email addresses containing uppercase letters caused authentication failures or account mismatches. | ||
| April 1, 2026 | 2025.10.17 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| March 30, 2026 | 2025.10.16 | General | Resolved a critical CosmosDB index error that caused backend upgrade failures. This fix ensures that database schema updates and indexing operations complete successfully during platform deployments, preventing service disruptions during the upgrade cycle. |
| General | Added GPU-accelerated workspaces with hardware acceleration for machine learning, data science, and graphics-intensive workloads. | ||
| March 17, 2026 | 2025.10.15 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| March 9, 2026 | 2025.10.14 | Networking | Resolved an issue where cross-workspace HTTP access was broken. |
| February 19, 2026 | 2025.10.13 | General | Resolved an issue with Git Large File Storage (LFS) that affected GitLab repositories when using SSH for authentication. |
| February 11, 2026 | 2025.10.12 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| February 11, 2026 | 2025.10.11 | General | Resolved an issue where a misleading error message was generated by the measurement cron job for workspaces with no active pods, such as those in a paused state. |
| January 30, 2026 | 2025.10.10 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| January 28, 2026 | 2025.10.9 | General | Resolved an issue with the VS Code Extensions Gallery that prevented the discovery and installation of extensions. |
| New features | Upgraded the NetScaler Ingress Controller (NetScaler CPX) from version 3.2.22 to 3.3.2. This update provides improved stability and higher performance for ingress traffic management. | ||
| January 23, 2026 | 2025.10.8 | Security | This release includes several vulnerability fixes across the platform’s core services. |
| January 15, 2026 | 2025.10.7 | Security | Refactored the Helm Chart RBAC configuration to enhance the platform’s security posture through least-privilege principles. The previously unified ClusterRole has been split into two specific scopes: Namespace-scoped Role manages workload-specific resources, including pods, jobs, and secrets; Minimal ClusterRole is restricted to essential cluster-wide resources, such as nodes, storage classes, and metrics. |
| December 18, 2025 | 2025.10.6 | General | Fixed a bug in 1-click VM environments using OAuth integration that prevented local IDEs from successfully connecting via SSH extensions and plugins. This resolution ensures that developers can use local IDE tools, such as VS Code Desktop or JetBrains Gateway, within the authenticated workspace session. |
| December 15, 2025 | 2025.10.5 | General | Added support for F5 NGINX annotations. Platform administrators can enable dedicated controller support with platform.useF5NginxController: true. |
| Security | Updated the Go language runtime to version 1.25.5, which addresses known security vulnerabilities. | ||
| December 2, 2025 | 2025.10.4 | General | Fixed a permission issue that prevented users with the security officer role from disabling analytics features on the platform configuration settings page. |
| General | Resolved an issue causing the Workspace API component to enter a CrashLoopBackOff state when the system was managing a large number of active or decommissioned workspaces. | ||
| New features | Added a new configuration option to disable Amazon EKS auto-mode detection during cluster setup. Administrators can set region.clusterConfig.disableAutoModeCheck: true for more granular control in specific deployment environments. |
||
| New features | Introduced Terraform support for managing user groups, allowing administrators to provision, update, and manage workspace user groups using Infrastructure as Code practices. | ||
| November 26, 2025 | 2025.10.3 | General | Fixed an issue where some Visual Studio Code dependencies failed due to an underlying C standard library requirement. The minimum required glibc version is now 2.28 to ensure stability and compatibility with remote VS Code functionality on supported Linux distributions. |
| Security | Updated the Go language runtime to version 1.25.4, which addresses known security vulnerabilities. | ||
| November 21, 2025 | 2025.10.2 | General | Resolved slow database migration performance. An optimization to the database migration engine significantly reduces the time required to run database updates during product rollouts and version upgrades. |
| November 14, 2025 | 2025.10.1 | General | Removed the dependency on the C standard library (libc). The core workspace components no longer require libc at runtime. |
Copied!
Failed!