28,679 Entries 2,229 Sources 5 Verticals Last sync 8 minutes Live
Dashboard/ Self-hosted apps/ Home Assistant Core
Self-hosted apps

Home Assistant Core

Open Home Foundation
2026.6.1 frisch latest release
05.06.2026

frisch — vor < 7 Tagen erschienen · 0 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

17 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 0, 'checked_at': '2026-06-08T02:00:05.783665', 'open_regressions': 0}
gh_etagW/"9dc7dba18f134eda701cd061cc7558725b1ca9fa3c799c02dac865f7ef3760d6"
gh_checked_at2026-06-08T02:15:00.127061+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps Critical

A critical security vulnerability in Home Assistant allowed attackers to bypass authentication and access the Supervisor API. This affected Home Assistant OS and Supervised installations using Supervisor version 2023.03.2 or older.

CVE-2023-27482
05.06.2026
CVE
Self-hosted apps High

A vulnerability in the Home Assistant iOS/macOS app up to version 2023.4 allows attackers to execute arbitrary services on victims' Home Assistant systems through malicious links or QR codes, potentially leading to system compromise.

CVE-2023-44385
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Home Assistant Core allows attackers to send unauthorized requests to internal Supervisor APIs through the hassio.addon_stdin service, potentially leading to remote code execution.

CVE-2023-41899
05.06.2026
CVE
Self-hosted apps High

The Home Assistant Android app up to version 2023.8.2 can load arbitrary URLs in a WebView, allowing attackers to execute malicious JavaScript code and steal user credentials.

CVE-2023-41898
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Home Assistant's GitHub Actions allows attackers to inject commands, potentially stealing secrets and manipulating the repository through the workflow system.

Advisory
05.06.2026
CVE
Self-hosted apps Critical

Home Assistant Core doesn't set HTTP security headers like X-Frame-Options, allowing attackers to use clickjacking attacks to trick users into installing malicious add-ons and gain remote code execution on the system.

CVE-2023-41897
05.06.2026
CVE
Self-hosted apps Critical

A vulnerability in Home Assistant Core allows attackers to create malicious links that force the frontend to connect to a fake WebSocket server, leading to cross-site scripting attacks and complete system takeover.

CVE-2023-41896
05.06.2026
CVE
Self-hosted apps Low

Home Assistant Core has a vulnerability where webhooks can be triggered via public URLs without authentication, even when configured as locally accessible only.

CVE-2023-41894
05.06.2026
CVE
Self-hosted apps Critical

A vulnerability in Home Assistant Core allows attackers to execute malicious JavaScript code through manipulated login redirects, potentially leading to complete takeover of the Home Assistant account and installation.

CVE-2023-41895
05.06.2026
CVE
Self-hosted apps Low

Home Assistant Core has a vulnerability in its login system where attackers can manipulate redirects to steal access credentials if users click on crafted links and their installation is publicly accessible.

CVE-2023-41893
05.06.2026
CVE
Self-hosted apps Medium

Home Assistant Core displays all active user accounts on the login page without requiring authentication when the request originates from the local network.

CVE-2023-50715
05.06.2026
CVE
Self-hosted apps High

Home Assistant Core has a vulnerability in SSL certificate verification that enables man-in-the-middle attacks. Incorrect use of the ssl parameter in HTTP requests unintentionally disables certificate verification, allowing attackers to intercept encrypted connections.

CVE-2025-25305
05.06.2026
CVE
Self-hosted apps High

Home Assistant Core is vulnerable to Cross-Site Scripting attacks when malicious HTML content is inserted into entity names, which then gets executed in the Energy dashboard view when users hover over data points.

CVE-2025-62172
05.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Home Assistant Core allows authenticated users to inject malicious code into device names, which then executes as a Cross-Site Scripting attack against other users when they hover over data points in map dashboards.

CVE-2026-33044
05.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Home Assistant Core allows cross-site scripting attacks through malicious sensor names in history graphs, enabling attackers to execute JavaScript code in other users' sessions and potentially take over accounts.

CVE-2026-33045
05.06.2026
CVE
Self-hosted apps Critical

Home Assistant apps using host network mode incorrectly expose internal Docker interfaces to the local network, allowing attackers to access critical functions like shell access without authentication.

CVE-2026-34205
05.06.2026
CVE
Self-hosted apps High

A security vulnerability in Home Assistant Companion apps for Android and iOS allows malicious websites in embedded frames to steal access tokens from logged-in users, granting full access to their smart home systems.

CVE-2026-44698
05.06.2026
REL
Self-hosted apps Low frisch

Maintenance update with bug fixes for various integrations and dependency updates

2026.6.1
05.06.2026
REL
Self-hosted apps Low frisch

Beta release adding zone-based triggers and conditions for automation, improving media player code quality, updating various dependencies, fixing SwitchBot Blind Tilt errors, preventing log spam, and enhancing error handling across multiple integrations.

2026.6.0b3
03.06.2026
REL
Self-hosted apps Low frisch

Beta release updating intents library to version 2026.6.1, improving WebSocket condition testing by removing error logging, adding Bluetooth reachability diagnostics for Avea devices, and updating the frontend interface to version 20260527.4.

2026.6.0b4
03.06.2026
REL
Self-hosted apps frisch

Unable to analyze release notes as the provided URL appears to be for a future version (2026.6.0) that does not exist yet. No changelog content was accessible to determine changes or breaking modifications.

2026.6.0
03.06.2026
REL
Self-hosted apps Medium bewährt

Beta release containing numerous bug fixes across integrations including MQTT valve state handling, Apple TV streaming issues, backup security improvements, and various sensor/device connectivity problems. Includes dependency updates and minor feature enhancements.

2026.6.0b1
01.06.2026
REL
Self-hosted apps Low bewährt

Beta release containing various bug fixes including media player platform improvements for Alexa devices, proper user-agent for feed fetching, Bluetooth device discovery error explanations, dependency updates, and fixes for ProxmoxVE and iCloud integrations.

2026.6.0b2
01.06.2026
REL
Self-hosted apps bewährt

Beta release announcement for Home Assistant Core 2026.6.0b0 with incomplete release notes, testing instructions, and issue reporting guidelines for the beta period.

2026.6.0b0
27.05.2026
REL
Self-hosted apps Medium bewährt

Patch release fixing multiple crashes and bugs across various integrations including SmartThings, PowerView, Wyoming satellite, Lutron Caseta, and Hue. Updates several dependencies and resolves translation issues. Addresses stability problems that could cause component failures.

2026.5.4
22.05.2026
REL
Self-hosted apps Medium bewährt

Patch release fixing numerous crashes and bugs across multiple integrations including Apple TV, Overkiz covers, utility meters, template conditions, and various device-specific issues. Updates several dependencies and resolves startup blocking problems in Google Assistant and GoodWe integrations.

2026.5.3
19.05.2026
REL
Self-hosted apps Medium bewährt

Patch release containing numerous bug fixes across integrations including LG ThinQ, SmartThings, Comelit, and others. Includes dependency updates and one breaking change in Duco integration that removes temperature sensors and migrates to new connectivity library.

2026.5.2
15.05.2026
REL
Self-hosted apps Low bewährt

Patch release containing bug fixes for multiple integrations including WiZ lights, IntelliFire, Overkiz covers, Z-Wave discovery, and various dependency updates. Fixes connection timeouts, state handling issues, and crash conditions across different device integrations.

2026.5.1
08.05.2026
REL
Self-hosted apps Low bewährt

Beta release adding new automation triggers and conditions for media players, improving error handling for energy data updates, enhancing Matter fan controls, fixing Zinvolt select options, and updating various dependencies including frontend and library components.

2026.5.0b3
06.05.2026
REL
Self-hosted apps Medium bewährt

Beta release removes internal method from EntityConditionBase, excludes incompatible entities from climate/water heater/humidifier automations, improves template entity cleanup, and updates Tibber integration dependency.

2026.5.0b4
06.05.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.5.0) that does not exist yet. No changelog content was accessible to determine changes, breaking compatibility, or severity level.

2026.5.0
06.05.2026
REL
Self-hosted apps Low bewährt

Beta release with various improvements including new media player muted trigger, template reload enhancements, script teardown race condition fix, device class additions for weather sensors, multiple dependency updates, and bug fixes for uptime sensors and config validation across several integratio

2026.5.0b2
05.05.2026
REL
Self-hosted apps Low bewährt

Beta release containing various bug fixes and improvements across multiple integrations including Hive authentication, OpenAI reasoning, Victron GX device mapping, Broadlink infrared support, cover position fixes, sensor corrections, and frontend updates. No breaking changes identified.

2026.5.0b1
04.05.2026
REL
Self-hosted apps bewährt

Beta release announcement for Home Assistant Core 2026.5.0b0 with incomplete release notes, testing instructions, and issue reporting guidelines for the beta period.

2026.5.0b0
29.04.2026
REL
Self-hosted apps Low bewährt

Patch release addressing various integration bugs including Kodi media browsing, Victron BLE authentication issues, Google AI TTS case sensitivity, MQTT light color mode restoration, and API rate limiting improvements for Tractive. Also includes dependency updates and user validation enhancements.

2026.4.4
24.04.2026
REL
Self-hosted apps Low bewährt

Patch release addressing various integration bugs including crashes in Proxmox VE storage monitoring, template binary sensor device class issues, incorrect units in OpenEVSE and Growatt sensors, ESPHome color temperature problems, Wyoming satellite memory leaks, VOIP event loop blocking, and MQTT en

2026.4.3
17.04.2026
REL
Self-hosted apps Low bewährt

Bug fix release addressing various integration issues including meter disconnection handling, state corrections for LG soundbars and FRITZ!Box switches, authentication flow fixes, backup encryption calculations, and dependency updates across multiple integrations.

2026.4.2
11.04.2026
REL
Self-hosted apps Medium Breaking

Patch release containing multiple bug fixes across various integrations including Tuya energy sensors, Ring snapshots, Tesla Fleet OAuth handling, and Sonos media state reporting. Includes one breaking change in SMHI integration and removes Transmission port forward sensor feature.

2026.4.1
03.04.2026
REL
Self-hosted apps bewährt

Beta release with backup storage improvements to use temporary directory and frontend update to version 20260325.5.

2026.4.0b10
01.04.2026
REL
Self-hosted apps Low bewährt

Beta release containing minor fixes and dependency updates including grammar correction for victron_ble error message, Chess.com player stats fetching fix, BMW integration repair skeleton addition, Dropbox integration extraction, and version bumps for multiple libraries including solarlog_cli, led-b

2026.4.0b9
01.04.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.4.0) that does not exist yet, making the changelog inaccessible for review.

2026.4.0
01.04.2026
REL
Self-hosted apps Medium Breaking

Beta release with entity naming changes that may affect automations, new valve conditions and triggers, Z-Wave sensor restructuring, vacation mode support for Econet, battery percentage fixes, OpenAI image generation improvements, and various dependency updates across multiple integrations.

2026.4.0b6
31.03.2026
REL
Self-hosted apps bewährt

Improved translation system performance by implementing asynchronous download functionality for language files.

2026.4.0b7
31.03.2026
REL
Self-hosted apps Low bewährt

Beta release with action naming improvements, bug fixes for nrgkick phase count and ista EcoTrend coordinator, new timer and calendar conditions, counter-specific conditions, platform registration optimizations, and frontend update to version 20260325.4.

2026.4.0b8
31.03.2026
REL
Self-hosted apps Medium Breaking

Beta release with OAuth2 error handling improvements across multiple integrations, dependency updates including aiohttp security fix, Musiccast sound mode correction, Miele washing machine code addition, and MQTT vacuum segments support reversion.

2026.4.0b5
30.03.2026
REL
Self-hosted apps Low bewährt

Beta release adding weather humidity conditions, select conditions, device registry improvements, dependency updates for idasen-ha and aioamazondevices, missing Miele program codes, legacy entity naming, and frontend update to version 20260325.2.

2026.4.0b4
27.03.2026
REL
Self-hosted apps Low bewährt

Beta release adding new automation triggers for humidifier mode changes and battery events, Google Drive backup progress tracking, dependency updates for sense-energy and asyncsleepiq libraries, trigger/condition schema adjustments, and reverting a Z-Wave door sensor repair issue change.

2026.4.0b2
26.03.2026
REL
Self-hosted apps Medium Breaking

Beta release with multiple breaking changes including removal of number entity support from various triggers/conditions, removal of tplink_lte integration, and updates to condition syntax. Also includes dependency updates, translation additions, and new condition types for climate, humidifier, and l

2026.4.0b3
26.03.2026