GovCMS Lagoon Update to 11.3.5 & 10.5.7

Scheduled Maintenance Report for GovCMS

Update

Lagoon Update to 11.3.5 & 10.5.7 are complete for production sites.

Deployments on D11 non-prods are also complete and are now commencing on D10 non-prod sites.
Posted Jun 03, 2026 - 16:23 AEST

In progress

Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Jun 03, 2026 - 09:41 AEST

Scheduled

Who is affected: All GovCMS community

Advice:
- On Tuesday 2 June 2026, GovCMS released new GOVCMS_IMAGE_VERSION that includes the latest Lagoon base images in releases 11.3.5 & 10.5.7
- It addresses the following security vulnerabilities:

CVE-2026-9256 (https://nvd.nist.gov/vuln/detail/CVE-2026-9256)
CVE-2026-42945 (https://nvd.nist.gov/vuln/detail/CVE-2026-42945)

PaaS Actions Required:
❗ IMPORTANT: You must redeploy your environments and ensure they are running the
latest release, 11.3.5 OR 10.5.7.

- IF the project pins to a specific release via environment variable (e.g in the project .env file or configured Lagoon environment variables) then ensure these values are updated to 11.x-latest or 11.3.5 OR 10.x-latest or 10.5.7 and trigger a redeployment. (https://hub.docker.com/r/govcms/govcms/tags)
- IF the values above are already 11.x-latest OR 10.x-latest then you only need to redeploy to ensure you are running the latest release.
- IF your codebase is referencing the release tag in some alternate way, or referencing the Lagoon images directly, then you will need to make changes as appropriate. Just ensure you are using Lagoon-images
26.5.1. (https://github.com/uselagoon/lagoon-images/releases/tag/26.5.1)

SaaS Actions Required:
- There is no action for SaaS projects.
- A lagoon release does not create any configuration management actions required

More Information
If you have any concerns, raise a ticket at https://www.govcms.support
Posted Jun 03, 2026 - 09:40 AEST
This scheduled maintenance affects: GovCMS Projects (Individual websites).