Skip to main content

Connect 2026.1 Release Notes

Release Notes Product Versions

Version

Date

Release

End of Support

2026.1.1.2 (Connect)

2026.1.1.2 (Loaders)

May 7, 2026

Major

May 7, 2028

2026.1.2.3 (Connect)

2026.1.2.3 (Loaders)

August 19, 2026

Minor/Patch

May 7, 2028

2026.1.3.6 (Connect)

2026.1.3.6 (Connect)

September 30, 2026

Minor/Patch

May 7, 2028

Upgrade Considerations

For best results, we strongly recommend that you download the same version of Server.

New Features

There are currently no new features for this release.

Fixed and Known Issues

Major Release

Version: 2026.1.1.2

There are currently no fixed or known issues for this release.

Patch 3

Version: 2026.1.2.3

Fixed

Major Release Version 2026.1.2.3

ID

Description

Version

Issue Status

TCON-7425

Connect users unable to sign in using Windows authentication and Active Directory Setup in 2025.2, 2026.1.

2026.1.2.3

Fixed

Security Updates

Major Release

Version: 2026.1.1.2

Improved the security of Alteryx Connect by updating several underlying third‑party components to address vulnerabilities identified in internal scans. These updates help ensure Connect continues to run on supported, more secure library versions.

Fixed

Major Release Version 2026.1.1.2

ID

Description

Version

Issue Status

TCON-6497

Upgraded urllib3 python library to 2.6.1 to address BDSA-2025-48097, BDSA-2025-48178, and BDSA-2026-0240.

2026.1.1.2

Fixed

TCON-6524

Upgraded pycparser python library to 2.21 to address CVE-2022-2255.

2026.1.1.2

Fixed

TCON-6727

Upgraded PyJMT python library to 2.11.0 to address BDSA-2025-8013.

2026.1.1.2

Fixed

TCON-6951

Upgraded pyca/cryptography library to 46.0.7 to address BDSA-2026-1856 and BDSA-2026-6691.

2026.1.1.2

Fixed

TCON-6874

Upgraded these python libraries to address CVE-2024-12797:

  • pyasn1/0.6.2

  • protobuf/7.34.0

  • pyopenssl/26.0.0

2026.1.1.2

Fixed

Patch 4

Version: 2026.1.3.6

This patch strengthens Connect’s upload validation, image processing, authentication error handling, response security headers, logout and cache behavior, and hostname protection.

Existing Customers Upgrading

A normal upgrade restores the existing Tomcat configuration. This preserves customer ports, SSL, and authentication settings, but it also means the new hostname protection in the packaged server.xml is not automatically applied.

To enable it, stop the Alteryx Connect service and back up C:\Program Files\AlteryxConnect\conf\server.xml (or the equivalent path for a custom installation). Edit the existing file. Do not replace the whole file, as it may contain customer-specific settings:

  1. In the existing <Engine> opening tag, change only defaultHost to invalid.invalid:

    <Engine name="Catalina" defaultHost="invalid.invalid">
  2. Inside that Engine, before the existing localhost Host, add:

    <Host name="invalid.invalid" appBase="blocked-webapps"
          deployOnStartup="false" autoDeploy="false">
      <Valve className="org.apache.catalina.valves.ErrorReportValve"
             showReport="false" showServerInfo="false" />
    </Host>
  3. Inside the existing <Host name="localhost" ...>, add an alias for each hostname Tomcat receives and add the error-report Valve if it is not already present:

    <Alias>connect.example.com</Alias>
    <Valve className="org.apache.catalina.valves.ErrorReportValve"
           showReport="false" showServerInfo="false" />

    Keep all other existing entries inside that Host. Add the alias as a real XML element—not inside a comment. Use only the hostname, not https://, a port, or a path.

  4. Separately, to match the new packaged HTTPS-redirect configuration, add transportGuaranteeRedirectStatus="308" to the existing LockOutRealm opening tag, retaining its other settings:

    <Realm className="org.apache.catalina.realm.LockOutRealm"
           transportGuaranteeRedirectStatus="308">

    This setting does not, by itself, turn an HTTP-only installation into an HTTPS installation.

Save the file and restart the service. Without steps 1–3, an upgraded installation should continue to operate, but the new Tomcat hostname protection will not be active. Step 4 applies the separate HTTPS-redirect setting included in this patch.

New Customers Installing This Patch

A fresh installation already contains the new Tomcat protection. Before users access Connect through a DNS name, stop the service and add that name inside the localhost Host in C:\Program Files\AlteryxConnect\conf\server.xml:

<Alias>connect.example.com</Alias>

Restart the service. Without the alias, localhost access works, but requests using the unconfigured hostname may return 404. Do not change defaultHost back to localhost.

Reverse-Proxy or Load-Balancer Deployments

Configure an alias for the hostname that the proxy sends to Tomcat. If the proxy replaces the public hostname with an internal one, add the internal hostname as an alias too.

If the immediate proxy connects to Tomcat from a non-local IP address, add that IP to the existing [global] section of C:\Program Files\AlteryxConnect\ac_work\alteryx_connect.properties. For example, if Tomcat sees the proxy as 10.20.30.40:

connect.trusted-proxies=127[.]0[.]0[.]1|::1|0:0:0:0:0:0:0:1|10[.]20[.]30[.]40

Replace 10.20.30.40 with the actual proxy IP; retain the loopback entries. This setting accepts an IP-matching regular expression, not a DNS hostname or an end-user IP. Direct-access installations, or proxies connecting from loopback, need no change. If a non-local proxy is not configured, valid logins can still succeed, but auditing and IP-based login controls may identify multiple users by the shared proxy IP.

Behavior Changes to Expect
  • New attachment and diagram uploads may be rejected if they exceed the configured limit or have an unsupported, mismatched, or unsafe file type. Existing stored files are not bulk-modified.

  • Newly saved images are processed to remove metadata. Unusual images may be rejected or appear slightly different.

  • Failed-login messages disclose less information.

  • Attachment downloads are no longer intended to remain in the browser cache for one year, so repeated downloads may use more network traffic.

  • HTTP installations remain supported; the patch does not require a new SSL certificate.

Fixed

Minor Release Version 2026.1.3.6

ID

Description

Version

Issue Status

TCON-7708

Issues while performing WAPT Testing for Alteryx Connect.

2026.1.3.6

Fixed