Heroku-22 and Heroku-24 stacks updated

Change effective on 06 May 2026

We updated the heroku-22 and heroku-24 stacks to pick up security fixes in upstream packages. The new base images for each stack roll out automatically to the Common Runtime over the next 48 hours, followed by Private Spaces.

If you use Heroku’s default buildpack-powered build system/stacks, you don’t need to redeploy your app to include these changes. We automatically restart any running dynos as we roll out the new base images for each stack. For Cedar-generation apps, each time a dyno starts, the slug applies on top of the most recent base image. For Fir-generation apps, the built image gets rebased on top of the most recent base image.

If your app uses Heroku’s container stack (most don’t), you must rebuild your app’s Docker image to pick up updates in the base image specified in your Dockerfile.

See this Dev Center article for an overview of the packages available in each stack’s base image.

Changelog of packages

Stack: heroku-22

  • Updated curl from version 7.81.0-1ubuntu1.23 to 7.81.0-1ubuntu1.24
  • Updated iproute2 from version 5.15.0-1ubuntu2 to 5.15.0-1ubuntu2.1
  • Updated jq from version 1.6-2.1ubuntu3.1 to 1.6-2.1ubuntu3.2
  • Updated libcurl3-gnutls from version 7.81.0-1ubuntu1.23 to 7.81.0-1ubuntu1.24
  • Updated libcurl4 from version 7.81.0-1ubuntu1.23 to 7.81.0-1ubuntu1.24
  • Updated libjq1 from version 1.6-2.1ubuntu3.1 to 1.6-2.1ubuntu3.2
  • Updated libkmod2 from version 29-1ubuntu1 to 29-1ubuntu1.1
  • Updated liblcms2-2 from version 2.12~rc1-2build2 to 2.12~rc1-2ubuntu0.1
  • Updated libnghttp2-14 from version 1.43.0-1ubuntu0.2 to 1.43.0-1ubuntu0.3
  • Updated linux-libc-dev from version 5.15.0-176.186 to 5.15.0-177.187
  • Updated openssh-client from version 1:8.9p1-3ubuntu0.14 to 1:8.9p1-3ubuntu0.15
  • Updated openssh-server from version 1:8.9p1-3ubuntu0.14 to 1:8.9p1-3ubuntu0.15
  • Updated openssh-sftp-server from version 1:8.9p1-3ubuntu0.14 to 1:8.9p1-3ubuntu0.15
  • Updated sed from version 4.8-1ubuntu2 to 4.8-1ubuntu2.1

Updates to packages available at build time only

  • Updated libcurl4-openssl-dev from version 7.81.0-1ubuntu1.23 to 7.81.0-1ubuntu1.24
  • Updated libkmod-dev from version 29-1ubuntu1 to 29-1ubuntu1.1
  • Updated liblcms2-dev from version 2.12~rc1-2build2 to 2.12~rc1-2ubuntu0.1

Stack: heroku-24

  • Updated curl from version 8.5.0-2ubuntu10.8 to 8.5.0-2ubuntu10.9
  • Updated iproute2 from version 6.1.0-1ubuntu6.2 to 6.1.0-1ubuntu6.3
  • Updated jq from version 1.7.1-3ubuntu0.24.04.1 to 1.7.1-3ubuntu0.24.04.2
  • Updated libcurl3t64-gnutls from version 8.5.0-2ubuntu10.8 to 8.5.0-2ubuntu10.9
  • Updated libcurl4t64 from version 8.5.0-2ubuntu10.8 to 8.5.0-2ubuntu10.9
  • Updated libjq1 from version 1.7.1-3ubuntu0.24.04.1 to 1.7.1-3ubuntu0.24.04.2
  • Updated liblcms2-2 from version 2.14-2build1 to 2.14-2ubuntu0.1
  • Updated libnghttp2-14 from version 1.59.0-1ubuntu0.2 to 1.59.0-1ubuntu0.3
  • Updated openssh-client from version 1:9.6p1-3ubuntu13.15 to 1:9.6p1-3ubuntu13.16
  • Updated openssh-server from version 1:9.6p1-3ubuntu13.15 to 1:9.6p1-3ubuntu13.16
  • Updated openssh-sftp-server from version 1:9.6p1-3ubuntu13.15 to 1:9.6p1-3ubuntu13.16
  • Updated sed from version 4.9-2build1 to 4.9-2ubuntu0.24.04.1

Updates to packages available at build time only

  • Updated libcurl4-openssl-dev from version 8.5.0-2ubuntu10.8 to 8.5.0-2ubuntu10.9
  • Updated liblcms2-dev from version 2.14-2build1 to 2.14-2ubuntu0.1
  • Updated linux-libc-dev from version 6.8.0-110.110 to 6.8.0-111.111
  • Updated python3-mako from version 1.3.2-1 to 1.3.2-1ubuntu0.1