Release Notes

Follow new updates and improvements to Speechmatics.

September 4th, 2026

Version 15.19.0 is now available for Batch Container, Realtime Container, GPU Transcription Inference Container and GPU Translation Inference Container.

New

GPU & CPU

  • Disfluency detection and removal now supports 16 additional languages: Arabic, Danish, Dutch, French, German, Greek, Hebrew, Hindi, Hungarian, Italian, Japanese, Mandarin, Polish, Portuguese, Russian, Spanish. See the documentation for more details.

  • Realtime transcript messages (AddTranscript, AddPartialTranscript, and EndOfUtterance) now include a forced flag, allowing clients to identify transcripts generated by a forced end of utterance.

GPU

  • New sm-gpu-inference-server-all-lang image is now available and supports all languages for both Standard and Enhanced models. See the documentation for more details.

  • New SM_LANGUAGES environment variable on the inference server entrypoint. Set it to a comma-separated list of language codes (e.g. SM_LANGUAGES=en,de,fr) to load only that subset of the image's baked-in language models at startup, instead of all of them. When unset, all languages are loaded (unchanged behaviour). An unknown language code fails startup with an error.

Improvements

GPU & CPU

  • Improved accuracy (reduced deletions at end of utterance) when using ForceEndOfUtterance, with specific values of max_delay.

  • Reduced latency between a client-triggered ForceEndOfUtterance and final transcripts arriving.

Fixes

GPU & CPU

  • Japanese smart formatting no longer fails on decimal money amounts (e.g. 十二 点 三 兆 円), which were previously left spelled out instead of being formatted as 12.3兆円.

  • remove_disfluencies no longer leaves orphan punctuation (for example a dangling . or ,) where filler words were removed.

Security fixes

Vulnerability Management

  • Software Bill of Materials (SBOM) is available for download from the corresponding release page in our Support Portal.

  • OpenVEX statements are also available for each image, download from the corresponding release page in our Support Portal. These encode our assessment of CVEs that don't affect this release.

  • The following components were updated across 15.15.0–15.19.0 to address known vulnerabilities:

    • ffmpeg updated to 9.0.1 (CVE-2026-8461, CVE-2026-66041)

    • gstreamer updated to 1.28.6 (CVE-2026-3083, CVE-2025-2759, CVE-2026-3085, CVE-2025-3887)

    • libc6 and libc-bin updated to 2.39-0ubuntu8.8

    • python-multipart updated to 0.0.31

    • pyOpenSSL updated to 26.4.0, resolving cryptography to 50.0.0 (CVE-2026-69247, CVE-2026-69249)

    • sh (Python package) updated (CVE-2026-54552)

    • transformers updated to 5.5.0 (CVE-2026-4372, CVE-2026-5241), with regex updated to 2025.10.22

    • wheel and setuptools removed from the inference server (CVE-2026-24049, CVE-2024-6345, CVE-2025-47273)

    • cuda-compat-13-0 updated to 580.159.03-1ubuntu1

    • Debian packages libnss3, libgcrypt20, libcurl3t64-gnutls and libnghttp2-14 updated

  • The CVEs identified against the Triton Inference Server in the GPU Transcription Inference and GPU Translation Inference images (CVE-2026-47627, CVE-2026-47628, and CVE-2026-47629) are tracked as known issues and will be addressed by a Triton upgrade in a future release.

How to read these tables. Each row is keyed by the package a scanner attributes the advisory to. That attribution comes from the distribution's own security tracker rather than from the advisory's subject, so where an advisory concerns a component bundled by a different project, the tracker may attribute it to a package this image does ship even though the vulnerable component itself is not present. Scanner coverage also differs: not every row below is reported by every tool.

Patched, but still reported by scanners

The following vulnerabilities are fixed in the versions this release ships. Scanners that identify a package by the distribution's own records will continue to report them, because those records track the distribution's package version rather than the version installed here.

Container

Components

Identified CVEs

Reason

Transcriber (Batch, Realtime) — batch-asr-transcriber

ffmpeg

44 CVEs — see the OpenVEX file for this image

Fixed upstream in the version this image ships (9.0.1), which is ahead of the distribution's package. Scanners report the distribution's version.

Transcriber (Batch, Realtime) — batch-asr-transcriber

gstreamer, gstreamer1.0-plugins-good, gstreamer1.0-plugins-ugly, libgstreamer1.0-0

15 CVEs — see the OpenVEX file for this image

Fixed upstream in the version this image ships (1.28.6), which is ahead of the distribution's package. Scanners report the distribution's version.

Transcriber (Batch, Realtime) — batch-asr-transcriber

gstreamer

CVE-2025-3887

Fixed in the Speechmatics build (1.28.6-sm-1400305). The distribution has not released a fix, so scanners continue to report its own package version.

Non-Applicable CVEs

The following vulnerabilities were reviewed and determined to have no security impact for this release.

These assessments assume the inference server APIs are reachable only from Speechmatics transcriber containers within your deployment. If you expose them to other clients, review the relevant Nvidia security bulletin directly.

Container

Components

Identified CVEs

Reason

Transcriber (Batch, Realtime) — batch-asr-transcriber

ffmpeg, libacl1, libcairo-gobject2, libcairo2, libcurl3t64-gnutls, libcurl4t64, libelf1t64, libexpat1, libgcrypt20, libglib2.0-0t64, libharfbuzz0b, libp11-kit0, libperl5.38t64, libpipewire-0.3-0t64, libpython3.12-minimal, libpython3.12-stdlib, libslang2, libsndfile1, libspa-0.2-modules, libssh-4, libssl3t64, libtag1v5, libtag1v5-vanilla, libtiff6, libvo-amrwbenc0, libx264-164, openssl, perl, perl-base, perl-modules-5.38, python3-pip, python3.12, python3.12-minimal, requests, setuptools, zipp

65 CVEs — see the OpenVEX file for this image

The affected code is not used at runtime.

Transcriber (Batch, Realtime) — batch-asr-transcriber

libexpat1, libpython3.12-minimal, libpython3.12-stdlib, python3.12, python3.12-minimal

CVE-2026-4739, CVE-2026-67422

The component the advisory covers is not present in this image.

GPU Transcription Inference — sm-gpu-inference-server

binutils, binutils-common, binutils-x86-64-linux-gnu, gir1.2-glib-2.0, libacl1, libaom3, libattr1, libbinutils, libctf-nobfd0, libctf0, libcurl3t64-gnutls, libexpat1, libgcrypt20, libglib2.0-0t64, libglib2.0-data, libgprofng0, libheif-plugin-aomdec, libheif-plugin-aomenc, libheif1, libp11-kit0, libperl5.38t64, libpython3.12-minimal, libpython3.12-stdlib, libpython3.12t64, libsframe1, libssh-4, libssl3t64, libtiff6, openssl, patch, perl, perl-base, perl-modules-5.38, python3.12, python3.12-minimal

75 CVEs — see the OpenVEX file for this image

The affected code is not used at runtime.

GPU Transcription Inference — sm-gpu-inference-server

libpython3.12-minimal, libpython3.12-stdlib, libpython3.12t64, python3.12, python3.12-minimal

CVE-2026-67422

The component the advisory covers is not present in this image.

GPU Transcription Inference — sm-gpu-inference-server

triton_inference_server

CVE-2026-47606, CVE-2026-47627

Path-traversal surface on the Triton HTTP/gRPC API. The API is not exposed beyond the trust boundary and its only client is the trusted transcriber in the same trust domain.

GPU Transcription Inference — sm-gpu-inference-server

triton_inference_server

CVE-2026-47628, CVE-2026-47629

Request-handling denial of service on the Triton HTTP/gRPC API, reachable only from the trusted transcriber; container restarts recover the service.

GPU Transcription Inference — sm-gpu-inference-server

triton_inference_server

CVE-2026-47630

Vector is local and requires an existing privileged account inside the container, which runs only the entrypoint and the tritonserver process.

GPU Translation Inference — sm-translation-inference-server

binutils, binutils-common, binutils-x86-64-linux-gnu, gir1.2-glib-2.0, libacl1, libaom3, libattr1, libbinutils, libctf-nobfd0, libctf0, libcurl3t64-gnutls, libexpat1, libgcrypt20, libglib2.0-0t64, libglib2.0-data, libgprofng0, libheif-plugin-aomdec, libheif-plugin-aomenc, libheif1, libp11-kit0, libperl5.38t64, libpython3.12-minimal, libpython3.12-stdlib, libpython3.12t64, libsframe1, libssh-4, libssl3t64, libtiff6, openssl, patch, perl, perl-base, perl-modules-5.38, python3.12, python3.12-minimal, zlib1g

74 CVEs — see the OpenVEX file for this image

The affected code is not used at runtime.

GPU Translation Inference — sm-translation-inference-server

libpython3.12-minimal, libpython3.12-stdlib, libpython3.12t64, libssh-4, python3.12, python3.12-minimal

CVE-2026-11972, CVE-2026-15308, CVE-2026-59851

The affected code is not present in the version shipped.

GPU Translation Inference — sm-translation-inference-server

triton_inference_server

CVE-2026-47606, CVE-2026-47627

The path-traversal surface is the model-control API. The image starts tritonserver in the default model-control mode, in which load, unload and repository-control requests return an error, and the API is reachable only from the trusted transcriber.

GPU Translation Inference — sm-translation-inference-server

triton_inference_server

CVE-2026-47628, CVE-2026-47629

Denial of service through the Triton inference API, reachable only from the trusted transcriber; container restarts recover the service.

GPU Translation Inference — sm-translation-inference-server

triton_inference_server

CVE-2026-47630

Requires local, already-privileged access inside the container. The container runs tritonserver as its only process and exposes no local shell to an untrusted principal.

Reviewed, no upstream fix available

The following vulnerabilities were reviewed and do apply to this release, with no fix released upstream at the time of writing. They are tracked and will be taken up when a fix becomes available.

Container

Component

Identified CVEs

Transcriber (Batch, Realtime) — batch-asr-transcriber

glib-networking

CVE-2026-10028

Transcriber (Batch, Realtime) — batch-asr-transcriber

glib-networking-common

CVE-2026-10028

Transcriber (Batch, Realtime) — batch-asr-transcriber

glib-networking-services

CVE-2026-10028

Transcriber (Batch, Realtime) — batch-asr-transcriber

gstreamer1.0-plugins-good

CVE-2026-17072

Transcriber (Batch, Realtime) — batch-asr-transcriber

libaom3

CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211

Transcriber (Batch, Realtime) — batch-asr-transcriber

libcairo-gobject2

CVE-2018-18064

Transcriber (Batch, Realtime) — batch-asr-transcriber

libcairo2

CVE-2018-18064

Transcriber (Batch, Realtime) — batch-asr-transcriber

libfaad2

CVE-2019-5459, CVE-2023-38857, CVE-2023-38858

Transcriber (Batch, Realtime) — batch-asr-transcriber

libfluidsynth3

CVE-2025-56225, CVE-2025-68617, CVE-2026-58264, CVE-2026-61714, CVE-2026-61720, CVE-2026-61721, CVE-2026-61722, CVE-2026-61723

Transcriber (Batch, Realtime) — batch-asr-transcriber

libopenexr-3-1-30

CVE-2021-45942, CVE-2023-5841, CVE-2024-31047, CVE-2025-12495, CVE-2025-12839, CVE-2026-27622, CVE-2026-34380, CVE-2026-34588

Transcriber (Batch, Realtime) — batch-asr-transcriber

libopenh264-7

CVE-2025-27091

Transcriber (Batch, Realtime) — batch-asr-transcriber

libopenjp2-7

CVE-2019-6988, CVE-2023-39328, CVE-2023-39329

Transcriber (Batch, Realtime) — batch-asr-transcriber

libpixman-1-0

CVE-2023-37769

Transcriber (Batch, Realtime) — batch-asr-transcriber

libsoup-3.0-0

CVE-2025-4035, CVE-2025-9901, CVE-2025-14523, CVE-2025-32049, CVE-2026-0716, CVE-2026-0719, CVE-2026-1761, CVE-2026-2369, CVE-2026-2436, CVE-2026-3099, CVE-2026-3632, CVE-2026-3633, CVE-2026-3634, CVE-2026-4271, CVE-2026-5119, CVE-2026-15709, CVE-2026-15711, CVE-2026-66338

Transcriber (Batch, Realtime) — batch-asr-transcriber

libsoup-3.0-common

CVE-2025-4035, CVE-2025-9901, CVE-2025-14523, CVE-2025-32049, CVE-2026-0716, CVE-2026-0719, CVE-2026-1761, CVE-2026-2369, CVE-2026-2436, CVE-2026-3099, CVE-2026-3632, CVE-2026-3633, CVE-2026-3634, CVE-2026-4271, CVE-2026-5119, CVE-2026-15709, CVE-2026-15711, CVE-2026-66338

Transcriber (Batch, Realtime) — batch-asr-transcriber

libwavpack1

CVE-2021-44269, CVE-2022-2476

Not every finding a scanner reports is listed individually above; the aggregated low-severity tail and a small number of findings still under review are not. The OpenVEX documents attached to each release are the authoritative per-CVE record.

September 3rd, 2026

Batch SaaS

Improvements

Updated Melia 1 model for multilingual transcription provides:

  • 2% relative WER improvement across many languages

  • Substantially fewer transliteration errors on Hindi-English audio

  • Better handling of Hindi-English code-switching within a single sentence

  • More accurate transcription of consecutive alphanumerics, such as repeated letters and digits

Updated Orchestrator Version:2026.07.31+f3542ffa97+1.5.0

August 20th, 2026

Realtime SaaS

Improvements

Reduced the mean and P95 latency between client-triggered ForceEndOfUtterance and when final transcripts arrive.

Updated Orchestrator Version: 2026.08.17+8225ca39de+15.19.0

August 7th, 2026

Batch SaaS

Improvements

The default behaviour for polling GET /jobs/{jobid} and GET /jobs/{jobid}/transcript endpoints is changing so that requests can wait for up to 2 seconds for a job to complete before returning. This reduces the need for frequent client-side polling and can improve turnaround time for users.

This behaviour can be disabled by sending wait=0 to return immediately. Client-side polling can be avoided for most jobs by using Synchronous transcription.

August 6th, 2026

Realtime SaaS

Fixes

Fixed recently introduced issue with remove_disfluencies, where punctuation around disfluencies was not being removed. Disfluency tagging (and removal) is currently unavailable for Finnish (fi), Norwegian (no) and Swedish (sv), after being added on Jul 29, 2027.

Bug introduced in release version: 2026.07.29

Updated Orchestrator Version: 2026.08.05+3c8ca0561c+15.18.0

August 6th, 2026

Batch SaaS

Fixes

Fixed recently introduced issue with remove_disfluencies, where punctuation around disfluencies was not being removed. Disfluency tagging (and removal) is currently unavailable for Finnish (fi), Norwegian (no) and Swedish (sv), after being added on Jul 28, 2027.

Bug introduced in release version: 2026.07.28

Updated Orchestrator Version: 2026.08.05+3c8ca0561c+15.18.0

August 3rd, 2026

Batch SaaS

Improvements

Updated Melia 1 model for multilingual transcription provides:

  • Improved transcription accuracy (WER reduced by 2% relative overall)

  • Improved alphanumerics, with output now more closely matching written form

Updated Orchestrator Version: 2026.07.31+f3542ffa97+1.5.0

July 29th, 2026

Realtime SaaS

New

Disfluency detection and removal now supports 19 additional languages, including Arabic, Danish, Dutch, Finnish, French, German, Greek, Hebrew, Hindi, Hungarian, Italian, Japanese, Mandarin, Norwegian, Polish, Portuguese, Russian, Spanish, and Swedish. See the documentation for more details.

Updated Orchestrator Version: 2026.07.24+b3c1e3bbc5+15.17.0

July 28th, 2026

Batch SaaS

New

Disfluency detection and removal now supports 19 additional languages, including Arabic, Danish, Dutch, Finnish, French, German, Greek, Hebrew, Hindi, Hungarian, Italian, Japanese, Mandarin, Norwegian, Polish, Portuguese, Russian, Spanish, and Swedish. See the documentation for more details.

Updated Orchestrator Version: 2026.07.24+b3c1e3bbc5+15.17.0

July 20th, 2026

Realtime SaaS

New

A new global endpoint is now available at global.rt.speechmatics.com. This address automatically routes connections to the nearest region, providing the lowest latency and eliminating the need to hard-code specific regional endpoints into your applications.

Regional endpoints such as eu.rt.speechmatics.com and us.rt.speechmatics.com remain available for customers with specific data residency requirements.

Refer to the Realtime transcription documentation for full details.