Releases: Blazemeter/jmeter-http-plugin
Release list
3.2.0
BlazeMeter HTTP v3.2.0
Networking & protocol enhancements release focused on stronger HTTP/2 (h2c) support, DNS integration, authentication improvements, and more robust connection/timing behavior.
Highlights
- Full DNSCacheManager support for JMeter-aligned DNS handling
- BASIC_DIGEST authentication support
- Configurable source address for outgoing connections
- Improved HTTP/2 cleartext (h2c) support, including POST requests and fallback to HTTP/1.1
- Better visibility into the connection handshake process
- Timing fixes and collection of in-flight requests when a Thread Group duration ends
Key Improvements
- Protocol robustness: Stronger h2c negotiation, ALPN handling (fallback to HTTP/1.1 when not specified), and POST support over HTTP/2 cleartext
- JMeter parity: DNSCacheManager integration, BASIC_DIGEST auth, and source-address binding for outgoing connections
- Reliability: Fixed subsample timeout doubling, sampler timing issues, and proper collection of in-flight requests at Thread Group end
- Enhanced connection handshake observability
What's Changed (v3.2.0)
- Fixed an issue when reaching timeout in subsample setting double time… by @diego-ferrand in #154
- Add support for DNSCacheManager by @3dgiordano in #158
- Add BASIC_DIGEST support by @3dgiordano in #159
- Support source address for outgoing connections by @3dgiordano in #160
- Enhance visibility of connection handshake process by @3dgiordano in #161
- Use HTTP/1.1 when ALPN protocol is not specified by @3dgiordano in #162
- Implement HTTP/2 support for h2c POST requests by @3dgiordano in #164
- Fix timing issues in samplers by @3dgiordano in #165
- Add H2C fallback to HTTP/1.1 support by @3dgiordano in #166
- Collect in-flight requests on Thread Group duration end by @3dgiordano in #167
- Release 3.2.0 by @3dgiordano in #163
Thanks to the users @Pill30 and @heysarthak for all the feedback provided.
These changes further improve protocol compatibility, connection control, and overall reliability while maintaining strong alignment with JMeter.
Recommended for all users. This release strengthens HTTP/2 handling, DNS support, and connection robustness.
Enjoy the new version! 🚀
Full Changelog: v3.1.0...v3.2.0
3.1.0
BlazeMeter HTTP v3.1.0
Compatibility & parity release focused on deeper JMeter alignment, improved SSL/HTTP handling, and a new migration tool.
Highlights
- Stronger SSL KeyStore / TrustStore support with graceful failure handling
- Full HEAD method support and improved User-Agent handling
- New headless CLI migration tool to convert stock JMeter HTTP samplers → BlazeMeter HTTP
- Better HTTP/2 cleartext (h2c) negotiation + fallback
- RFC 9110–aligned redirection behavior
- Lazy loading of HTTP response parsers and improved performance
Key Improvements
- JMeter parity: Many behaviors now match stock JMeter more closely (headers, keep-alive, cookies, multipart, redirects, embedded resources, cached resources, etc.)
- Robustness: Better exception handling, connection management, deflate/zlib decoding, and post-redirect header handling
- Developer experience: Migration CLI tool + improved controlled execution / thread drop-off
- Dependency updates (Jetty 12.1.11, commons-lang3, AssertJ, Guava) and various stability fixes
What's Changed (v3.1.0)
- Improvements and alignment to JMeter for SSL KeyStore and TrustStore support by @3dgiordano in #112
- Gracefully handle keystore load failures and reinitialize SSLManager by @3dgiordano in #115
- Preserve pre-decoding headers by @3dgiordano in #107
- Preserve connection keep-alive for JMeter compatibility by @3dgiordano in #116
- Handle HPACK errors and set dynamic response header size by @3dgiordano in #114
- Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.18.0 by @dependabot in #104
- Update Jetty version from 12.1.6 to 12.1.7 by @3dgiordano in #119
- Bump org.assertj:assertj-core from 3.12.2 to 3.27.7 by @dependabot in #105
- Bump guava from 29.0-jre to 32.0.0-jre by @dependabot in #52
- Allow 401 status without requiring HTTP authentication by @3dgiordano in #120
- Add user agent when default_user_agent_disabled is false by @3dgiordano in #123
- Implement support for HEAD HTTP method by @3dgiordano in #122
- Customize HPACK header validation by @3dgiordano in #121
- Delegate cached-resource sample result to JMeter HTTPHC4Impl by @3dgiordano in #125
- Decode both zlib-wrapped and raw deflate content by @3dgiordano in #126
- Fix User-Agent is the last request header by @3dgiordano in #128
- Harden HTTP/2 cleartext (h2c) upgrade negotiation and fallback by @3dgiordano in #127
- Fix exception handling for requests with only Cookie header by @3dgiordano in #129
- Enhance handling of post-redirect request headers and sentBytes by @3dgiordano in #134
- Catch Cookie header without using CookieManager by @3dgiordano in #130
- Fix multipart header casing and raw argument values by @3dgiordano in #133
- Load HTTP response parsers lazily by @3dgiordano in #137
- Support file:// URLs in sampler by @3dgiordano in #136
- Resolve HTTP file arguments in FileServer by @3dgiordano in #135
- Fix Content-Type check and gate request body attachment by @3dgiordano in #132
- Remove duplicate fallback and fix stale body reuse by @3dgiordano in #131
- Map Jetty client failures to HttpClient4 exception types by @3dgiordano in #138
- Add headless CLI tool to migrate stock JMeter HTTP samplers to BlazeMeter HTTP by @3dgiordano in #139
- Set default minimum JMeter version to 5.5 for compatibility tests by @3dgiordano in #140
- Restore original settings on exception by @3dgiordano in #141
- Implement RFC 9110 redirection and update legacy JMeter redirect by @3dgiordano in #142
- Set default maxBufferSize to unlimited with warning and truncation by @3dgiordano in #146
- Improve negotiation logic and embed hanging functionality by @3dgiordano in #148
- Fix flaky test execution by @3dgiordano in #149
- Improve controlled execution thread drop-off by @3dgiordano in #150
- HTTP parity regression by @3dgiordano in #113
- Improvements for timers and preprocessors in the Async Controller by @3dgiordano in #109
- Align Embedded Resource logic with JMeter by @3dgiordano in #151
- Enhance application performance by @3dgiordano in #152
- Release v3.1.0 by @3dgiordano in #143
Security
CVE-2026-2332 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') #119 and #121
CVE-2025-48924 - Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs #104
CVE-2026-24400 - AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion #105
CVE-2023-2976 - Guava vulnerable to insecure use of temporary directory #52
CVE-2020-8908 - Information Disclosure in Guava #52
CVE-2026-10051 - Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections #121
CVE-2026-6790 - Eclipse Jetty: HTTP Authority/Host mismatch #121
CVE-2026-8384 - Use of Non-Canonical URL Paths for Authorization Decisions #121
Thanks to the users @Pill30 and @heysarthak for all the feedback provided.
These changes collectively improve plugin quality, maintainability, and user guidance, while ensuring robust compatibility with current and future JMeter releases.
Recommended for all users. This release significantly improves JMeter compatibility and adds useful migration tooling.
Enjoy the new version! 🚀
Full Changelog: v3.0.1...v3.1.0
v3.0.1
BlazeMeter HTTP v3.0.1
Major release with plugin rename, Jetty 12 upgrade and full modern protocol support.
Highlights
- Plugin renamed to BlazeMeter HTTP
- Upgraded to Jetty 12.1.6 with official support for HTTP/3 + QUIC
- Full protocol support: HTTP/1.x, HTTP/2 and HTTP/3
- Added advanced compression: Brotli, Zstandard and Gzip
- Improved compatibility with JMeter Recorder and BlazeMeter Automatic Correlation Recorder
Key Improvements
- Better scenario modeling: Much more realistic and complex test scenarios are now possible
- Recorder support: Fully compatible with JMeter’s HTTP(S) Test Script Recorder and BlazeMeter’s Automatic Correlation Recorder
- Modernized build system with dependency shading (SLF4J + Jetty) for better isolation
- Updated to Java 17 compilation while keeping Java 8 runtime compatibility for user messages related with Java 17+ requirement.
What's Changed (v3.0.1)
- Brotli cross-platform support has been fixed. Issue: #99 reported by @Pill30
- Duplicate Request Body in HTTP Async Controller fixed when "Generate Parent Sample" is enabled. Issue: #100 reported by @Pill30
- Bootsrap Menu Creator for Java 8+ support (Java 17+ compatibility message for earlier Java versions) by @3dgiordano in PR: #98
Thanks to the users @Pill30 and @heysarthak for all the feedback provided on this latest major release.
Recommended for all users. This is a major upgrade that significantly expands protocol support and recording capabilities.
Enjoy the new version! 🚀
Full Changelog: v3.0.0...v3.0.1
v3.0.0
BlazeMeter HTTP v3.0.0
Major release with plugin rename, Jetty 12 upgrade and full modern protocol support.
Highlights
- Plugin renamed to BlazeMeter HTTP
- Upgraded to Jetty 12.1.6 with official support for HTTP/3 + QUIC
- Full protocol support: HTTP/1.x, HTTP/2 and HTTP/3
- Added advanced compression: Brotli, Zstandard and Gzip
- Improved compatibility with JMeter Recorder and BlazeMeter Automatic Correlation Recorder
Key Improvements
- Better scenario modeling: Much more realistic and complex test scenarios are now possible
- Recorder support: Fully compatible with JMeter’s HTTP(S) Test Script Recorder and BlazeMeter’s Automatic Correlation Recorder
- Modernized build system with dependency shading (SLF4J + Jetty) for better isolation
- Updated to Java 17 compilation while keeping Java 8 runtime compatibility for user messages related with Java 17+ requirement.
Recommended for all users. This is a major upgrade that significantly expands protocol support and recording capabilities.
Enjoy the new version! 🚀
Full Changelog: v2.0.6...v3.0.0
v2.0.6
What's new:
- This release includes the usage of the jmeter-bzm-commons
- A module that enables to reuse logic shared along all BlazeMeter maintained plugins
v2.0.5
v2.0.4
v2.0.3
v2.0.3-alpha.3
Release 2.0.3-alpha.3
v2.0.3-alpha.2
Release 2.0.3-alpha.2