Skip to content

3.1.0

Choose a tag to compare

@github-actions github-actions released this 06 Aug 07:51
· 20 commits to master since this release
9dbda59

BlazeMeter HTTP v3.1.0

Compatibility & parity release focused on deeper JMeter alignment, improved SSL/HTTP handling, and a new migration tool.

Highlights

  • Stronger SSL KeyStore / TrustStore support with graceful failure handling
  • Full HEAD method support and improved User-Agent handling
  • New headless CLI migration tool to convert stock JMeter HTTP samplers → BlazeMeter HTTP
  • Better HTTP/2 cleartext (h2c) negotiation + fallback
  • RFC 9110–aligned redirection behavior
  • Lazy loading of HTTP response parsers and improved performance

Key Improvements

  • JMeter parity: Many behaviors now match stock JMeter more closely (headers, keep-alive, cookies, multipart, redirects, embedded resources, cached resources, etc.)
  • Robustness: Better exception handling, connection management, deflate/zlib decoding, and post-redirect header handling
  • Developer experience: Migration CLI tool + improved controlled execution / thread drop-off
  • Dependency updates (Jetty 12.1.11, commons-lang3, AssertJ, Guava) and various stability fixes

What's Changed (v3.1.0)

Security

CVE-2026-2332 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') #119 and #121
CVE-2025-48924 - Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs #104
CVE-2026-24400 - AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion #105
CVE-2023-2976 - Guava vulnerable to insecure use of temporary directory #52
CVE-2020-8908 - Information Disclosure in Guava #52
CVE-2026-10051 - Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections #121
CVE-2026-6790 - Eclipse Jetty: HTTP Authority/Host mismatch #121
CVE-2026-8384 - Use of Non-Canonical URL Paths for Authorization Decisions #121

Thanks to the users @Pill30 and @heysarthak for all the feedback provided.

These changes collectively improve plugin quality, maintainability, and user guidance, while ensuring robust compatibility with current and future JMeter releases.


Recommended for all users. This release significantly improves JMeter compatibility and adds useful migration tooling.

Enjoy the new version! 🚀

Full Changelog: v3.0.1...v3.1.0