Skip to content

16.1.2

Latest

Choose a tag to compare

@github-actions github-actions released this 20 Jul 10:55

What's Changed

  • CVE-2026-54466 CVE-2026-54490 websocket-driver: Message corruption via abuse of protocol length headers +Resource limit bypass via message compression by @dependabot[bot] in #1072
  • CVE-2026-49982 CVE-2026-53550 JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases by @vharseko in #1060
  • CVE-2026-45736 CVE-2026-48779 ws: Uninitialized memory disclosure +Memory exhaustion DoS by @dependabot[bot] in #1066
  • CVE-2026-45736 CVE-2026-48779 ws: Uninitialized memory disclosure +Memory exhaustion DoS by @dependabot[bot] in #1068
  • CVE-2026-61787 Open Redirect in SAML2/IDFF IDP Discovery Endpoints thanks @mountainousmolehill @Kairos-T @regleyat ❤️
  • CVE-2026-62261 Groovy script sandbox escape leads to authenticated RCE thanks @Mickey777777 ❤️
  • CVE-2026-62263 WebAuthn Java deserialization RCE via ObjectInputFilter depth thanks @Pig-Tail @MarkLee131 @baradika @manus-use @tonghuaroot ❤️
  • CVE-2026-62280 Reflected XSS in the OAuth2/OIDC wap consent page thanks @geo-chen ❤️
  • CVE-2026-62379 Unauthenticated Remote Code Execution via unsafe class instantiation in the /authservice (PLL) endpoint thanks @manus-use ❤️
  • CVE-2026-63463 Unauthenticated stored SSRF in OpenAM (JAXRPC notification registration) thanks @manus-use
  • CVE-2026-63467 SSRF in OIDC dynamic client registration thanks @manus-use ❤️
  • CVE-2026-63488 Pre-authentication LDAP injection (certificate authentication) thanks @manus-use ❤️
  • CVE-2026-63468 Remote code execution via XACML policy import thanks @manus-use ❤️
  • CVE-2026-63487 LDAP injection in entitlement REST API thanks @manus-use ❤️
  • CVE-2026-63485 Pre-authentication SSRF (CRL Distribution Point fetch) thanks @manus-use ❤️
  • CVE-2026-63484 Stored SSRF via entitlement listener registration thanks @manus-use ❤️
  • Add revocation_endpoint to OpenID Connect discovery document by @dairoca90 in #1058
  • Update org.openidentityplatform.opendj to 5.1.2 by @vharseko in #1069
  • Run OpenFM unit tests and fix NotCondition.equals reflexivity by @vharseko in #1071
  • Enable Javadoc doclint (all,-missing) with failOnWarnings on JDK 11 and JDK 26 by @vharseko in #1070
  • Fix Non-resolvable parent POM for org.openidentityplatform.openam:openam-mcp-server:16.0.7-SNAPSHOT by @vharseko in #1054
  • Remove dead jwt-generator tool module by @vharseko in #1057
  • Reduce CI build matrix on macOS and Windows to min/max JDK by @vharseko in #1064
  • Add concurrency groups to CI workflows by @vharseko in #1065
  • Add CodeQL code scanning workflow by @vharseko in #1063
  • Remove obsolete openam-test integration test suite by @vharseko in #1055
  • Add openam-samples modules to the main reactor by @vharseko in #1056

New Contributors

Full Changelog: 16.1.1...16.1.2

Backers

Thank you to all our backers! Become a backer 🙏

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. Become a sponsor ❤️