What's Changed
- GHSA-6jpj-522x-53vv Arbitrary class loading and instantiation via the entitlement applications REST endpoint, thanks @manus-use @Buggs777 @tsujiguchitky @maximthomas ❤️
- GHSA-573r-mwh6-jw8j Arbitrary class loading and instantiation via policy import (incomplete fix for CVE-2026-63468), thanks @manus-use @maximthomas @tsujiguchitky ❤️
- GHSA-qcqm-7432-wg7r Unauthenticated federation-management operations via Liberty ID-FF endpoints, thanks *@manus-use @maximthomas @tsujiguchitky ❤️
- GHSA-hmwh-9r8r-44gw Delegated session-destroy privilege is not scoped to the realm of the session being destroyed, thanks @arpitjain099 @maximthomas @tsujiguchitky ❤️
- GHSA-6f8c-crwq-jqm3 End-session endpoint accepts an unverified id_token_hint, enabling redirects to any client's registered post-logout URI, thanks @rockmelodies @santhreal @maximthomas @tsujiguchitky ❤️
- GHSA-mw38-8gr7-c4x2 Anonymous forgot-password and self-registration REST actions send attacker-worded email from the server's own address, thanks @santhreal @maximthomas @tsujiguchitky ❤️
- GHSA-v796-mg6j-9c5m Unencoded values in the SAML auto-submit page of the load-balancer cookie bounce (not reachable in released versions), thanks @santhreal @maximthomas @tsujiguchitky ❤️
- GHSA-wxmx-q96f-w4gw Unauthenticated arbitrary class instantiation via the legacy JAX-RPC remote SDK interface, thanks @manus-use @alex-sc @maximthomas @tsujiguchitky ❤️
- GHSA-3m32-w9x3-vvq8 Reflected XSS on the OAuth2 authorization error page, thanks @Buggs777 @tsujiguchitky @maximthomas ❤️
- GHSA-xq25-2x9w-94w9 Incomplete SSRF protection for server-fetched URLs (bypass of the CVE-2026-63467 and CVE-2026-63484 fixes), thanks @tonghuaroot @tsujiguchitky @maximthomas ❤️
- GHSA-g7cv-hh35-cc7c SSRF and unbounded server-side fetch via the OpenID Connect client jwks_uri, thanks @arpitjain099 @rockmelodies @santhreal @alex-sc @jamesbishup @ayhambashtawi2-lang @maximthomas @tsujiguchitky ❤️
- GHSA-5p2f-7vcr-6vfh PKCE enforcement does not cover OAuth 2.0 hybrid flows (residual of CVE-2026-48717), thanks @arpitjain099 @maximthomas @tsujiguchitky ❤️
- GHSA-x8cj-3hqv-cgwh Session query REST endpoint lets a realm administrator list the sessions of every realm, thanks @maximthomas @tsujiguchitky ❤️
- CVE-2026-13149 CVE-2026-33750 CVE-2026-33750 CVE-2026-45149 brace-expansion: DoS protection by @dependabot[bot] in #1073
- CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption by @dependabot[bot] in #1074
- CVE-2026-59879 Immutable.js
List32-bit trie overflow → unrecoverable DoS by @dependabot[bot] in #1076 - CVE-2026-13676 CVE-2026-16221 fast-uri vulnerable to host confusion via literal backslash authority delimiter by @dependabot[bot] in #1077
- CVE-2026-59887 linkify-it: Quadratic-complexity DoS via the
mailto:validator scan-loop on attacker text by @dependabot[bot] in #1078 - CVE-2026-53666 CVE-2026-53669 React Router: Arbitrary Constructor Injection via deserializeErrors() Open redirect via backslash in and useNavigate by @dependabot[bot] in #1079
- CVE-2026-59949 at.yawk.lz4:lz4-java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges by @dependabot[bot] in #1085
- GHSA-qwww-vcr4-c8h2 React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response by @dependabot[bot] in #1087
- GHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure by @dependabot[bot] in #1086
- [#1082] Fix docs contradicting each other on XUI + HttpOnly session cookies by @maximthomas in #1084
- [#1080] OAuth2 consent: accept the resource owner's session id as the csrf value by @maximthomas in #1083
- Harden AuthXMLRequest.setPrincipal against arbitrary class instantiation (same pattern as GHSA-wg5r-wc3x-39vc) by @BarakSrour in #1088
- CVE-2026-69185 CVE-2026-33151 Socket.IO: Zero-attachment Memory Exhaustion + unbounded number of binary attachments by @dependabot[bot] in #1095
- CVE-2026-18446 fast-uri vulnerable to host confusion via backslash authority introducer by @vharseko in #1098
- CVE-2026-13149 CVE-2026-14257 CVE-2026-69152 brace-expansion: DoS via unbounded expansion by @vharseko in #1099
- CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption by @vharseko in #1100
- CVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elements by @dependabot[bot] in #1105
- [#1103] Add upgrade step syncing missing ScriptingService sub-configurations by @vharseko in #1104
- GHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution by @dependabot[bot] in #1106
- CVE-2026-75899 CVE-2026-75931 CVE-2026-75975 CVE-2026-76172 GHSA-qw65-cvwx-89v3 GHSA-58mr-gqgx-xq4g fast-uri: SSRF and host confusion (3.1.5 -> 3.1.7) by @vharseko in #1118
- CVE-2026-73088 CVE-2026-73089 browserslist: Prototype write via untrusted custom stats and unbounded cache growth (-> 4.28.9) by @vharseko in #1123
- [#1111] Click fork: stop calling javax.servlet-bound upstream ClickUtils by @maximthomas in #1112
- CVE-2026-43871 GHSA-8wv5-x4w7-5gww libthrift: Infinite loop in Apache Thrift Java bindings (0.23.0 -> 0.24.0) by @dependabot[bot] in #1115
- GHSA-p498-v437-472g @humanfs/node: Recursive copy follows symlinks and copies files from outside the source tree by @dependabot[bot] in #1119
- CVE-2026-84373 vitest: Path traversal / arbitrary file read via @vitest/mocker redirect mocks (4.1.0 -> 4.1.11) by @dependabot[bot] in #1124
- CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources (4.3.1 -> 4.3.2) by @dependabot[bot] in #1125
- [#1114] Fix precompile-jsps profile for the Jakarta EE 9 webapp by @vharseko in #1120
- SetupUtils: pass chmod arguments to Runtime.exec as an array by @vharseko in #1126
- Escape reflected request parameters in the sample servlets by @vharseko in #1129
- Do not log session ids, access tokens and password attributes by @vharseko in #1127
- CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources in openam-ui-api (4.3.1 -> 4.3.2) by @vharseko in #1132
- [#1130] Verify client assertions by their own alg; default id_token_signed_response_alg by @vharseko in #1131
- Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target by @vharseko in #1128
New Contributors
- @BarakSrour made their first contribution in #1088
Full Changelog: 16.1.2...16.1.3
Backers
Thank you to all our backers! Become a backer 🙏
Sponsors
Support this project by becoming a sponsor. Your logo will show up here with a link to your website. Become a sponsor ❤️