This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Summary
AI summaryCVE-2025-7962 SMTP injection vulnerability fixed in OpenMeetings 8.1.0.
Full changelog
Release 8.1.0, provides following improvements:
Security:
- All libraries are updated to most recent versions
WB:
- Whiteboard video player controls are fixed
Some other fixes and improvements, 9 issues were addressed
=====================================
IMPORTANT!
Apache OpenMeetings prior to 8.1.0 are vulnerable to CVE-2025-7962 [1]
"SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages."
The issue was found by b1u3r and 1ue
All users should upgrade to OM 8.1.0 ASAP!
Security Fixes
- CVE-2025-7962 — SMTP Injection vulnerability fixed by sanitizing \r and \n UTF-8 characters.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Openmeetings
Video conferencing, instant messaging, whiteboard, collaborative document editing and other groupware tools using API functions of the Red5 Streaming Server for Remoting and Streaming.
Beta — feedback welcome: [email protected]