This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 version 9.1.0 patches CVE-2026-49488 to stop arbitrary file reads and now mandates Java 21 plus KMS 7.3.0 or newer.
Why it matters: CVE‑2026‑49488 (severity 90) enables unauthorized file access; upgrade to 9.1.0 is required if using the WB download service, and deployments must run Java 21 with KMS 7.3.0+.
Summary
AI summaryCVE-2026-49488 fixes an arbitrary file read vulnerability.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches CVE-2026-49488 preventing arbitrary file read. Patches CVE-2026-49488 preventing arbitrary file read. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | Medium |
Adds more security checks in WB download service. Adds more security checks in WB download service. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Security | Low |
Protects default git branches from unauthorized access. Protects default git branches from unauthorized access. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Breaking | High |
Requires Java 21 and KMS 7.3.0+ for operation. Requires Java 21 and KMS 7.3.0+ for operation. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Dependency | Low |
Updates all libraries to their most recent versions. Updates all libraries to their most recent versions. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
Full changelog
Release 9.1.0, provides following improvements:
IMPORTANT: Java 21 and KMS 7.3.0+ are required
Security:
- More security checks in WB download service
- Default git branches are protected
- All libraries are updated to most recent versions
Vulnerabilities:
- CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Some other fixes and improvements, 5 issues were addressed
All users should upgrade to OM 9.1.0 ASAP!
Breaking Changes
- Java 21 and KMS 7.3.0+ are now required runtime dependencies
Security Fixes
- CVE-2026-49488 — Apache OpenMeetings: Arbitrary File Read
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Openmeetings
Video conferencing, instant messaging, whiteboard, collaborative document editing and other groupware tools using API functions of the Red5 Streaming Server for Remoting and Streaming.
Beta — feedback welcome: [email protected]