Skip to content

humhub

v1.18.4 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 5d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

enterprise-social-networks humhub ldap php social-network social-networking
+2 more
social-networks yii2

Affected surfaces

deps rce_ssrf

Summary

AI summary

Fix CVE-2026-46636 sandbox allow‑list bypass in Twig and GHSA vulnerability in JWT library.

Full changelog
  • Enh #8170: Handle controllers with using external modules
  • Enh #8176: Upgrade Twig package to v3.26.0
  • Fix #8189: Scroll to highlighted comment when navigating from Last Activities
  • Enh #8187: Update composer package symfony/mime
  • Fix #8188: AutoContrast and Sign In Footer Links
  • Fix #8193: Fix rendering of the widget AuthChoice
  • Fix #8195: Improve permalink error handling for guest users
  • Fix #8196: Fix whitespace between notification bar items
  • Fix #8205: Fix permission filter alignment
  • Fix #8197: Don't use the setting "Allow individual topics" for user and space tags
  • Fix #8222: Fix filter people page by checkbox list field
  • Enh #8231: Activate a search dialog for CodeMirror fields
  • Enh #8238: Reset OPcache after update a module
  • Enh #8248: Fix updating of space notification state per user after reset for all users
  • Enh #8260: Make form fieldset focusable and expanded via keyboard
  • Fix #8253: Fix Select2 dropdown flickering/closing when it doesn't fit the viewport at browser zoom > 100%
  • Fix #8264: Update Twig to 3.28.0 (GHSA-529h-vh3j-85hq / CVE-2026-46636 - sandbox allow-list bypass on cached templates)
  • Fix #8268: Fix dropdown menu hidden behind topbar when flipped upward
  • Fix #8273: Fix confirm modal getting stuck open forever when closed while still transitioning in
  • Fix #8282: Fix confirm modal closing itself on next open after being closed during its hide transition
  • Enh #8286: Display a success toast when a module is enabled
  • Enh #8300: Update composer package web-token/jwt-library to 4.1.7 (GHSA-3prj-6hqw-cm82, GHSA-jc38-x7x8-2xc8)
  • Fix #8301: Revert missed MobileAppHelper::registerHideOpenerScript()
  • Enh #8307: Add public and standalone file flags for module-managed files (e.g. config images) with explicit access semantics
  • Fix #8324: Fix ActiveFileUpload remove button for standalone files (new standalone widget option)

Security Fixes

  • CVE-2026-46636 — Twig sandbox allow‑list bypass on cached templates (GHSA-529h-vh3j-85hq)
  • dep: GHSA-3prj-6hqw-cm82, GHSA-jc38-x7x8-2xc8 — vulnerabilities in web-token/jwt-library

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track humhub

Get notified when new releases ship.

Sign up free

About humhub

HumHub is an Open Source Enterprise Social Network. Easy to install, intuitive to use and extendable with countless freely available modules.

All releases →

Related context

Beta — feedback welcome: [email protected]