Skip to content

snipe-it

v8.6.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

asset-management asset-manager assets-management itam license-management

Affected surfaces

auth

Summary

AI summary

Requires PHP 8.2+ (8.4 recommended) and fixes LDAP STARTTLS failures.

Full changelog

[!CAUTION]
This version of Snipe-IT REQUIRES PHP 8.2.0 or greater, 8.4+ recommended. PHP 8.2 is still in security release support until 31 Dec 2026, but let's not play that game

This is largely a security release, but also fixes some more niche SCIM/LDAP issues and adds some additional UX love around more confusing and/or dangerous features (such as remote login headers.)

What's Changed

  • Authentication/LDAP - Fixed [FD-56031] - throw Exception if STARTTLS fails by @uberbrady in https://github.com/grokability/snipe-it/pull/19190

Full Changelog: https://github.com/grokability/snipe-it/compare/v8.6.2...v8.6.3

Breaking Changes

  • Minimum PHP version raised to 8.2 (8.4+ recommended)

Security Fixes

  • Fixed FD-56031 – STARTTLS failures now throw an Exception

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track snipe-it

Get notified when new releases ship.

Sign up free

About snipe-it

A free open source IT asset/license management system

All releases →

Related context

Earlier breaking changes

  • v8.6.0 Requires PHP 8.2.0 or greater, recommends PHP 8.4+.
  • v8.5.0 Requires PHP 8.2.0 or greater; PHP 8.1 and earlier no longer supported

Beta — feedback welcome: [email protected]