Skip to content

Openmeetings

Communication & Email

A self‑hosted video conferencing and collaboration platform

Java Latest 9.1.0 · 12d ago Security brief →

Features

  • Video conferencing
  • Instant messaging
  • Whiteboard support
  • Collaborative document editing
  • Groupware tooling

Recent releases

View all 2 releases →
Upgrade now
9.1.0 Breaking risk
RCE / SSRF

CVE-2026-49488 fix

8.1.0 Security relevant
Security fixes
  • CVE-2025-7962 — SMTP Injection vulnerability fixed by sanitizing \r and \n UTF-8 characters.
Full changelog

Release 8.1.0, provides following improvements:

Security:

  • All libraries are updated to most recent versions

WB:

  • Whiteboard video player controls are fixed

Some other fixes and improvements, 9 issues were addressed

=====================================
IMPORTANT!
Apache OpenMeetings prior to 8.1.0 are vulnerable to CVE-2025-7962 [1]

"SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages."

The issue was found by b1u3r and 1ue

All users should upgrade to OM 8.1.0 ASAP!

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
684
Forks
263
Languages
Java HTML JavaScript

Community & Support

Beta — feedback welcome: [email protected]