Skip to content

Openfire

Communication & Email

Openfire is an open-source XMPP real‑time collaboration (RTC) server licensed under the Apache License.

Java Latest v5.1.1 · 19d ago Security brief →

Features

  • Provides a robust, standards‑based XMPP messaging platform
  • Easy to set up and administer with strong security guarantees
  • High performance suitable for production deployments

Recent releases

View all 9 releases →
Upgrade now
v5.1.1 Bug fix
Auth RBAC RCE / SSRF +1 more

NullPointer fix + PubSub fixes

Upgrade now
v5.1.0 Breaking risk
Auth Crypto / TLS Dependencies +1 more

SAN limit + MUC avatar + JID fix

Upgrade now
v5.0.5 Breaking risk
Dependencies

User group removal fix

v5.0.4 Bug fix
Notable features
  • Improved error handling on MUC service creation failure
  • BouncyCastle upgraded from 1.78.1 to 1.83
  • Netty upgraded to version 4.1.131
Full changelog

Improvement

  • [OF-3156] - Improve error handling when MUC service creation fails in admin console
  • [OF-3160] - Bump BouncyCastle.version from 1.78.1 to 1.83
  • [OF-3164] - High CPU usage caused by exception-based control flow in UserManager.isRegisteredUser()
  • [OF-3177] - Improve logging when TrustManager initialization fails (exception currently suppressed)
  • [OF-3200] - Improve InMemoryPubSubPersistenceProvider.purgeNode() to target the service cache entry directly instead of scanning all entries

Task

  • [OF-3161] - Upgrade Netty to 4.1.131 version
  • [OF-3162] - Upgrade Apache commons-text from 1.10.0 to 1.15.0
  • [OF-3178] - Update install4j to 12.0.2

Bug

  • [OF-2637] - Admin Console -> Logs viewer. Selecting 'All' lines causes exception
  • [OF-3132] - When obtaining user sessions for bare JID, not all sessions are returned
  • [OF-3165] - Fix incorrect message in closeNeverEncryptedConnection method
  • [OF-3175] - Openfire startup deadlocks during autosetup when encrypted XML properties are processed
  • [OF-3197] - updateSubscription() sets wrong parameter index when deleting a subscription in state none, silently failing to delete the correct row
  • [OF-3198] - LOAD_LAST_ITEMS_LIMIT query returns items in ascending order, causing incorrect results for non-SQL Server, non-Oracle databases
  • [OF-3205] - always update lastPublished when same item is overwritten (XEP-0060 §7.1.2)

sha256sum values for release artifacts

c49add8f50999b2d7fcdd8960bc7d70bf59eb95d12daedf92902e4b034c1c737  openfire-5.0.4-1.noarch.rpm
14d22bef24fb01770f51c655c8b3b54207125b1b70641175d8ad25b585e6332a  openfire_5.0.4_all.deb
ddd40e0bac4c4fae0678b6df4fd5ad28f77af50fd530e3327326f3b488f16ae4  openfire_5_0_4.dmg
8c2fcb27f9afe01b79d59f7bf0736b21cdb72b5464de25a183b596329e351099  openfire_5_0_4.exe
01c7314268d87b1f8eee0677bb89656f12a082e6461b207d3955f5d9632e2f78  openfire_5_0_4.tar.gz
13b579672b2ce238934aa919cd968636c0f5c8afda5aeb3aec08d60feca35df4  openfire_5_0_4_x64.exe
05b9e5fa976202ef97d183177f6de699cf68bf0cfd422f721a4c8dc5676c1612  openfire_5_0_4.zip
v5.0.3 Bug fix

Fixed admin MUC affiliations not persisting after restart.

Full changelog

Improvement

  • [OF-3130] - Update PostgreSQL JDBC driver to 42.7.8
  • [OF-3134] - Upgrade HSLQDB from 2.7.1 to 2.7.4
  • [OF-3135] - Improve wording of TLS Auth setting
  • [OF-3139] - Remove obsolete transport icons

Bug

  • [OF-3127] - ConcurrentModificationException on room join
  • [OF-3133] - Fix datatype of muc#register_faqentry field
  • [OF-3144] - Upgrade sqlserver JDBC driver to 10.2.4
  • [OF-3146] - Chat room count value is incorrect
  • [OF-3147] - server_bytes_out statistic is not being populated
  • [OF-3148] - Admin MUC affiliations are not persisted in ofMucAffiliation (lost after restart)
  • [OF-3149] - IllegalStateException occurs when removing shared groups due to multiple Iterator.remove() calls for a single Iterator.next().
  • [OF-3155] - Resource policy "Always kick" does not function correctly

sha256sum values

a08493cb19bef6dd2b51ebe88d4ffd121553e2e4473ddbecf94f5ff350e367aa  openfire-5.0.3-1.noarch.rpm
3dd1e9de84d6b177f3b890bea7d6cd88359698bd82c2e656d4b937a8ef7af96e  openfire_5.0.3_all.deb
b3674baa3ab53a1f61db8846c3cdd16ce211917c4df3cee2d4a46fbba265ea76  openfire_5_0_3.dmg
cfabc92ab9e473e71f42ec40533a5d4ae7a9c1dc5ebd060784ce434ae1ba6c12  openfire_5_0_3.exe
fb13bd4e0aff7bd6cc16d78e6f2c35d8b59a95e4f4f886d353265306f151ec45  openfire_5_0_3.tar.gz
dcad510a8a7fda677b07281d08ebb29017555944eeb41c98fb4f38c743a341c4  openfire_5_0_3_x64.exe
0ee9a0837e75b785a40653f78b94a900431067f8a9d2bac5104d2971c46a9779  openfire_5_0_3.zip

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
3,042
Forks
1,404
Languages
Java HTML CSS

Community & Support

Beta — feedback welcome: [email protected]