Security Fixes
-
[FISH-13096] CVE-2026-24457 - Remote Attacker Can Read Arbitrary Files via Unsafe Parsing of OpenMQ Configuration
-
[FISH-13363] Restrict Access to Vulnerable EL Expressions
Bug Fixes
-
[FISH-13385] Fix Admin Console Freezing After Upgrading from Payara 6 to 7
Improvements
-
[FISH-10287] Update
JaccProviderCompatibilityStartupService -
[FISH-11069] Remove Audit Modules
-
[FISH-12092] Add
warlibsSupport to Redeployment via Admin Console -
[FISH-13090] Reduce INFO Logging for Jakarta Data Impl
-
[FISH-13126] Create New Deployment Descriptors with Deprecated Properties Removed
-
[FISH-13193] Fix
@Repositorymethods not throwingUnsupportedOperationExceptionwhen no implementation logic can be injected at deploy time -
[FISH-12430] Remove Container Managed Persistence (CMP) Implementation
Component Upgrades
-
[FISH-13231] Upgrade
org.glassfish:jakarta.facesfrom 4.1.6 to 4.1.7 -
[FISH-13357] Upgrade
smallrye-common.versionfrom 2.17.0 to 2.17.1 -
[FISH-13360] Upgrade
ant.versionfrom 1.10.16 to 1.10.17 -
[FISH-13394] Upgrade
org.apache.felix:org.apache.felix.scrfrom 2.2.14 to 2.2.18 -
[FISH-13395] Upgrade
io.projectreactor:reactor-corefrom 3.8.4 to 3.8.5 -
[FISH-13424] Upgrade
org.javassist:javassistfrom 3.30.2-GA to 3.31.0-GA -
[FISH-13433] Upgrade
org.eclipse.microprofile.config:microprofile-config-apifrom 3.1 to 3.1.1 -
[FISH-13437] Upgrade Docker JDK to 21.0.11
-
[FISH-13441] Upgrade Docker JDK to 25.0.3
-
[FISH-13462] Upgrade
jline.versionfrom 3.30.9 to 3.30.11