Ejabberd 26.07 / ProcessOne – Erlang Jabber/XMPP/Matrix Server – Communication
7 hours ago
- The ejabberd 26.07 release includes multiple security fixes, such as prevention of PLAIN auth request manipulation, SQL injection in mod_pubsub, atom exhaustion via REST requests, and OAuth URL redirect vulnerability.
- Important security issues also address weak random number generators in token generation for mod_bosh, captcha, and other modules, as well as missing CSRF protection and XSS prevention headers.
- New features include mod_invites pages for users to generate account creation invites from WebAdmin, and mod_conversejs support for ConverseJS 14 with cosmetic improvements.
- Erlang/OTP 27.0 is now the soft minimum for compilation, with a bypass option available, and Rebar/Rebar3 binaries have been updated to support Erlang/OTP versions 26-29.
- The ejabberd Business Edition introduces SQL schema changes for push notifications, a new local_health_status command, and enhancements to client certificate authentication and clustering.