Share on:
OpenAM 16.0.6 Released
What’s new
- Addressed security vulnerabilities:
- CVE-2026-2391 -
qslibraryarrayLimitbypass in comma parsing allows denial of service - CVE-2026-32141 -
flattedlibrary vulnerable to unbounded recursion denial of service inparse() - CVE-2026-33228 - Prototype pollution via
parse()in Node.jsflattedlibrary - CVE-2026-33439 - Pre-authentication remote code execution via
jato.clientSessiondeserialization in OpenAM
- CVE-2026-2391 -
- Fixed inability to set the
SameSitecookie attribute in XUI - Updated embedded OpenDJ dependency to version 5.0.4
Full changeset (more details)
Thanks for the contributions
1. Valery Kharseko
2. Maxim Thomas
3. IvanAndrukh
4. iamnoooob
5. hacktronai-research