Share on:
OpenAM 16.1.2 Released
What’s new
- Addressed third-party dependency vulnerabilities:
- CVE-2026-53550 -
js-yamlquadratic-complexity DoS in merge key handling via repeated aliases - CVE-2026-45736 -
wsuninitialized memory disclosure - CVE-2026-48779 -
wsmemory exhaustion DoS from tiny fragments and data chunks - CVE-2026-54466 -
websocket-drivermessage corruption via abuse of protocol length headers - CVE-2026-54490 -
websocket-driverresource limit bypass via message compression
- CVE-2026-53550 -
- Added
revocation_endpointto the OpenID Connect discovery document - Fixed
NotCondition.equalsreflexivity and enabled the OpenFM unit tests - Fixed non-resolvable parent POM for the
openam-mcp-servermodule - Added the
openam-samplesmodules to the main reactor - Removed the dead
jwt-generatortool module and the obsoleteopenam-testintegration test suite - Added CodeQL code scanning and enabled Javadoc doclint on JDK 11 and JDK 26
- Updated embedded OpenDJ dependency to version 5.1.2
Full changeset (more details)
Thanks for the contributions
1. Valery Kharseko
2. dairoca90