How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Security vulnerabilities (CVEs) and notable bug fixes in 26.0.0.6

calendar_today June 16, 2026 person Navaneeth S Nair domain open-liberty

This GA release addresses security vulnerabilities and bug fixes that enhance stability and performance. It includes two CVE fixes: CVE-2026-4410 (denial of service, CVSS 4.8, affecting sipServlet-1.1) and CVE-2026-5516 (denial of service, CVSS 4.4, affecting appSecurity features). Notable bug fixes cover featureUtility exit codes, EJB remote runtime exceptions, AES encryption, Windows JAVA_HOME configuration, HTTP/2 race conditions, and Windows service stop timeout handling, plus four new guides on observability with OpenTelemetry, Jakarta Faces, and Gradle multi-module applications.

open_in_new Read original post