News

JumpServer v4.10.16-lts Release Notes

#Release Notes
JumpServer v4.10.16-lts Release Notes

What’s new

  • Added support for trusted client IP validation.

Improvements

  • Replaced Environment with SandboxedEnvironment to enhance the security of YAML template rendering.

Bug fixes

  • Fixed an issue where SSL certificates were not properly validated during outbound requests.
  • Fixed a logic conflict caused by inconsistent field order when exporting resources.

Recommended Reading

Client-Side Recording Player and Transcoding Tool: JumpServer v4.10.17 LTS Release
News

Client-Side Recording Player and Transcoding Tool: JumpServer v4.10.17 LTS Release

JumpServer v4.10.17 LTS is released. This version integrates a recording player and transcoding tool into the client, adds UKey hardware authentication, custom favorite asset node trees, custom SSO authentication, and sensitive information export prevention. Core dependencies upgraded to Django 5.2, Python 3.14, and Vue 3.5. This article provides a detailed interpretation of all new features and improvements.

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.7.29)
Security

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.7.29)

JumpServer security advisory JS-2026.7.29: Four vulnerabilities identified — CVE-2026-16723 (Fastjson in Chen), CVE-2026-54336 (KoKo SFTP path traversal), CVE-2026-44845 (Applet Host Jinja template injection RCE), CVE-2026-44846 (organization invitation permission override). Affects V3 < v3.10.22 LTS and V4 < v4.10.17 LTS. Upgrade to safe versions immediately.

JumpServer v4.10.18-lts Release Notes
News

JumpServer v4.10.18-lts Release Notes

JumpServer v4.10.18-lts release notes — includes improvements to Chen SQL parsing and memory optimization, along with 11 bug fixes addressing KoKo, Docker isolation, Redis session sharing, and Luna UI issues.

Download Community Free Trial