<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw" -->

---
title: Eclipse GlassFish 8.0.2 released with three critical...
description: Eclipse GlassFish 8.0.2 was released on May 5, 2026, with three critical security patches including CVE-2026-24457 (CVSS 9.8) in OpenMQ and two undisclosed...
canonical: https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Eclipse GlassFish 8.0.2 released with three critical security fixes | daily.dev
og:description: Eclipse GlassFish 8.0.2 was released on May 5, 2026, with three critical security patches including CVE-2026-24457 (CVSS 9.8) in OpenMQ and two undisclosed...
og:url: https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw
og:image: https://api.daily.dev/og/posts/GoSvbqshW.png
og:image:alt: Eclipse GlassFish 8.0.2 released with three critical security fixes
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Eclipse GlassFish 8.0.2 released with three critical security fixes

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Eclipse GlassFish 8.0.2 was released on May 5, 2026, with three critical security patches including CVE-2026-24457 (CVSS 9.8) in OpenMQ and two undisclosed Admin Console CVEs scoring 9.6 and 9.1. The release also upgrades Grizzly HTTP to 5.0.1, updates Mojarra, Jackson, Nimbus JOSE JWT, and other components, and fixes EJB annotation behavior for appclient. A JAXB Impl 4.0.7 upgrade was rolled back due to TCK regressions and will be retried in 8.0.3. Full Jakarta EE 11 TCK compliance is maintained. Work on 8.0.3 is underway, targeting additional security fixes and ~10% faster Embedded GlassFish boot times. IBM has also submitted Jakarta EE 11 compatibility certification requests for Open Liberty and WebSphere Liberty 26.0.0.5.

## Content

## What's in 8.0.2

Eclipse GlassFish 8.0.2 shipped on May 5, 2026, and the headline is security. Three critical CVEs were patched:

- **CVE-2026-24457** (9.8 CRITICAL) in OpenMQ
- Two undisclosed CVEs in the Admin Console, scoring 9.6 and 9.1

If you're running an older 8.x build, upgrading is worth doing promptly given those scores.

Beyond security, the release includes a handful of practical fixes and upgrades:

- Grizzly HTTP framework bumped to 5.0.1
- Mojarra, OpenMQ, ORB, HK2, Jackson, and Nimbus JOSE JWT all updated
- Localhost hostname resolution improved
- `@EJB` annotation behavior fixed for appclient
- A Maven build dependency issue resolved

One thing that didn't make it: the JAXB Impl 4.0.7 upgrade was rolled back after it caused TCK regressions. That'll be revisited in 8.0.3.

The release maintains full Jakarta EE 11 TCK compliance.

## What's coming in 8.0.3

Work on 8.0.3 is already underway. The plan includes additional security fixes and improvements to Embedded GlassFish startup, targeting roughly 10% faster boot times. The JAXB Impl upgrade will also get another shot once the regression is sorted out.

## Jakarta EE ecosystem updates

On the broader Jakarta EE front, the Eclipse Krazo and Jakarta MVC projects have aligned with the latest EE4J Parent POM to support releasing through the new Maven Central Publishing portal and staging repository. The TCK now passes on GlassFish 8, with WildFly and Open Liberty runs still in progress.

IBM has submitted Jakarta EE 11 compatibility certification requests for both Open Liberty 26.0.0.5 and IBM WebSphere Liberty 26.0.0.5.

Commercial support for GlassFish is available through OmniFish.

## Similar posts on daily.dev

- [GlassFish 8.0.3 Released: Performance optimizations and security fixes – OmniFish – Modern Jakarta EE Runtimes](https://daily.dev/posts/glassfish-8-0-3-released-performance-optimizations-and-security-fixes-omnifish-modern-jakarta-e-ptvkvjrjh) · Jakarta EE · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#java](https://daily.dev/tags/java), [#jakarta-ee](https://daily.dev/tags/jakarta-ee)

[View this post on daily.dev](https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Eclipse GlassFish 8.0.2 released with three critical security fixes","url":"https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw"},"datePublished":"2026-05-19T13:38:02.227Z","dateModified":"2026-05-24T10:19:45.198Z","description":"Eclipse GlassFish 8.0.2 was released on May 5, 2026, with three critical security patches including CVE-2026-24457 (CVSS 9.8) in OpenMQ and two undisclosed...","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/eclipse-glassfish-8-0-2-released-with-three-critical-security-fixes-gosvbqshw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,java,jakarta-ee","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Eclipse GlassFish 8.0.2 released with three critical security fixes"}]}
```

