Eclipse GlassFish 8.0.3 was released on June 7, 2026, with a focus on security fixes and performance improvements. The most notable security fix addresses CVE-2024-9342, a brute force vulnerability on admin interfaces, with progressive login delay and anti-DDoS measures. Additional unpublished CVEs in Grizzly and JAXB Impl are also patched, covering HTTP smuggling and malicious XML payload attacks. On the performance side, Jakarta Faces rendering speed has more than doubled, bringing GlassFish on par with Tomcat and WildFly. Embedded GlassFish startup time is also ~10% faster via parallel subsystem loading. The release includes several bug fixes, component upgrades (JAXB 4.0.9, Grizzly 5.0.2, Jackson 2.22.0, and others), and restored SBOM generation for distribution artifacts.

4m read timeFrom omnifish.ee
Post cover image
Table of contents
Security fixes and brute force preventionSignificant performance optimizationsBug fixesComponent upgrades and SBOMA platform worth trusting
411 Impressions