TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_7.9.11
  4. #28674

7.9.11
TopLogic Release

2026-03-31

enhancement

minor
#28915
Update GWT to version 2.12

defect

critical
#29199
XSS vulnerability in /jsp/openapi/server/displayAPISpec.jsp
major
#28674
Security issues in the UMLJS project
#29107
StackOverflowError when rolling back in the transaction monitor
minor
#27850
Modelleditor swallows classification with a less-than sign in the name
#29112
Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq
#29197
Eclipse error after dependency update: maven-jar-plugin 3.5.0 causes "outside of a scoping block" error in m2e

update

critical
#29110
Update dependency com.fasterxml.jackson.core:jackson-core to v2.21.1 [SECURITY]
defect

major

#28674

Security issues in the UMLJS project

SecurityIssueUmlJs

Various npm dependencies are integrated via the com.top_logic.umljs module.

Vulnerabilities have been found in several of these dependencies in the meantime:

braces
CVE-2024-4068 | High severity
micromatch
CVE-2024-4067 | Moderate severity
rollup
CVE-2024-47068 | High severity
cross-spawn
CVE-2024-21538 | High severity
serialize-javascript
CVE-2024-11831 | Moderate severity
brace-expansion
CVE-2025-5889 | Low severity
js-yaml
CVE-2025-64718 | Moderate severity

The version of the explicit dependencies rollup and cross-spawn is thus raised manually and the others automatically by compiling with npm.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login