TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_7.9.11
  4. #29112

7.9.11
TopLogic Release

2026-03-31

enhancement

minor
#28915
Update GWT to version 2.12

defect

critical
#29199
XSS vulnerability in /jsp/openapi/server/displayAPISpec.jsp
major
#28674
Security issues in the UMLJS project
#29107
StackOverflowError when rolling back in the transaction monitor
minor
#27850
Modelleditor swallows classification with a less-than sign in the name
#29112
Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq
#29197
Eclipse error after dependency update: maven-jar-plugin 3.5.0 causes "outside of a scoping block" error in m2e

update

critical
#29110
Update dependency com.fasterxml.jackson.core:jackson-core to v2.21.1 [SECURITY]
defect

minor

#29112

Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq

UmlJs

The minimatch dependency in com.top_logic.umljs/src-js/package-lock.json is at version 10.2.2, which is vulnerable to two ReDoS CVEs:

  • CVE-2026-27903: matchOne() combinatorial backtracking - fixed in 10.2.3
  • CVE-2026-27904: Nested extglob catastrophic backtracking - fixed in 10.2.3

These are dev dependencies only (eslint, rollup toolchain) and not shipped in production, but should still be updated.

A prior fix (commit afea3c24981, Feb 24) upgraded minimatch to 10.2.2, which addressed CVE-2026-26996, but the two newer CVEs require 10.2.3+.

Fix: Update minimatch to >= 10.2.3 via npm update minimatch in com.top_logic.umljs/src-js/.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login