# BigBlueButton v3.0.35 - Product: BigBlueButton (https://whatsnew.fyi/product/bigbluebutton) - Vendor: BigBlueButton - Date: 2026-08-13 - Version: v3.0.35 - Original notes: https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.35 - Permalink: https://whatsnew.fyi/product/bigbluebutton/releases/v3.0.35 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Harden static asset path resolution in bbb-etherpad This iteration of BigBlueButton 3.0 contains security fixes only. **We strongly encourage administrators to update!** In addition to updating to this patched version, we encourage administrators to switch to BlockNote shared notes and we proactively **rotate the API secret** via `bbb-conf --setsecret` https://docs.bigbluebutton.org/administration/bbb-conf/#--setsecret-new_secret More details included in the advisory below. ###### bbb-etherpad * fix(sec): harden static asset path resolution by @prlanzarin https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-4g74-4wqf-fr8c **Full Changelog**: https://github.com/bigbluebutton/bigbluebutton/compare/v3.0.34...v3.0.35