thingsboard v4.2.2.1

v4.2.2.1

ThingsBoard 4.2.2.1 Release

Added 3
  • Added OTA package data cleanup
  • Added WS update on telemetry deletion
  • Support combined PEM cert+key for Edge gRPC SSL
Changed 3
  • Sanitize database error messages
  • Updated locales da_DK, de_DE, el_GR, es_ES, fr_FR, it_IT, ja_JP, nl_NL, no_NO, pt_BR, tr_TR, uk_UA, zh_CN
  • Hidden Show on widgets button on sysadmin level
Fixed 6
  • Fixed notification requests and RPC cleanup timeout on large datasets
  • Fixed WS reconnect loop and notification spam when session limit is reached
  • Fixed resetting of validation on storeLink property
  • Fixed proxy error handling for 502/503/504 HTTP status codes
  • Fixed string-items-list autocomplete selection and blur handling
  • Fixed LwM2M Redis stores startup by using separate connections for SCAN and GET
Security 9
  • Fixed XSS vulnerability in notification center
  • Fixed CVE-2026-24308, CVE-2026-24281 and CVE-2026-24400
  • Added configurable security headers and env-var-backed CORS configuration
  • Fixed SSRF DNS rebinding bypass and added allow-list
  • Fixed CVE-2026-24281, CVE-2026-24308, CVE-2026-24400, CVE-2026-29063, CVE-2026-29087, CVE-2026-29786, CVE-2026-30827, CVE-2026-31802, CVE-2026-32141, CVE-2026-32635, CVE-2026-27904
  • Fixed CVE-2026-22731, CVE-2026-22732, CVE-2026-22733, CVE-2026-22737 and upgraded Spring Boot to 3.5

From thingsboard

What's Changed
Security
Core & Rule Engine
UI
Edge
Transport

Full Changelog: https://github.com/thingsboard/thingsboard/compare/v4.2.2...v4.2.2.1

View original

Upgraded? How did it go?

Discussion