thingsboard v4.3.1

v4.3.1

ThingsBoard 4.3.1 Release

Added 1
  • Added Cassandra result set byte-size limit
Changed 3
  • Migrated UI to Angular 20
  • Improved Apple OAuth2 mapper and refactored OAuth2 client validation
  • Made max WS message size configurable
Fixed 9
  • Fixed getTimeseries API (/{entityType}/{entityId}/values/timeseries)
  • Fixed TBEL script execution failures on repeated runs
  • Fixed blocking JPA queries on access-validator single thread
  • Fixed preservation of rule node execution counter in delay and deduplication nodes
  • Fixed infinite loop when rule chain input node forwards to its own rule chain
  • Fixed Redirect Url encoding
Security 7
  • Fixed CVE-2026-24734 and CVE-2025-66614
  • Fixed CVE-2025-7783, CVE-2026-26996 and CVE-2026-26960
  • Fixed CVE-2026-27903 and CVE-2026-27904
  • Added SSRF protection (must be enabled with SSRF_PROTECTION_ENABLED env)
  • Fixed CWE-770 in Jackson Core (GHSA-72hv-8253-57qq)
  • Fixed CVE-2026-27970 and CVE-2026-2391
  • Fixed CVE-2026-2781, CVE-2026-25646, CVE-2026-21945 and CVE-2026-21932 for Docker images

From thingsboard

What's Changed
Security
Major UI
Core & Rule Engine
UI
Transport
Edge

Full Changelog: https://github.com/thingsboard/thingsboard/compare/v4.3.0.1...v4.3.1

View original

Upgraded? How did it go?

Discussion