75.0.0
Added
- a9s Backup Services: a9s Backup Manager: Add
api.max_backup_list_limitandapi.max_restore_list_limitBOSH properties to configure the maximum number of items returned by the a9s Backup Manager API. Both values default to50, with the minimum accepted value being1and the maximum being1000. The Ops filebackup-service-max-backup-list-limit.ymlis provided for ease of configuration. - a9s MariaDB: Make the
wsrep_max_ws_sizeMariaDB Galera parameter configurable through custom parameters. For more information, see a9s MariaDB - Custom Parameters. - a9s Search: a9s Search SPI: Allow the Platform Operator to define which plugins can be enabled by the Application
Developer. This change directly impacts the
pluginscustom parameter. - docs: Application Developer: a9s MariaDB: Add information about the new custom parameter
wsrep_max_ws_size. For more information, see a9s MariaDB - Custom Parameters. - docs: Platform Operator: a9s Backup Services: a9s Backup Manager: Document the new
api.max_backup_list_limitandapi.max_restore_list_limitproperties, their usage, and the performance impact of increasing these limits. For more information, see a9s Backup Manager - Properties. - docs: Platform Operator: a9s MariaDB: Add information about the new custom parameter
wsrep_max_ws_size. For more information, see a9s MariaDB - SPI Configuration. - docs: Platform Operator: a9s Messaging: Add information about TLS hostname verification for shovel and federation links. For more information, see a9s Messaging - Configuration and Features.
Changed
- breaking change a9s Messaging: Update Erlang/OTP to
27.3.4.14, fixing CVE-2026-42790. Following RFC 9525, TLS hostname verification no longer falls back to the certificate's Common Name (CN): shovel and federationamqps://links to brokers whose certificate does not carry the connection hostname in a SANdNSNameentry (e.g. CN-only certificates) now fail hostname verification. Wildcard SAN entries continue to be matched, as a9s Messaging enables RFC 6125/9525-compliant wildcard matching for these links. The fix also closes a name-constraints bypass, so certificates issued by a DNS-name-constrained intermediate CA for out-of-scope hostnames are now rejected as well. For more information, see UPGRADE.md. - all services: a9s Public API: Adapt the endpoint
/v1/instances/:instance_idto containallowed_update_timein its response when retrieving the Service Instance overview. For more information, see API V1 Endpoints - Instance Endpoints - Get Instance Overview. - all services: a9s Service Dashboard: Change the endpoint used to get Service Instance information from a9s Public API v0 to a9s Public API v1.
- a9s Backup Monit: Reduce the number of outbound requests made to the backup storage when computing the content length of a backup. This prevents high request volumes from overwhelming firewalls.
- a9s CF Service Guard: Update a9s CF Service Guard to prevent matching the details of a new Service Instance to a "deleted" Service Instance when searching across Service Brokers to mark it for synchronization.
- a9s MariaDB: Update the
dashboard_client.idfor the a9s Public API Auth Provider and the smoke-test errand name to a supported Data Service version in the Data Service manifest. - a9s Messaging: Update the
dashboard_client.idfor the a9s Public API Auth Provider and the smoke-test errand name to a supported Data Service version in the Data Service manifest. - a9s MongoDB: Update the
dashboard_client.idfor the a9s Public API Auth Provider to a supported Data Service version in the add-mongodb-sspl.yml Ops file. - a9s PostgreSQL: Update the
dashboard_client.idfor the a9s Public API Auth Provider and the smoke-test errand name to a supported Data Service version in the Data Service manifest. - a9s Search: a9s Search SPI: Fix an issue where the custom parameters reset to their default in certain conditions.
- a9s Search: Allow the Application Developer to configure any supported plugin that has been allowed by the Platform
Operator. This change directly impacts the
pluginscustom parameter. - a9s Template Uploader Errand: a9s MariaDB: Extend the a9s MariaDB templates to allow adding the custom parameter
wsrep_max_ws_size. - docs: Application Developer: a9s Search: Update the documentation for the
pluginscustom parameter to reflect the new behavior. For more information, see a9s Search - Enable Custom Plugins. - docs: Platform Operator: a9s LogMe2: Update the "Plugins" section to improve clarity on the enabled plugins. For more information, see a9s LogMe2 - Resource Considerations.
- docs: Platform Operator: a9s Search: Update the documentation for the
pluginscustom parameter to reflect the new behavior. For more information, see a9s Search - Enable Custom Plugins. - BOSH stemcell: all services: Update Jammy stemcell to version
1.1298for internal tests of all supported services.
Updated Dependencies
- all services:
- bpm to v1.4.34.
- routing to v0.387.0.
- a9s Backup Agent: Update internal dependencies.
- a9s Bee: Update internal dependencies.
- a9s Public API:
- Update internal dependencies.
- Node.JS to v24.18.0.
- a9s-beehive to v1.2.13.
- krakend to v2.13.8.
- krakend-custom-plugins to v2.13.8.
- nginx to v1.31.3.
- a9s Service Dashboard:
- Node.JS to v22.23.1.
- Update internal dependencies.
- a9s Smoke Tests: Update internal dependencies.
- logstash to v8.19.19.
- nginx:
- nginx to v1.31.3.
- a9s-pg: Update internal dependencies.
- a9s Backup Services:
- a9s Backup Manager: Update internal dependencies.
- a9s Backup Monit: Update internal dependencies.
- a9s CF Service Guard: Bump Ruby gem dependencies.
- a9s KeyValue: a9s KeyValue 8: valkey to v8.1.9.
- a9s LogMe2:
- Update internal dependencies.
- fluentd to 1.19.3.
- OpenSearch to v2.19.6.
- a9s MariaDB:
- a9s MariaDB 10.6: Update internal dependencies.
- a9s MariaDB 10.11: Update internal dependencies.
- a9s Messaging:
- a9s Messaging 4:
- erlang to v27.3.4.14.
- RabbitMQ to 4.3.3.
- Update internal dependencies.
- a9s Messaging 4:
- a9s MongoDB:
- a9s MongoDB 8:
- mongosh to v2.9.2.
- a9s MongoDB 7:
- mongosh to v2.9.2.
- a9s MongoDB 8:
- a9s PostgreSQL:
- a9s PostgreSQL 15: Update internal dependencies.
- a9s PostgreSQL 17: Update internal dependencies.
- a9s Prometheus:
- prometheus2: Update internal dependencies.
- prometheus-legacy: Update internal dependencies.
- promgraf2: Update internal dependencies.
- a9s Dashboard API:
- Update internal dependencies.
- Node.JS to v22.23.1.
- a9s Search:
- OpenSearch to v2.19.6.
Deprecated
-
a9s MariaDB: Deprecation: Deprecate the following a9s Data Service version:
- a9s MariaDB 10.6: MariaDB 10.6 is end-of-life by their vendor since July 2026
Please ensure that you organize the migration of your existing Service Instances to a more up-to-date version of the same a9s Data Service:
- for a9s MariaDB 10.6: a9s MariaDB 10.11 is available as GA version.
This deprecation follows the announcement in v73.0.0. The deprecation phase is planned to last until v78.0.0 (expected end of October 2026), in which the unsupport phase of the deprecated version will start. The creation of new a9s Data Service Instances for this particular version will then be disabled by default in the a9s Data Service Bundle when the unsupport occurs in v81.0.0 (expected end of January 2027) and we will not provide regular support for this version. The corresponding documentation will also be removed. Therefore, we strongly recommend that you start your migrations to a supported GA version as soon as possible and complete them until the end of the deprecation phase. For more information see a9s Platform Operator - Sunrise Sunset.
Fixed
- a9s Search: Fix an installation issue in the
analysis-phoneticplugin.
Security
- all services:
- a9s Bee:
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39829.
- Fix CVE-2026-39830.
- Fix CVE-2026-39831.
- Fix CVE-2026-39832.
- Fix CVE-2026-39833.
- Fix CVE-2026-39834.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42508.
- Fix CVE-2026-46595.
- Fix CVE-2026-46597.
- a9s Public API:
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- a9s Service Dashboard:
- Fix CVE-2026-9277.
- Fix CVE-2026-12143.
- Fix CVE-2026-48619.
- Fix CVE-2026-48779.
- Fix CVE-2026-48930.
- Fix CVE-2026-48933.
- a9s Smoke Tests:
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39829.
- Fix CVE-2026-39830.
- Fix CVE-2026-39831.
- Fix CVE-2026-39832.
- Fix CVE-2026-39833.
- Fix CVE-2026-39834.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42508.
- Fix CVE-2026-46595.
- Fix CVE-2026-46597.
- Improve measures to prevent credential leakage in the Smoke Tests logs.
- a9s SSO Proxy: Fix a reflected cross-site scripting (XSS) vulnerability in the SSO proxy authentication failure page.
- nginx:
- Fix CVE-2026-42533.
- Fix CVE-2026-60005.
- a9s Bee:
- a9s-pg:
- Fix CVE-2026-11822.
- Fix CVE-2026-11824.
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39829.
- Fix CVE-2026-39830.
- Fix CVE-2026-39831.
- Fix CVE-2026-39832.
- Fix CVE-2026-39833.
- Fix CVE-2026-39834.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42508.
- Fix CVE-2026-46595.
- Fix CVE-2026-46597.
- a9s LogMe2:
- Fix CVE-2026-34477.
- Fix CVE-2026-34478.
- Fix CVE-2026-34480.
- Fix CVE-2026-44024.
- Fix CVE-2026-44025.
- Fix CVE-2026-44160.
- Fix CVE-2026-44161.
- a9s MariaDB:
- a9s MariaDB 10.6: Fix CVE-2026-39822.
- a9s MariaDB 10.11: Fix CVE-2026-39822.
- a9s Messaging:
- a9s Messaging 4:
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42790.
- Fix CVE-2026-49759.
- a9s Messaging 4:
- a9s PostgreSQL:
- a9s PostgreSQL 15:
- Fix CVE-2026-11822.
- Fix CVE-2026-11824.
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39829.
- Fix CVE-2026-39830.
- Fix CVE-2026-39831.
- Fix CVE-2026-39832.
- Fix CVE-2026-39833.
- Fix CVE-2026-39834.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42508.
- Fix CVE-2026-46595.
- Fix CVE-2026-46597.
- a9s PostgreSQL 17:
- Fix CVE-2026-11822.
- Fix CVE-2026-11824.
- Fix CVE-2026-33811.
- Fix CVE-2026-33814.
- Fix CVE-2026-39820.
- Fix CVE-2026-39822.
- Fix CVE-2026-39829.
- Fix CVE-2026-39830.
- Fix CVE-2026-39831.
- Fix CVE-2026-39832.
- Fix CVE-2026-39833.
- Fix CVE-2026-39834.
- Fix CVE-2026-39836.
- Fix CVE-2026-42499.
- Fix CVE-2026-42501.
- Fix CVE-2026-42508.
- Fix CVE-2026-46595.
- Fix CVE-2026-46597.
- a9s PostgreSQL 15:
- a9s Prometheus:
- prometheus2: Fix CVE-2026-39822.
- prometheus-legacy: Fix CVE-2026-39822.
- promgraf2: Fix CVE-2026-39822.
- a9s Dashboard API:
- Fix CVE-2026-48619.
- Fix CVE-2026-48930.
- Fix CVE-2026-48933.
- a9s Search:
- Fix CVE-2026-34477.
- Fix CVE-2026-34478.
- Fix CVE-2026-34480.