Java 27 Support in 26.0.0.10
Open Liberty 26.0.0.10 adds support for Java 27.
In Open Liberty 26.0.0.10:
View the list of fixed bugs in 26.0.0.10.
Check out previous Open Liberty GA release blog posts.
Support for Java 27
Java 27 is the latest version of Java. It contains a few new features and enhancements over previous versions of Java that you need to review. This is not a Long-Term-Support (LTS) release.
There are 9 new features (JEPs) in Java 27. Five are test features and four are fully delivered:
Test features:
Delivered features:
An important note about JEP 523 — JEP 523 changes the default garbage collector in Java 27. The G1 garbage collector (GC) is now the default in all environments, including environments that previously used the Serial or Parallel GC, for example, single-CPU or low-memory environments such as containers. If you run Liberty in constrained environments, you might notice different GC behavior compared to earlier Java releases. To revert to the previous garbage collector, use -XX:+UseSerialGC or -XX:+UseParallelGC.
Try out the new changes now and get more time to preview your applications and microservices running with Java 27.
Download IBM Semeru Runtimes 27 or Java 27, download and install the 26.0.0.10, set JAVA_HOME to your Java 27 installation directory in your Liberty server’s server.env file, and start testing.
For more information about Java 27, see the Java 27 release notes page, Javadoc or download page. For more information about Open Liberty, see our documentation page.
Security vulnerability (CVE) fixes in this release
| CVE | CVSS Score | Vulnerability Assessment | Versions Affected | Notes |
|---|---|---|---|---|
5.4 |
Information disclosure |
17.0.0.3-26.0.0.9 |
||
6.5 |
SQL injection |
17.0.0.3-26.0.0.9 |
||
9.8 |
Server-side request forgery |
17.0.0.3-26.0.0.9 |
Affects the |
|
7.5 |
Cross-site scripting |
17.0.0.3-26.0.0.9 |
Affects the |
|
7.5 |
Denial of service |
17.0.0.3-26.0.0.9 |
Affects the |
|
7.5 |
Denial of service |
17.0.0.3-26.0.0.9 |
Affects the |
|
7.5 |
Denial of service |
17.0.0.3-26.0.0.9 |
Affects the |
For a list of past security vulnerability fixes, reference the Security vulnerability (CVE) list.
Notable bugs fixed in this release
We’ve spent some time fixing bugs. The following sections describe just some of the issues resolved in this release. If you’re interested, here’s the full list of bugs fixed in 26.0.0.10.
-
When an MCP tool has multiple arguments without names defined we report too many error messages
-
McpRequest.clientInfo throws NPE when server is in stateless mode
-
httpAccessLogging enabled="false" still schedules rollover and causes NullPointerException
-
Avoid logging errors when
jndiEntry decode="true"is used with plain text values
Develop and run your apps using 26.0.0.10
If you’re using Maven, include the following in your pom.xml file:
<plugin>
<groupId>io.openliberty.tools</groupId>
<artifactId>liberty-maven-plugin</artifactId>
<version>3.12.3</version>
</plugin>
Or for Gradle, include the following in your build.gradle file:
buildscript {
repositories {
mavenCentral()
}
dependencies {
classpath 'io.openliberty.tools:liberty-gradle-plugin:4.0.2'
}
}
apply plugin: 'liberty'
Or if you’re using container images:
FROM icr.io/appcafe/open-liberty
Or take a look at our Downloads page.
If you’re using IntelliJ IDEA, Visual Studio Code or Eclipse IDE, you can also take advantage of our open source Liberty developer tools to enable effective development, testing, debugging and application management all from within your IDE.
Get Open Liberty 26.0.0.10 now
Available through Maven, Gradle, Docker, and as a downloadable archive.