SaaS Customers: No action is required. Your instances have already been patched and secured by our team.

Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.

Vulnerabilities patched

For full technical details, please refer to the security advisories on GitHub.

📣 Important Announcements

String#utf8_encode and Object#to_utf8 will be removed

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#stringutf8_encode-and-objectto_utf8-will-be-removed

Debian 11 will no longer be supported

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#debian-11-will-no-longer-be-supported

Inline attachments will be listed separately in ticket article API responses

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#inline-attachments-will-be-listed-separately-in-ticket-article-api-responses

Exceptions::UnprocessableEntity will be removed

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#exceptionsunprocessableentity-will-be-removed

The deprecated Rails.application.config.db_* values will be removed

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#the-deprecated-railsapplicationconfigdb_-values-will-be-removed

String#utf8_encode and Object#to_utf8 will be deprecated in favour of TextEncoding.utf8_encode

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#stringutf8_encode-and-objectto_utf8-were-deprecated-in-favour-of-textencodingutf8_encode

Import mode will also enable maintenance mode

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#import-mode-also-enables-maintenance-mode

Deleting organizations via API will require the admin.organization permission

All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#deleting-organizations-via-api-requires-the-adminorganization-permission