Skip to main content

25.3.6

Published: 27 August 2026

Bug fixes

Platform
AVA-3413

Fixed a null pointer exception that could occur when starting a fully stopped SAP system, which prevented the start action from completing.

Platform
AVA-3471

Fixed a file handle leak on the Avantra Server where idle network connections were not reliably closed, which could exhaust the OS file handle limit over time on large, gateway-fronted fleets. Attachment downloads for checks such as RUN_PROG are now served through a dedicated pool with concurrency limits, preventing large downloads from delaying agent monitoring.

Security
AVA-3640

Fixed 14 critical CVEs by updating bundled third-party libraries: BouncyCastle (CVE-2026-8763, CVE-2026-59650, CVE-2026-58062, CVE-2026-5588), Jackson (CVE-2026-54513, CVE-2026-54512), Netty (CVE-2026-44249, CVE-2026-56820, CVE-2026-56821, CVE-2026-56822), Spring Boot (CVE-2026-40974, CVE-2026-40971), Spring GraphQL (CVE-2026-41699), and Spring Web (CVE-2026-41855).

Security
AVA-3490

Fixed an issue where navigating directly to another URL instead of completing the forced password-reset screen let a user reach a fully authenticated session (including classic UI admin pages) while still using an expired password.