The recently disclosed CVE-2025-48976 vulnerability in Apache Commons FileUpload does not affect Skyve 9. Skyve 8 is only conditionally vulnerable when using the commons uploader with an outdated JSF version. Recommended mitigations are provided for affected configurations.
Read MoreA new critical vulnerability has been found in the Apache Struts 2 web application framework. No version of Skyve is affected by this vulnerability.
Read MoreI came across an interesting security article by penetration tester Daniel Thatcher discussing a proposed attack against older versions of UUIDs. I describe some of the design decisions which went into designing the identifier systems used in Skyve.
Read More