← Back to all sparks
E

EGroupware

COLLAB
Velocity5.0

Online groupware suite with calendar, contacts, projects and file management

Two branches, one deadline: 23.1 security coverage ends August 15th and 26.x is the only exit.

groupwaresecurity-advisoriesbranch-eolcaldav-syncai-automation
Current state
EGroupware is releasing date-stamped builds on two branches simultaneously, and July was almost entirely security. Three separate advisory waves shipped in a fortnight, twice requiring a same-day follow-up build for vulnerabilities reported after the first fix went out. The 23.1 branch now carries an explicit end date: security coverage stops on August 15th 2026.
Where it's heading
Underneath the advisory churn, the 26.x branch is where anything new lands — AiTools gained prompts that fire on entry add, update and delete rather than only from a context menu, and can chain up to five tool calls per prompt; Invoices gained OCR that identifies document type and billing period. Meanwhile CalDAV and ActiveSync fixes keep recurring, the fallout of an internal move from timestamps to DateTime objects in Calendar.
Prediction
Expect a final 23.1 security build before the August 15th cutoff and continued 26.x releases where the AiTools trigger and tool-calling work is the thread to watch.

Recent moves

  1. 9d ago

    Security release plus fallout fixes from the previous one

    Multiple vulnerabilities fixed, along with repairs to things the last security release broke: merge-print to PDF, a stalled ImportExport installation, and a lost admin background image. OpenID Connect now only accepts unverified email when explicitly configured, which is a real authentication tightening.

    View source ↗
  2. 9d ago

    23.1 security fixes with an August 15th end-of-support date

    The same advisory batch backported to 23.1, carrying a hard notice that security coverage for the branch ends August 15th 2026. Anyone still on 23.1 now has a dated migration deadline rather than an open-ended one.

    View source ↗
  3. 22d ago

    Two more 23.1 vulnerabilities patched same day

    A same-day follow-up to the earlier 23.1 build for two further vulnerabilities, with no other content. The second time in a fortnight a security release needed an immediate second cut.

    View source ↗
  4. 22d ago

    High-severity fixes plus custom-field data loss repair

    Fixes multiple high-level vulnerabilities and a data-loss bug where inserting a custom field before or between existing ones wiped most of their data. The custom-fields bug is the more consequential of the two for anyone who edited a form recently.

    View source ↗
  5. 22d ago

    26.x security build adds OCR document-type detection

    The 26.x half of the same advisory wave, plus the custom-field data-loss fix, a recurrence end-date bug when applying external organiser updates, and Invoices OCR now identifying document type and billing period. Even the security builds carry new 26.x capability, which is the clearest signal of where development sits.

    View source ↗
  6. 22d ago

    Two further vulnerabilities patched immediately after

    A follow-up build cut seconds after the main 26.x release for two vulnerabilities reported in the interim. Content-free beyond the fixes themselves.

    View source ↗