← Back to all sparks
R

Request Tracker

SUPPORT
Velocity0.0

Enterprise-grade issue tracking and ticketing system for support desks

Request Tracker maintains three branches in lockstep, and security is what sets the release calendar.

ticketingsecurity-releasesmulti-branchcveend-of-lifeself-hosting
Current state
Best Practical ships RT across three concurrent branches, 4.4, 5.0 and 6.0, and coordinates security releases across all of them on the same day. The most recent pair, 5.0.10 and 6.0.3, both landed on 2026-05-20 carrying the same fixes: a privilege escalation and credential disclosure through the REST 2.0 user collection endpoint (CVE-2026-44231), SQL injection via the entry_aggregator parameter in JSON search (CVE-2026-41075), and an LDAP authentication bypass. Feature work rides along on the 6.0 branch, while 5.0 and 4.4 receive security fixes and little else.
Where it's heading
The branch structure is consolidating. RT 4.4 reached its last planned release at 4.4.9 in October 2025, with users pointed at 5 or 6, and 6.0 is where features now land: dashboard saved searches gained pagination and sorting, statuses take colors from lifecycle configuration, custom fields display multi-column by default, and keyboard menu navigation improved. The 5.0 line still gets real work but of a narrower kind, such as the inline CSS handling in ticket history that shipped with 5.0.10. Expect the same-day multi-branch security release to remain the pattern for as long as two branches are supported.
Prediction
The next release is most likely another coordinated security pair on 5.0 and 6.0, with feature work continuing to accumulate only on 6.0.

Recent moves

  1. 3mo ago

    Security release fixes REST 2.0 credential disclosure and SQL injection

    The 5.0 half of a same-day security pair with 6.0.3, fixing a REST 2.0 endpoint that exposed and rotated other users' feed credentials, SQL injection in JSON search, and an LDAP authentication bypass. The one non-security change is inline CSS handling in ticket history, balancing HTML email display against processing very large messages.

    View source ↗
  2. 3mo ago

    Same security fixes as 5.0.10, plus dashboard and accessibility work

    The 6.0 half of the 2026-05-20 security pair, carrying the same CVEs as 5.0.10 but bundling the feature work that only lands on this branch: pagination and sorting for saved searches on dashboards, status colors from lifecycle configuration, multi-column custom field display, and improved keyboard menu navigation.

    View source ↗
  3. 10mo ago

    Calendar view for saved searches and memory management work

    A feature-carrying 6.0 release with security fixes attached: a calendar view for saved searches, enhanced history filtering and paging, and memory management improvements. It shipped the same day as 5.0.9 and 4.4.9, the usual coordinated pattern.

    View source ↗
  4. 10mo ago

    CSV injection fix in TSV export, with assorted updates

    The 5.0 branch's share of the October 2025 coordinated security release, fixing CSV injection through ticket values exported to TSV from search results, alongside a batch of smaller updates and fixes. It is the middle branch of the three released that day.

    View source ↗
  5. 10mo ago

    Final RT 4.4 release closes the branch with one security fix

    The last planned release of the 4.4 series, carrying a single fix for the same CSV injection issue patched across the other branches that day, with users directed to RT 5 or RT 6. It closes a long-lived branch rather than adding to it.

    View source ↗
  6. 1y ago

    Release exists mainly to support RTIR 6.0.1

    A 6.0 point release whose stated purpose is supporting the newly released RTIR 6.0.1, with assorted UI fixes attached: loading spinners moved out of the way of clickable elements, multi-value handling in TomSelect inputs, and Bootstrap styling consistency. Little here changes RT itself.

    View source ↗