Request Tracker
Enterprise-grade issue tracking and ticketing system for support desks
Request Tracker maintains three branches in lockstep, and security is what sets the release calendar.
◆Recent moves
- 3mo ago
Security release fixes REST 2.0 credential disclosure and SQL injection
The 5.0 half of a same-day security pair with 6.0.3, fixing a REST 2.0 endpoint that exposed and rotated other users' feed credentials, SQL injection in JSON search, and an LDAP authentication bypass. The one non-security change is inline CSS handling in ticket history, balancing HTML email display against processing very large messages.
View source ↗ - 3mo ago
Same security fixes as 5.0.10, plus dashboard and accessibility work
The 6.0 half of the 2026-05-20 security pair, carrying the same CVEs as 5.0.10 but bundling the feature work that only lands on this branch: pagination and sorting for saved searches on dashboards, status colors from lifecycle configuration, multi-column custom field display, and improved keyboard menu navigation.
View source ↗ - 10mo ago
Calendar view for saved searches and memory management work
A feature-carrying 6.0 release with security fixes attached: a calendar view for saved searches, enhanced history filtering and paging, and memory management improvements. It shipped the same day as 5.0.9 and 4.4.9, the usual coordinated pattern.
View source ↗ - 10mo ago
CSV injection fix in TSV export, with assorted updates
The 5.0 branch's share of the October 2025 coordinated security release, fixing CSV injection through ticket values exported to TSV from search results, alongside a batch of smaller updates and fixes. It is the middle branch of the three released that day.
View source ↗ - 10mo ago
Final RT 4.4 release closes the branch with one security fix
The last planned release of the 4.4 series, carrying a single fix for the same CSV injection issue patched across the other branches that day, with users directed to RT 5 or RT 6. It closes a long-lived branch rather than adding to it.
View source ↗ - 1y ago
Release exists mainly to support RTIR 6.0.1
A 6.0 point release whose stated purpose is supporting the newly released RTIR 6.0.1, with assorted UI fixes attached: loading spinners moved out of the way of clickable elements, multi-value handling in TomSelect inputs, and Bootstrap styling consistency. Little here changes RT itself.
View source ↗