NDMS 4.3.8 LTS
10/06/2026
Improved
Upgraded the OpenSSL library to versions 3.5.6 and 3.0.20 to address multiple security vulnerabilities, including CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790. [NDM-4402]
Addressed the CVE-2026-28753 security vulnerability in the Web Interface service. [NDM-4368]
Disabled HTTP/2 support to mitigate security vulnerabilities, including CVE-2026-49975, related to an HPACK out-of-memory (OOM) attack. [NDM-4499]
Fixed
Fixed an issue where the SSH session timeout might not be applied properly. [NDM-4406]
Fixed a memory leak in the IPv6 addresses and prefixes API parser. [NDM-4376]
In this section: