Skip to content

Closed Issues

The following issues have been fixed in this release of JasperReports® Server:

Key Summary
JRIO-841 Jetty and JasperReports Library documentation links are not working in JasperReports® IO application.
JRIO-842 The system fails to generate the expected PDF output files during report bursting.
JRIO-844 Formatting dialog does not open for Table reports.
JRIO-846 The AccessibleReport reference sample located in the JasperReports® IO /samples/reports directory is outdated.
JRL-2112 When a report is configured with PDF/A properties, JasperReports® Web Studio drops the linkType attribute from JRHyperlink elements. As a result, the generated hyperlinks are non-clickable.
JS-34719 In JasperReports® Server, memory leak warnings during application shutdown prevented the server process from closing entirely, resulting in orphaned Java processes.
JS-57111 Incorrect date shown on AdHoc view with Oracle DATE datatype.
JS-67108 When an Ad Hoc View uses an Is one of filter and the Select All option is applied, saving the view as an Ad Hoc View report fails to transfer the selection. The resulting report's Input Control shows none of the values selected.
JS-68665 When navigating to View > Search, the system fails to return any results if the query exceeds the maximum parameter limit allowed by SQL Server.
JS-75375

On MySQL platform, the API returns wrong response code after updating permissions.

JS-75655 The Report execution (Async) scenario in JasperReports Server 10.0 exhibited a substantial 30% performance degradation compared to JasperReports Server 9.0.0 during regression testing with a single user. This was attributed to a rise in average latency for all actions, and the performance impact became more pronounced with increasing concurrent users.
JS-75712 Import with jobs failing on JBoss 8 platform.
JS-75713 On JBoss 8 platform, when the data format of a timestamp field is altered to show date and time, the resulting format is incorrect. It shows extra comma after date value.
JS-75735 On MySQL platform, the API returns an incorrect response code after the permission is updated.
JS-75739 On MySQL platform, the API returns an incorrect response code after an attribute's value or description is updated.
JS-76888 When accessed via the rest_v2 API endpoints, JasperReports® Server 9.0.0 fails to properly sanitize or escape the type query parameter, allowing arbitrary JavaScript to be executed in the context of the user's browser.
JS-77015 When an item is deselected from the input control's "Selected" list, the report is not updated.
JS-77222 Select All option fails in the Scheduler input controls for Ad Hoc View reports.
JS-77308 Editing and saving an existing Domain Topic updates both its 'Modified' and 'Created' dates to the current date.
JS-77475 In JasperReports® Server 9.0.0, when user role is added for ERROR MESSAGE, then key details are displayed instead of the value in error message.
JS-77563 When running an Ad Hoc View report, the Input Controls panel displays locale keys for labels instead of the Input Control labels.
JS-77638 Users encounter an error when attempting to access folder containing dashboard resources following an upgrade or overlay upgrade on Postgresql database.
JS-78095 In JasperReports® Server 10.0.0, when a scheduled report job is deleted by a user or an administrator, the deletion is incomplete at the database level. The entries are deleted from some tables and still exist in some.
JS-78203 JasperReports® Server is currently utilizing deprecated and EOL AWS-Java-SDK-1.x dependencies.
JS-78365 When JasperReports® Server is configured to use an IBM DB2 database, following a standard major version upgrade or an overlay upgrade to JasperReports® Server 10.0.0, users encounter error dialog when navigating to repository folders containing Dashboard resources.
JS-78499 In JasperReports® Server 9.0.0, a performance is observed when a user interacts with a report input control and selects the Select All option, specifically when the underlying dataset for that input control exceeds 100,000 (100K) values.
JS-78514 JasperReports® Server 10.0.0 fails to start if the theme is configured to load directly from the local file system rather than the standard metadata repository database.
JS-78530 In JasperReports® Server 10.0.0, when a report is configured with an optional input control and scheduled with the option to save as a data snapshot, the scheduled execution fails to save data snapshot during output generation.
JS-78612

In JasperReports® Server 10.0.0, when a report has a valid data snapshot saved directly to the repository database, manual execution correctly pulls data from that snapshot under normal conditions.

However, if the Apache Tomcat cache is cleared (deleting the contents of the <tomcat>/temp and <tomcat>/work directories) and the service is restarted, manual report execution runs a fresh query instead of referring to data snapshot which is saved to repository database.

JS-78767 Data source creation is blocked when using a license restricted to the FUSION feature.
JSS-3194 For jasperQL, aggregate functions are not getting applied on the fields and the column is being returned as blank.
JSS-3531 When copying and pasting a resource within the same directory in the Repository Explorer, the system does not offer the option to rename the duplicate file.
JSS-3558 When designing reports in Jaspersoft® Studio using jasperQL, field aggregations are not working correctly.
JSS-3646 Users were unable to view or access the report options within Jaspersoft® Studio.
JSS-3705 Allow the table column weight property to accept negative numbers for layout configurations.
JSS-3706 Fix proposed i18n properties file list in Translation Wizard.
JSS-3707 Exception thrown when creating table-based reports using the New Report Wizard.
JSS-3710 Jaspersoft® Studio requires internal classes to be explicitly added to the whitelist property for publishing to JasperReports® Server.
JSS-3730 Reports utilizing Google Maps components are currently failing to render and are throwing timeout errors during execution.
JSS-3733 After successfully publishing a report to JasperReports® Server, the Reset and Legend components fail to render on the page.
JSS-3734 There is a color mismatch with Google Maps components, where the marker colors displayed in the legend box do not align with the actual markers on the map.
JSS-3749 Fix the UI and input handling behavior of the date widget during report previews.
JRWS-1113 When you drop an element from the Palette to the Designing Area, the alignment of the existing elements on the Designing Area is not displayed.
JRWS-1129

While creating a report:

  • when the report is not saved, it is correctly previewed.
  • when the report is saved and previewed, an error message is displayed.
  • when the report is reopened and previewed, an error message is displayed.
JRWS-1296

The color of the Search icons in Dataset view and in report preview are different.

JRWS-1300 When you log in using Gdrive, add an image in a report and preview it, an error is displayed. However, when you save the report, you can preview it without any errors.
JRWS-1303 When you log in using JackRabbit, provide a report Description in Properties view, save, and preview or close the report, the added Description is lost.
JRWS-1312 When you log in using a local repository, on previewing a report from Samples, an error is displayed.
JRWS-1315 On starting JasperReports® Web Studio and checking the details for JasperReports® Web Studio 3.0.1 in the command prompt, the details are not available.
JRWS-1317 Log in using the local repository and open a report from the Samples folder. When you change the chart type, and revert to the original chart type of a report, the chart is not displayed on previewing a report.
JRWS-1130 Two configuration properties within the dataset fail to apply or execute properly.
JRWS-1214 Missing documentation for concurrent report execution.
JRWS-1337 Unable to toggle Start on a new page and associated group definition checkbox properties.
JRWS-1405 On previewing a report in the JasperReports® Server + JasperReports® Web Studiointegrated environment, the left-side bookmarks tab does not display correctly.
JRWS-1406 Previewing a report in the JasperReports® Server + JasperReports® Web Studiointegrated environment triggers a console error and results in page alignment discrepancies when compared to the standalone JasperReports® Web Studio view.
JRWS-1471 The initial report in the JasperReports® Server sample library fails to render, triggering a Headers too big HTTP error.
JRWS-1474 The HTML Pro Component is displayed as unparsed text instead of HTML when rendered via Visualize.js.
JRWS-1486 When exploring repositories or folders in both Standalone JasperReports® Web Studio and the JasperReports® Server integration, repository paths are no longer visible when attempting to select a data adapter.
JRWS-1487 A 403 Forbidden error occurs when the system attempts to load the required fonts for FirstJasper.jrxml, preventing the report from rendering correctly.
JRWS-1488 Prevented users from generating TIBCO maps within the system.
JRWS-1509 Opening the Query Editor initializes the Text tab as undefined and causes an error upon switching to the Outline tab.
JRWS-1510

Intermittent session/state corruption occurs when navigating from JasperReports® Server back to Jackrabbit repository, resulting in:

  • An infinite loading loop when expanding the root (/) path in the New Report file picker.

  • A save failure error (Error saving this new report) on report creation.

  • Intermittent errors during the logout process on both repositories.

JRWS-1513 Switching between Text and Outline tabs in Query Editor deletes the WHERE clause.
JRWS-1515

Issues in the Properties > Dataset tab:

  • Search function is not working as expected.

  • The Custom properties section is misnamed.

  • The net.sf.jasperreports.style.fontName property is incorrectly displayed by default in the custom properties section.

JRWS-1518 Implemented standard multi-select behavior in Repository view (Cmd/Ctrl and Shift clicks).
JRWS-1519 The jrws.jrs.token.login.url.js file was ignored during token-based SSO. The UIService servlet has been updated to correctly pass this property from jrws.properties to the frontend.
JRWS-1520 Clean up JasperReports® Web Studio by removing all references to the TibcoMaps component.
JRWS-1533 A 500 Internal Server Error is triggered when a user attempts to log in using their GitHub account.
JRWS-1534 Update the JasperReports® Web Studio implementation to adopt and integrate JasperReports® Library export tags.
JRWS-1537 For Integrated JasperReports® Web Studio, clicking Get Metadata triggers a 500 Internal Server Error and fails to retrieve data for the selected data adapter.
JRWS-1539 When running JasperReports® Web Studio in Standalone mode, statistics are not being captured or tracked for the creation of data adapters.
JRWS-1542 About dialog shows incorrect product details when license file is missing.

Security Issues

The following security issues have been fixed in this release of JasperReports® Server:

Key Area of the Product Affected Type of Vulnerability Description and Impact on Users
JSSEC-163/ JRL-2103 Configuration files Access to sensitive files

The server's insecure handling of untrusted object serialization allowed attackers to bypass type validation restrictions, enabling remote code execution via a manipulated report file.

The attacker was able to trigger arbitrary code execution by uploading a malicious JRXML report that forces the server to fetch and parse a crafted .jrprint file, which directly processes untrusted data through an unsafe object input stream. The following CVE was resolved:

  • CVE-2026-6009

JS-70720 N/A Dependency on third-party libraries

Upgraded aws-java-sdk-core-1.11.505.jar to resolve the following CVE:

  • CVE-2022-31159

JS-76514 N/A Dependency on third-party libraries

Upgraded jackson-core-2.13.4.jar to resolve the following CVE:

  • CVE-2025-52999

JS-76953 N/A Dependency on third-party libraries

Upgraded commons-lang3-3.0.jar to resolve the following CVE:

  • CVE-2025-48924

JS-77826 N/A Dependency on third-party libraries

Upgraded Spring JARs to resolve the following CVE:

  • CVE-2025-41254

JS-77889 N/A Dependency on third-party libraries

Upgraded underscore.string to resolve the following CVE:

  • WS-2017-3772

JS-78055 N/A Dependency on third-party libraries

Upgraded Log4j2 JARs to resolve the following CVE:

  • CVE-2025-68161

JS-78254 N/A Dependency on third-party libraries

Upgraded netty-codec-http-4.1.127.Final.jar to resolve the following CVE:

  • CVE-2025-67735

JS-78653 N/A Dependency on third-party libraries

Upgraded the Spring security JARs to resolve the following CVE:

  • CVE-2026-22732

JS-78719 N/A Dependency on third-party libraries

Upgraded Netty jar to 4.1.132.Final and 4.2.10.Final to resolve the following CVE:

  • CVE-2026-33870

JS-79040 N/A Dependency on third-party libraries

Upgraded Log4j2 JARs to resolve the following CVEs:

  • CVE-2026-34477

  • CVE-2026-34478

  • CVE-2026-34479

  • CVE-2026-34480

JSS-3742 N/A Dependency on third-party libraries

Upgraded Log4j2 JARs to resolve the following CVEs:

  • CVE-2026-34480

  • CVE-2026-34478

JRWS-1470 HTTP protocol Cross-Site Request Forgery (CSRF) Verified and corrected CSRF behavior for JasperReports® Web Studio when embedded within JasperReports® Server, addressing previous integration issues.
JRWS-1504 N/A Dependency on third-party libraries

Upgraded log4j2 JARs for jrws-jrio-jrs.war and jrws-repository-jrs.war to resolve the following CVE:

  • CVE-2025-68161

For information about cases fixed in previous releases, see that version's release notes. For information about your specific cases, visit Jaspersoft Technical Support.