Eclipse GlassFish 8.0.2 was released on May 5, 2026, featuring critical security fixes including a 9.8 CRITICAL CVE in OpenMQ and two undisclosed CVEs in the Admin Console with scores of 9.6 and 9.1. The release also improves hostname resolution for localhost, fixes @EJB annotation behavior for appclient, and upgrades several components including Grizzly HTTP framework 5.0.1, Mojarra, OpenMQ, ORB, HK2, Jackson, and Nimbus JOSE JWT. A JAXB Impl 4.0.7 upgrade was rolled back due to TCK regressions and will be revisited in 8.0.3. Work is already underway on 8.0.3, which will include additional security fixes and Embedded GlassFish startup improvements targeting ~10% faster boot times.
Table of contents
Security fixesStability and other ImprovementsComponent upgradesConclusion – GlassFish is a platform you can trustSort: