Redmine 7.0.2 and 6.1.5 released
On September 30, 2026 (Central European Time), Redmine 7.0.2 and 6.1.5 were released. These releases include several security fixes.
What is Redmine:
Redmine is an open-source project management tool. It can be freely installed in your own environment, such as an on-premises server, and cloud services are also available.
Security information
The two released versions include the following common security fixes:
- Defect #44467: Private/invisible issue subjects leaked via REST API
include=children - Defect #44468: Private project names + role assignments leaked via
GET /groups/<id>.json?include=memberships
Redmine 7.0.2 includes the following security fix:
- Defect #44429: DOM-Based XSS via Clipboard HTML Paste
Changes
Common changes in 7.0.2 and 6.1.5 (17 changes)
Attachments
- Defect #44556: No error is shown when pasting an image after the limit of attachments at once is reached
Code cleanup/refactoring
- Defect #44438: DateCalculationTest is not run by
rails test - Defect #44527: Stubs of initialize_ldap_con in UserTest have no effect
- Patch #44392: Replace IO.read with File.read
- Patch #44455: Fix tests that fail when the date changes during a test run
Database
- Defect #44375: Concurrency problem in project deletion / project marking for deletion
Documentation
- Patch #44413: Document that Redmine does not start on Ruby 3.3.0
Issues
- Defect #44560: Issue creation fails when the default assignee is no longer assignable
LDAP
- Defect #44526: 500 error when the LDAP server is unreachable on macOS 26.7
Performance
- Feature #44415: Reduce icon rendering time by caching sprite paths
Plugin API
- Defect #37686: Plugin migrations are skipped or fail due to stale cached versions when a plugin is migrated more than once in the same process
Projects
- Defect #44462: Project list rows show the context menu cursor although no context menu is available
Security
- Defect #44467: Private/invisible issue subjects leaked via REST API
include=children - Defect #44468: Private project names + role assignments leaked via
GET /groups/<id>.json?include=memberships
SCM
- Defect #27043: Subversion repositories with spaces in the root URL cause broken file and diff links on the revision page
- Defect #44476: Fails to fetch revisions if a Git branch name contains a 40-character hexadecimal string
Translations
- Defect #44418: Fix typo in Japanese translation of mail_body_account_information_external
Changes only in 7.0.2 (15 changes)
Administration
- Defect #44488: Info text for "Initials" fallback avatars shows Gravatar URL even when a custom avatar_server_url is configured
- Patch #44559: User bulk lock/unlock does not run callbacks
Attachments
- Defect #44378: Ghostscript process is left running when PDF thumbnail generation times out
Email notifications
- Defect #44442: Large blank space before pre blocks in HTML email notifications
Performance
- Defect #44372: Chrome freezes for several minutes when opening the possible values page of a key/value list custom field with thousands of values
- Defect #44412: Themes with custom icons.svg slow down page rendering
- Patch #44386: Avoid N+1 queries generated by Webhook#setable_projects
Rails support
- Patch #44523: Update Rails to 8.1.4
Security
- Defect #44429: DOM-Based XSS via Clipboard HTML Paste
UI
- Defect #44408: Autocomplete popup appears off-screen when the caret is near the bottom of the viewport
- Defect #44443: Top menu is thinner than expected when the user is not logged in
- Defect #44445: Selected main menu tab looks detached from the content area due to gaps above and below it
- Patch #44453: Add slightly rounded corners (3px) to top menu item highlights
UI - Responsive
- Feature #44444: Update the mobile header and flyout menu colors to match the redesigned desktop header
Webhooks
- Feature #44337: Add an administration page listing all webhooks
Changes only in 6.1.5 (1 change)
Rails support
- Patch #44524: Update Rails to 7.2.4
