Update to OpenSSL 3.0.22, APR Util 1.6.5 and Expat 2.8.4
We are glad to announce that VisualSVN products have been updated to OpenSSL 3.0.22, APR Util 1.6.5 and Expat XML parser 2.8.4.
This update fixes multiple security vulnerabilities, some of which affect both VisualSVN Server and the VisualSVN plug-in. Therefore, updating to the new builds is strongly recommended for all users.
The update to APR Util 1.6.5 cumulatively fixes a number of security vulnerabilities. They include CVE-2026-32327 and CVE-2025-49506, which may affect up-to-date versions of VisualSVN Server. The CVE-2026-32327 vulnerability has a critical base CVSS score and can potentially lead to a denial of service, but exploiting it requires the attacker to be authenticated. CVE-2025-49506is a high-severity vulnerability that potentially allows an unauthenticated attacker to perform a timing side-channel attack on password hashes. However, practical exploits of this vulnerability are considered infeasible.
The update to Expat XML parser 2.8.4 also cumulatively fixes a number of security vulnerabilities. They include medium-severity CVE-2026-56406 and high-severity CVE-2026-66046 vulnerabilities, which affect both VisualSVN Server and the VisualSVN plug-in. CVE-2026-66046 can potentially lead to a denial of service, but exploiting it requires the attacker to be authenticated and have read access to a repository.
The update to OpenSSL 3.0.22 fixes a number of security vulnerabilities as well, but none of them affect up-to-date VisualSVN products.
Update for VisualSVN Server
You can get the latest VisualSVN Server 5.4.9 version from the official download page. For the complete list of changes, see the VisualSVN Server 5.4.9 changelog.
Version families older than VisualSVN Server 5.4.x are no longer supported, and maintenance updates are not available for them. It is strongly recommended that you upgrade to VisualSVN Server 5.4.9 if you are using any version family older than 5.4.x. If upgrading from VisualSVN Server 5.3.x or earlier, please read the article KB233: Upgrading to VisualSVN Server 5.4 before beginning the upgrade.
Update for VisualSVN (a plug-in for Visual Studio)
Select an appropriate VisualSVN plug-in version with respect to your Visual Studio version:
- If you use Visual Studio 2026 or 2022, update to VisualSVN 8.5.2
- If you use Visual Studio 2019, update to VisualSVN 7.5.3
- If you use Visual Studio 2017, update to VisualSVN 6.9.3
- If you use Visual Studio 2015 or older, update to VisualSVN 5.8.3
For the complete list of changes in these maintenance builds, see the corresponding changelog entries for these plug-in versions: VisualSVN 8.5.2, VisualSVN 7.5.3, VisualSVN 6.9.3 and VisualSVN 5.8.3.