Fixes:
- Fixed an issue where parallel stages editing the same pipeline state could lead to data loss.
- Increased OPC browse timeout to 5 minutes and all other browse timeouts to 1 minute.
- Removed the “Auto” type option from OPC UA Method Input Parameters.
- Fixed an issue where Instance test reads would only display the first error. Now all errors are shown.
- Fixed an issue that would cause the Write New stage to error if the qualifier had no settings.
- Fixed an issue where indexing into a complex object with {{source}}[“attribute”] would fail if one of the attribute keys contained a “.”
- Fixed an issue where a templated Instance or Input would not be visible in the default HighByte Namespace if it didn’t also define parameters.
- Fixed an issue where pipeline statistics would have inconsistent alignment.
- Fixed an issue where some stages would appear editable in Pipeline Replay.
- Fixed an issue where namespace test read panel sizing would reset after a read.
- Updated the Dashboard Connection Widget to only redirect when clicking the “View” button (previously would happen when clicking anywhere).
- Removed a non-functional browse button from the reference panel for Ignition Module connections.
- Fixed an issue where the remote hub variables UI would not close after saving changes.
- Fixed an issue where a pipeline would not go into an error state when it reached the 10,000-value event queue limit.
- Fixed an issue where Pipelines would not subscribe to OPC UA tag updates if the OPC UA server was unavailable at Pipeline startup but operational after.
- Fixed an issue where connections with invalid or unresolved settings could appear healthy and continue being used, causing Pipelines to attempt data operations on invalid connections.
- Fixed an issue where publishing a wildcard in the group or edge node of a Sparkplug output would cause repeated write failures that could only be cleared by re-saving the connection.
- Fixed an issue where users could not change the Redundancy Ping Timeout setting in the UI.
- Fixed an issue where Sparkplug inputs with a metric filter would receive unwanted subscription updates for unrelated metrics under the same device.
- Fixed an issue where OPC UA tags with overridden sampling intervals could result in Pipelines failing to start.
- Fixed an issue that prevented the Condition Usage interface from listing the Instances that use the condition.
- Removed requirement in the MCP Client connection for a session ID from the target MCP Server, now aligning with the MCP specification.
- Fixed an issue in Instances where descendant attributes wouldn’t override nested values in the parent value.
Breaking Changes:
- Java 25 is now the minimum version required to run the Intelligence Hub.
- Updated REST Data, MCP, and i3X APIs to share a common TCP port. All existing REST Data endpoints remain unchanged. MCP clients hosted on a separate port are automatically moved to the common port. Shared settings can be configured under Settings > HTTP Server.
- Updated the default HTTP client character set (from ISO-8859-1 to UTF-8). This could cause connections like the REST Client, InfluxDB, and MCP Client connections sending multipart form requests to a server to no longer work due to unsupported content types.
- Changed the way templated Instances and Inputs are mapped to a Namespace node. Previously, all expansions of a template were grouped under a single node with a fixed name, returned as an array. This made it difficult to identify individual expansions. Now, the expansions are placed under a common parent node with a name matching the configured Input/Instance. The child nodes are assigned their template name, or a unique name derived from the parent node. This improves organization, avoids name conflicts, and improves performance. Existing Smart Queries that read nodes mapped to templated Inputs or Instances need to be updated to account for the path change. The path metadata field produced by the Smart Query stage will reflect the new path.
- Ordering of child nodes in the internal HighByte namespace (e.g., Connection Inputs, Instances) is now sorted alphanumerically. Previously, the order depended on the order configuration objects were created. This applies to Namespaces in the UI and Smart Query results.
- 4.4.2 Only: When starting the Intelligence Hub via Docker, the ACCEPT_EULA=Y environment variable is now required; the runtime will not start if it is absent. Review the End User License Agreement before starting the product.
Security Patch Updates:
Runtime:
-
CVE-2026-1225: Defect that could allow crafted input to cause denial of service.
-
CVE-2026-21452: Defect that allows specially crafted input to trigger excessive memory allocation and denial of service.
-
CVE-2026-33701: Defect that allows specially crafted input to potentially achieve remote code execution.
- CVE-2026-25087: Defect that could allow memory corruption or denial of service.
- CVE-2026-39883: Defect that could allow PATH hijacking potentially enabling privilege escalation.
- CVE-2026-40682: Defect that allows specially crafted input to enable file disclosure or server-side request forgery.
- CVE-2026-42440: Defect that allows specially crafted input to trigger unbounded array allocation and potential denial of service.
- CVE-2026-42027: Defect that allows specially crafted input to potentially achieve remote code execution.
- CVE-2026-0994: Defect that could allow denial of service.
S3 Tables:
Azure IoT Hub:
- CVE-2026-33117: Defect that allows an unauthenticated attacker to bypass authentication and gain unauthorized access to resources.
Kafka Connection:
- CVE-2026-33557: Defect in Apache Kafka's default OAUTHBEARER JWT validator that allows an attacker to authenticate as any user by presenting an unvalidated JWT token.
PostgreSQL Connection:
- CVE-2026-42198: Defect that allows a malicious server to cause unbounded CPU consumption and denial of service.
SQLite Connection:
- CVE-2025-70873: Defect that could allow a crafted ZIP file to leak sensitive heap memory contents.
MQTT Broker, REST Server, REST API:
- CVE-2026-42581: Defect in Netty's HTTP/1.0 handling that allows requests with coexisting Transfer-Encoding and Content-Length headers to be used for request smuggling.
- CVE-2026-33870: Defect in Netty's HTTP/1.1 chunked transfer encoding parsing that allows crafted requests to be used for request smuggling.
- CVE-2026-33871: Defect in Netty's HTTP/2 implementation that could allow a denial of service.
- CVE-2026-42582: Defect in Netty's HTTP/3 QPACK decoder that could allow a denial of service.
- CVE-2026-42585: Defect in Netty's HTTP request decoder that allows malformed Transfer-Encoding headers to be used for request smuggling.
- CVE-2026-42578: Defect in Netty's HTTP proxy handler that allows CRLF sequences in user-controlled headers to enable HTTP header injection.
- CVE-2026-42584: Defect in Netty's HttpClientCodec that allows certain pipelined HTTP request sequences to cause response desynchronization.
- CVE-2026-42587: Defect in Netty's HttpContentDecompressor that could allow the maximum allocation limit to be bypassed for certain content encodings, leading to a decompression bomb denial of service.
- CVE-2026-42583: Defect in Netty's LZ4 frame decoder that could allow a crafted compressed frame to trigger unbounded memory allocation, leading to denial of service.
- CVE-2026-42579: Defect in Netty's DNS codec that allows input validation to be bypassed in the encoder and decoder, potentially enabling DNS response manipulation.
- CVE-2026-44248: Defect in Netty's MQTT decoder that could allow MQTT 5 header properties to be buffered without size limits, enabling resource exhaustion.
Frontend:
-
CVE-2025-13465: Defect that allows prototype manipulation through crafted object paths.
-
CVE-2025-64756: Defect that allows crafted filenames to trigger command injection and arbitrary command execution.
-
CVE-2025-64718: Defect that allows prototype pollution when parsing malicious YAML input.
-
CVE-2025-68470: Defect that allows crafted navigation paths to trigger unintended redirects to external URLs.
-
CVE-2026-21884: Defect that allows cross-site scripting through improperly sanitized input during server-side rendering.
-
CVE-2026-22029: Defect that could allow improper input handling, leading to potential denial of service.
-
CVE-2026-22030: Defect that could allow improper input handling, leading to potential denial of service.
-
CVE-2026-25639: Defect that could allow improper input validation, leading to denial of service.
-
CVE-2026-27606: Defect that allows path traversal to overwrite files on the host filesystem.
-
CVE-2026-27903: Defect that allows crafted glob patterns to cause excessive processing and denial of service.
-
CVE-2026-29063: Defect that allows prototype pollution through crafted input, potentially altering object behavior.
Ignition Module:
-
CVE‑2023‑28154: Defect that allows mishandled import parsing to enable cross‑realm object access and potential code compromise.
-
CVE‑2024‑43788: Defect that could allow cross‑site scripting via improper input validation.
-
CVE-2025-15284: Defect that allows attackers to bypass array limits and exhaust server resources via crafted requests.
-
CVE‑2025‑30359: Defect that could allow source code exposure when serving content from a development server.
-
CVE‑2025‑30360: Defect that could allow source code exfiltration via inadequate WebSocket origin validation.
-
CVE-2025-68157: Defect that could allow specially crafted input to cause denial of service.
-
CVE-2025-68458: Defect that could allow improper handling of input leading to unintended behavior or denial of service.
-
CVE-2026-2391: Defect that could allow memory corruption, leading to potential code execution.
-
CVE-2026-22029: Defect that could allow improper input handling, leading to potential denial of service.
Patch (4.4.1 2026.4.14.7)
- Fixed an issue with the EventTrigger when subscribing to OPC UA Branches, OPC UA Collections, and Sparkplug Inputs where the ‘All’ setting only returned changes. The trigger now returns all values (tags or metrics), including those that changed. The ‘Compressed’ option has been renamed to ‘Changed’.
- Added a new Index Window Mode option to PI System Point and Asset reads to control when the read returns data. Modes include Strict or Best Effort. Best Effort is the default behavior and returns data even if the full Index Window isn’t available. Strict only returns data and updates the Index if the full Index Window is available.
- Added support for Basic128Rsa15 in OPC UA Connections.
- Updated i3X server to the Beta version of the specification.
Patch (4.4.2 2026.5.21.2)
- Fixed an issue to correctly capture PI Asset Read Get selection of “Interpolate” vs. “Raw Values”.
- Fixed an issue where projects that were created in version 4.0 and contained pipelines with event triggers failed to import in version 4.4.
- Added Primary Host support to SparkplugB. When enabled, publishes ONLINE/OFFLINE state messages on connect/disconnect.
- Updated i3X Server to support the latest Beta changes to the spec in preparation for version 1.0.
- When starting the Intelligence Hub via Docker, the ACCEPT_EULA=Y environment variable is now required; the runtime will not start if it is absent. Review the End User License Agreement before starting the product.
- Added support to the PI System connector for exposing categories for assetmetadata, asset, and eventframe input types.
Patch (4.4.3 2026.6.30.8)
Fixes:
- Fixed an issue where pipelines were slow to update when using templated flow triggers after saving a configuration change.
- Fixed an issue where System and Environment Variable References were not resolved when building subscription identifiers for Event and Flow triggers.
- Fixed an issue in the Kafka connection where the peer port and host were not forwarded for SSL.
- Fixed an issue where S3 List operation was capped at 1000 results.
- Fixed an issue to consistently use clean sessions in the MQTT connection to the broker for the UNS client.
- Added Primary Host support to SparkplugB. When enabled, publishes ONLINE/OFFLINE state messages on connect/disconnect.
- Added support for i3X v1.0.
- Removed the new Index Window Mode option to PI System Point and Asset reads to control when the read returns data that was added in the 4.4.1 patch.
Security Patch Updates:
Runtime:
- CVE-2026-54512: Defect that allows crafted JSON with generic type parameters to bypass the configured allowlist and instantiate arbitrary classes during deserialization, potentially enabling remote code execution.
- CVE-2026-54513: Defect that allows array-wrapped types to bypass the configured allowlist during deserialization, enabling instantiation of non-allowlisted classes and potentially remote code execution.
- CVE-2026-54514: Defect that allows attacker-controlled JSON to trigger outbound DNS resolution before any application-level validation, enabling server-side request forgery.
- CVE-2026-54515: Defect that allows certain JSON configuration settings to unintentionally restore access to properties that were meant to be excluded during deserialization.
Amazon Redshift:
- CVE-2026-8178: Defect that allows attacker-controlled JDBC connection properties with a datatype. prefix to be passed to Class.forName(), enabling arbitrary class loading and remote code execution.
SQLite:
- CVE-2026-11822: Defect in SQLite's FTS5 extension that could allow a crafted database to trigger memory corruption, leading to a crash or arbitrary code execution.
- CVE-2026-11824: Defect in SQLite's FTS5 extension that could allow a crafted database to trigger a heap buffer overflow, leading to a crash or arbitrary code execution.
MQTT Broker, REST Server, REST API:
- CVE-2026-44249: Defect in Netty's IpSubnetFilterRule that allows IPv6 subnet access-control rules to be bypassed by valid public IP addresses due to an incorrect masking operation.
- CVE-2026-44250: Defect in Netty's RedisArrayAggregator that could allow deeply nested Redis arrays to cause memory exhaustion, leading to denial of service.
- CVE-2026-44890: Defect in Netty's RedisDecoder that could allow unbounded direct memory consumption when decoding Redis responses, leading to denial of service.
- CVE-2026-44892: Defect in Netty's HTTP/3 codec that could allow an unbounded HTTP/3 header size in the default configuration to cause denial of service.
- CVE-2026-44893: Defect in Netty's HAProxy codec that could allow a memory leak when processing SSL TLV entries with invalid lengths, leading to resource exhaustion.
- CVE-2026-44894: Defect in Netty's QUIC codec that allows a crafted Initial packet with a client-supplied token to bypass the anti-amplification limit and reflect handshake traffic to a spoofed victim.
- CVE-2026-45416: Defect in Netty's SniHandler that could allow a crafted TLS ClientHello to trigger excessive memory pre-allocation, leading to denial of service.
- CVE-2026-45674: Defect in Netty's DNS resolver that allows malicious DNS responses with out-of-bailiwick CNAME records to poison the DNS cache.
- CVE-2026-46340: Defect in Netty's SCTP transport that could allow incomplete SCTP message fragments to be accumulated without bound, leading to memory exhaustion and denial of service.
- CVE-2026-47691: Defect in Netty's DNS resolver that could allow DNS cache poisoning, leading to traffic being redirected to attacker-controlled hosts.
- CVE-2026-48006: Defect in Netty's Redis codec that could allow unbounded memory consumption when decoding Redis data, leading to denial of service.
- CVE-2026-48043: Defect in Netty's HTTP/2 codec that could allow a reference-count leak when processing certain HTTP/2 frames to cause memory exhaustion and denial of service.
- CVE-2026-48059: Defect in Netty's HAProxy codec that could allow unbalanced reference counts when parsing nested PP2_TYPE_SSL TLV entries to cause memory exhaustion.
- CVE-2026-48748: Defect in Netty's HTTP/3 codec that could allow unbounded memory allocation when processing HTTP/3 headers, leading to denial of service.
- CVE-2026-50010: Defect in Netty's TLS handler that causes TLS hostname verification to be accidentally disabled when a plain X509TrustManager is wrapped during SSL context construction.
- CVE-2026-50011: Defect in Netty's Redis codec that could allow unbounded memory consumption when decoding certain Redis responses, leading to denial of service.
Frontend:
- CVE-2026-6733: Defect that could allow an idle socket to be reused after a connection error, causing a subsequent request to be silently dropped or routed incorrectly.
- CVE-2026-6734: Defect that allows a shared connection pool to route requests for multiple origins through the first origin's connection, enabling cross-origin credential exposure and potential HTTPS downgrade.
- CVE-2026-9678: Defect that could allow a crafted Set-Cookie header to bypass cookie scope restrictions, enabling cross-origin cookie injection.
- CVE-2026-9679: Defect that could allow cookies with crafted domain attributes to be sent to unintended origins, enabling credential leakage.
- CVE-2026-9697: Defect that causes the requestTls option to be silently dropped, falling back to default certificate validation and allowing MITM attacks against custom CA configurations.
- CVE-2026-11525: Defect that could allow a server to send an unbounded number of empty continuation frames, causing memory exhaustion and denial of service.
- CVE-2026-53550: Defect that allows repeated YAML aliases in a merge sequence to trigger quadratic CPU exhaustion, leading to denial of service.
- CVE-2026-53571: Defect that could allow NTFS alternate data stream paths and 8.3 short names on Windows to bypass server.fs.deny rules and expose sensitive files such as .env and certificates.
- CVE-2026-53632: Defect that could allow UNC paths on Windows to trigger an outbound SMB connection, leaking the server's NTLMv2 hash to an attacker-controlled host.