Release Notes for OpenCms 22
October 6, 2026: OpenCms 22 moves to Jakarta EE and supports modern servlet containers such as Tomcat 10 and Jetty 12. It introduces the optional Deduplicating Media Storage Engine (DMSE), which eliminates duplicate media content at the storage level and can move binaries out of the database to S3-compatible object storage. In typical installations, this shrinks the database by around 40%; with binaries on S3, the reduction is 80% or more. For content managers, OpenCms 22 shows the validity period of time-controlled elements directly in the page editor and uses real placeholder texts in the content editor. This version also generates an llms.txt file for AI crawlers and agents, adds partial-word search in galleries, and improves the selection of global and local categories.
Main new features of OpenCms 22
- Support for Tomcat 10 and Jakarta EE
- New deduplicating media storage engine (DMSE) for binary content
- Display of time-controlled elements in the page editor
- Generation of an llms.txt file for the website
- Placeholder texts in the content editor
- Search for partial words in galleries
- Option to not extract metadata from PDF files for search
- Improved selection of global and local categories
- Redirects in navigations can optionally be opened in a new window
Further improvements in OpenCms 22
- Workplace: Date fields accept 24:00 as midnight of the following day
- Workplace: The link gallery widget no longer uses an iframe
- Workplace: Optional client label in the request context and the session table
- Workplace: Cache app supports time-based cleanup of the image cache with progress reporting
- Workplace: The "About" dialog shows the Java EE version and a shortened Git message
- Workplace: More robust CSV user import with better error handling
- Core API: Detail page resolution without a servlet request
- Core API: Methods to find out where an ADE configuration value is defined
- Core API: Configurable element marker handler for container pages
- Core API: The publish history uses the online path for files moved out of deleted folders
- Core API: Fewer permission cache flushes and cached OU lookups for role checks
- Core API: Custom EL resolver for better JSP performance on Jetty
- Core API: Content extraction policy API for formatters
- Solr: Basic auth credentials for external Solr servers
- Solr: Exclude containers from indexing by name or type via sitemap attributes
- Solr: Option to skip metadata extraction for PDF, RTF and MS Office documents
- Solr: Content fields keep the order of the XML content
- Solr: More reliable clients with fixed timeouts, HTTP/1.1 and proper shutdown
- Solr: Improved normalization of folder values in search queries
- Solr: Search results of an unknown resource type are now permission checked
- WebDAV: All init parameters of the Jackrabbit WebDAV servlet can be configured
- Shell: New commands to add a bookmark with a title and to remove a user from a role
- Gradle build: Updated to Gradle 9.4 with Java 25 support
- Gradle build: Tests migrated to JUnit 6
- Gradle build: Source formatting enforced with Spotless
- Gradle build: New opencms_variant property to add a suffix to generated Maven artifacts
- Libraries: Migrated to commons-fileupload2, commons-email2 and Jakarta Mail
- Libraries: Updated GWT
- Pull request #849 fixes the CSV user import with UTF-8 BOM and improves its error handling, provided by rgaviras (github pull #849)
- Pull request #848 fixes silently swallowed Solr core initialization failures, provided by gallardo (github pull #848)
- Pull request #846 reports a NullPointerException in CmsADEConfigData.hasFormatters() for resource types without a schema, provided by gallardo, not merged but fixed independently (github pull #846)
- Pull request #845 adds the missing HttpOnly flag in CmsFlexResponse#addCookie, provided by Thyodas (github pull #845)
- Pull request #844 fixes typos in the German localization, provided by Rainer559 (github pull #844)
Bug fixes in OpenCms 22
- Security: Fixed remote code execution through static export of .jspx files
- Security: Fixed deserialization vulnerability in the database import
- Security: Fixed XXE vulnerability in OpenOffice document indexing
- Security: Fixed unauthenticated Solr aggregation leak by removing the OpenCmsSolrHandler
- Security: Fixed path traversal through the "exportname" property, reported by pig-tail (https://github.com/pig-tail)
- Security: Fixed issue with login bean accepting protocol-relative redirect URIs, reported by Fushuling (github issue #843)
- Security: Fixed missing HttpOnly flag in CmsFlexResponse#addCookie (github pull #845)
- Fixed category selection when overlapping categories are displayed by repository
- Fixed removing a category from a folder also removing it from all resources in that folder
- Fixed accidental relation removal caused by missing escaping of underscores
- Fixed nested setting includes not being resolved from the ADE configuration
- Fixed content folder type index for types configured in a master configuration
- Fixed inconsistent handling of formatters for types with a missing content definition, also reported in pull request #846
- Fixed default path prefixes in OpenCmsUrlServletFilter also matching longer names, for example "/services" blocking "/services_page"
- Fixed GWT RPC exception messages not reaching the client
- Fixed CmsSolrQuery#createTextQuery for multiple text search fields
- Fixed CmsContainerBean#getSimpleName()
- Fixed MIME types for .ott, .tcl and .tk in opencms-vfs.xml
- Fixed Jetty components pulled in by Solr conflicting with container libraries
General OpenCms features
- The page editor allows WYSIWYG inline editing of web pages and arrangement of content by drag & drop.
- The form based editor allows editing of structured content in a well defined form mask.
- The sitemap editor allows to create new pages and re-arrange the navigation tree by drag & drop.
- Responsive "Mercury" default template based on Bootstrap 4 with many features.
- Headless API for accessing content as JSON from external applications.
- Content creation for mobile devices with preview and device specific content control.
- Structured contents can be defined using a simple XML schema.
- Easy to use "Online / Offline" workflow, changes must be approved before they become visible.
- Link management for all internal resources with broken link detection.
- Integrated image scaling and cropping.
- SEO features with automatic sitemap.xml generation and page alias support.
- Full featured user management that supports the concept of "Organizational Units" (OUs).
- Allows management of multiple websites within one installation.
- Contents can be served dynamically or exported to static HTML files.
- File access to the OpenCms content repository over a shared network / SMB drive.
- CMIS and WebDAV access to the OpenCms content repository.
- Integrates Apache SOLR for powerful content searching and noSQL like queries.
- Full text search for web pages as well as in office documents like PDF, MS Office and Open Office.
- Extensions can be added through a flexible module system.
- The "time warp" feature allows to view resources which are expired or not yet released.
- JSP integration for dynamic functionality in templates, dynamic forms etc.
- ... and many more
Backward compatibility
OpenCms 22 is available in two variants built from the same code base: a Jakarta variant for Tomcat 10, and a legacy Java EE 8 variant for existing Tomcat 9 installations.
The Jakarta variant (Tomcat 10 / EE 10) is not compatible with older OpenCms versions. Templates and other OpenCms developed code needs at least an import change from javax.servlet to jakarta.servlet to be compatible.
The legacy OpenCms 22 variant (Tomcat 9 / EE 8) is backwards compatible with all OpenCms versions from 10 to 21. Templates and other OpenCms developed code from these versions should mostly work “out of the box” with version 22.
Note for Alkacon OCEE users: Alkacon OCEE users will need a new OCEE version for OpenCms 22. The update is free for Alkacon customers with a current OCEE subscription. Please contact Alkacon to obtain the new version.
Further details about the switch to Jakarta
Compatibility with Java versions, servlet containers and databases
OpenCms 22 is compatible with Java 25 and 21.
The Jakarta OpenCms 22 variant requires a Java Servlet 6.0 compliant web container. We have tested this release with Jetty and Tomcat. It works with Jetty 12 or Tomcat 10.1.
The legacy OpenCms 22 variant (Tomcat 9 / EE 8) requires a Java Servlet 4.0 compliant web container. We have tested this release with Jetty and Tomcat. It works with Jetty 12 or Tomcat 9.
Others have reported successful deployments of OpenCms on other web servlet containers like WildFly, GlassFish, WebLogic, WebSphere and Resin.
On the database side, we provide support for MySQL, MariaDB, Oracle, PostgreSQL, MS SQL Server, DB2 and HSQLDB.