Skip to content

Releases: apache/cloudstack

Apache CloudStack 4.20.3.0 (LTS)

17 Apr 08:12

Choose a tag to compare

Apache CloudStack 4.22.0.0 (LTS)

11 Nov 14:25

Choose a tag to compare

Apache CloudStack 4.20.2.0 (LTS)

27 Oct 08:34
4.20.2.0
4dc3931

Choose a tag to compare

Apache CloudStack 4.21.0.0 (Regular)

29 Aug 04:57
f9513b4

Choose a tag to compare

Apache CloudStack 4.20.1.0 (LTS)

10 Jun 14:51

Choose a tag to compare

Apache CloudStack 4.20 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.20.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.20.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.20.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.20.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.20

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain
  • CVE-2025-22829: Unauthorised access to dedicated resources in Quota plugin

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0

Apache CloudStack 4.19.3.0 (LTS)

10 Jun 14:50

Choose a tag to compare

Apache CloudStack 4.19 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.19.3.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.3.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.3.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.3.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0

Apache CloudStack 4.19.2.0 (LTS)

03 Mar 11:01

Choose a tag to compare

Apache CloudStack 4.20.0.0 (LTS)

02 Dec 13:42

Choose a tag to compare

Apache CloudStack 4.19.1.3 (LTS Security Release)

12 Nov 13:46
4.19.1.3

Choose a tag to compare

Apache CloudStack 4.18.2.5 (Security Release)

12 Nov 13:40
4.18.2.5

Choose a tag to compare