Skip to main navigation Skip to main content Skip to page footer

TYPO3 14.1.1, 13.4.26 and 12.4.43 maintenance releases published

The versions 14.1.1, 13.4.26 and 12.4.43 of the TYPO3 Enterprise Content Management System have just been released.

The following TYPO3 updates have been released:

  • TYPO3 14.1.1
  • TYPO3 13.4.26 LTS
  • TYPO3 12.4.43 LTS

All versions are maintenance releases only.

These releases address a Composer installation issue caused by CVE-2025-45769, a disputed security advisory against the firebase/php-jwt library. From TYPO3's perspective, there is no vulnerability in how the library is used within TYPO3 and no known exploit in this scenario. These releases are published solely to unblock affected Composer-based installations.

Further upgrade instructions

Site maintainers who require firebase/php-jwt v6.x and cannot upgrade at this time can suppress the disputed advisory by running the following command in their project root:

composer config -jm audit.ignore '{"CVE-2025-45769":"disputed"}'

No further database upgrades are required for these maintenance releases.

Download

TYPO3 can be installed in various ways. For example the traditional way by using the source package at get.typo3.org or the modern way by setting up a project using composer, to name just two. Further details can be found in the according release notes:

Maintenance Releases

Plan ahead with TYPO3’s transparent release schedule. See upcoming maintenance and bugfix updates for current LTS versions.