Skip to content

Releases: processone/ejabberd

26.09

Choose a tag to compare

@github-actions github-actions released this 30 Sep 09:34

Release notes copied from the original ejabberd 26.09 announcement post:

We are pleased to announce the publication of ejabberd 26.09, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.

Contents:

Security fixes

This release contains fixes for those security issues:

  • Unauthenticated Remote Code Execution on ejabberd (reported by Gia Bui) when:
    • ejabberd versions is at least 25.10
    • BOSH is enabled on any port
    • S2S is enabled
    • mod_adhoc_api is loaded
    • outbound connectivity from ejabberd on ports epmd (default 4369), s2s (default 5269) and Erlang distribution port (dynamically assigned, typically in the range 49152-65535 unless FIREWALL_WINDOW is set in ejabberdctl.cfg).
  • DoS attack on 16.12+ versions if BOSH is enabled on any port.
  • Cross-Tenant MUC, Roster and Shared-Roster unauthorized access (reported by Hoang Gia).

Fixed the ordering of some XML child elements

There was a reference-ordering problem in the fast_xml generator, it generated XML encoders that could reorder child elements in a different order from the one declared in the codec specification. From now, the order is the one declared in the codec specification. See details in processone/fast_xml#53

Additionally there was an incorrect sasl2_continue declaration order in the xmpp erlang library: it declared "additional-data, text, tasks". Now it follows the ordering defined in XEP-0388 schema: "additional-data, tasks, text". See details in processone/xmpp#112

New option for CAPTCHA POW

New toplevel option captcha_pow adds a SHA-256 hashcash challenge as described in XEP-0158 in the CAPTCHA form, alongside the image challenge or on its own.

Unlike the image challenge, this does not require setting the option captcha_cmd.

This option is used only by mod_register when registering a new account using In-Band Registration, not in MUC rooms or in mod_register_web. It is disabled by default.

Improved support for vhost-admins

It is well known how to grant administrative privileges to an account: by adding that account to an acl called admin:

acl:
  admin:
    user: admin1@localhost

The default ejabberd configuration uses this admin ACL in many places:

Consequently, that admin account can administer all of ejabberd: all the global features, all the modules, in all the vhosts... For now let's call it a "global admin".

If you have several vhosts, you can allow specific accounts to administer only specific vhosts. Let's call them "vhost-admins". In this example admin1@localhost can execute commands on all vhosts. Additionally, localhost has a vhost-admin, second has two vhosts-admins, and third has a vhost-admin:

hosts:
 - localhost
 - second
 - third

acl:
  admin:
    user: admin1@localhost

append_host_config:
  localhost:
    acl:
      aclhostadmin:
        - user: hostadmin@localhost
  second:
    acl:
      aclhostadmin:
        - user: hostadmin@second
        - user: hostadmin@third
  third:
    acl:
      aclhostadmin:
        - user: hostadmin@second

api_permissions:
  "vhost http access":
    from: mod_http_api
    who:
      access:
        allow:
          - acl: admin
        allow:
          - acl: aclhostadmin
    what: "*"

Example call of a vhost command by a vhost-admin:

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/status_num_host?host=second&status=dnd'
7

If a vhost-admin tries to execute an API command directed to a vhost he does not administer, or a global command (that has no host argument, and affects all ejabberd), they are rejected:

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/status_num_host?host=third&status=dnd'
{"code":32,
 "message":"AccessRules: Account does not have the right to perform the operation.",
 "status":"error"}

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/stats?name=registeredusers'
{"code":32,
 "message":"AccessRules: Account does not have the right to perform the operation.",
 "status":"error"}

ChangeLog

Security fixes

  • Unauthenticated Remote Code Execution on ejabberd
  • DoS attack on BOSH
  • Cross-Tenant MUC, Roster and Shared-Roster unauthorized access

Core

  • Add force value to auth_external_user_exists_check option
  • Add XEP-0158 SHA-256 hashcash CAPTCHA challenge (#4594)
  • Add gen_mod:get_module_proc_check()
  • Fix to preserve reference order in XML, done in fast_xml and xmpp (#4606)
  • Get rid of couple *_to_atom
  • Make ejabberd_cluster:*call operate only on known nodes
  • More fixes for arguments in commands for vhost-admin
  • Optimize acl:load_tab()
  • ejabberd_systemd: Prefer matching over length/1
  • Updated Portuguese-Brazil and Chinese-Simplified translations

Modules

  • mod_auth_fast: Make sure that fast tokens can be used only with method that they were created for
  • mod_invites: don't apply overuse limit if max_invites is infinity (#4615)
  • mod_invites: don't crash in get_invite_by_invitee_t if reset_token present (#4620)
  • mod_invites: now that Conversations is for free we remove Yaxim (#4621)
  • mod_mix: Make access_create rule be applied when creating channel
  • mod_mqtt: Add lower limits for pre-auth packets
  • mod_muc_room: Fix handling of hats request with missing xdata
  • mod_muc_rtbl: Accept also plain account and domain JIDs
  • mod_muc_rtbl: Fix handling of remote ban servers (#4622)
  • mod_register: After changing password disallow password change on currently authenticated sessions

SQL

  • Add db_serialize to mod_privacy and mod_pubsub
  • Add rename_column op to ejabbrd_sql_schema update routines
  • Make rename_column compatible with older mysql versions
  • ejabberd_sql_schema: Escape all column/table names
  • Update mod_roster serializer with info about approved field

Administration

  • Allow vhost-admin to execute MUC commands for his vhost (#4603)
  • Fix method to check vhost-admin permission in Host API (#4619)
  • WebAdmin: Fix shared roster page when visited by vhost-admin
  • WebAdmin: For vhost-admins, hide useless link to node page
  • WebAdmin: Show proper domain in URLs, not the first configured vhost

Installers and Container

  • make-binaries: Bump Elixir to 1.19.6
  • make-binaries: Bump Erlang/OTP version to 28.5.0.7
  • make-binaries: Bump Expat version to 2.8.5
  • make-binaries: Bump JPEG version to 10
  • make-binaries: Bump OpenSSL 3.6.4
  • make-binaries: Bump PNG version to 1.6.58
  • make-binaries: Bump SQLite version to 3530400
  • make-binaries: Bump WebP version to 1.6.0
  • Dockerfile: Workaround to get image with amd64 (#4598)

Full Changelog

26.07...26.09

Acknowledgments

We would like to thank for the security reports provided by:

the contributions to the source code by:

  • rallep71 for the fixes in fast_xml and xmpp XML child ordering
  • [Mr...
Read more

26.07

Choose a tag to compare

@github-actions github-actions released this 30 Jul 17:27

Release notes copied from the original ejabberd 26.07 announcement post:

We are publishing this security release ejabberd 26.07, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.

Contents:

Changes in SQL schema

If you upgrade ejabberd from a previous release to 26.07, there are no changes in SQL schemas, but there is one for ejabberd Business Edition (see below).

Security fixes

This release contains fixes for those security issues:

  • It's possible to craft PLAIN auth request and authenticate as one user, but then open session for different one.
  • mod_caps persistent cache can be poisoned by using legacy version requests.This cache was only used to determine list of nodes that should trigger notifications in PubSub presence-based delivery.
  • SQL injection in mod_pubsub handling of paging requests.
  • Possible atom exhaustion that can be triggered by issuing REST requests to mod_http_api.
  • It was possible to make ejabberd send redirect response for OAuth requests to unvetted url. This required enabling ejabberd to act as OAuth provider (by adding request handler for ejabberd_oauth in http listener). As part of this fix we changed oauth_client_id_check default value to db.
  • using ejabberd as OAuth provider will be only allowed by clients
    that were previously registered with oauth_add_client_password or oauth_add_client_implicit commands.
  • Tokens generated by mod_bosh, captcha, mod_auth_fast, mod_http_upload and mod_invites used not cryptographically strong random number generators.
  • Files server by mod_http_upload didn't have XSS prevention headers.
  • Issues in authentication of SIP requests.
  • Request to web_admin were lacking CSRF protection.
  • It was possible to skip captcha verification in mod_register_web.
  • mod_conversejs allowed putting unescaped value from url in page content.

mod_invites: New pages to create invites and WebAdmin

mod_invites now includes a startpage where regular users can use their account credentials to generate new account creation invites.

This is useful for people using XMPP clients that do no support that feature. The URL of that page is the root of mod_invites; you can find a link to that page in the bottom of WebAdmin left menu.

There are also new WebAdmin pages to view the existing invites, generate new invites, expire, delete ... Go and take a look at WebAdmin > "Virtual Hosts" > one of your hosts > "Invites"

mod_conversejs: Support ConverseJS 14

ConverseJS published version 14.0.0 recently, and it requires some changes in the web server. In this sense, mod_conversejs is updated to support ConverseJS 14, and also got other minor cosmetic improvements.

Erlang/OTP 27.0 as a soft minimum

Are you compiling ejabberd with Erlang/OTP 25 or 26? Then please try to update to Erlang/OTP 27, 28, or 29. For example, the ejabberd installers are compiled with Erlang/OTP 28.5.0.4.

ejabberd supports compilation with Erlang/OTP 25 and 26, and those versions are still tested in runtime.yml and weekly.yml, but those Erlang/OTP versions are not actively maintained anymore by Erlang/OTP.

Following the erlang security recommendation to Use Actively Maintained Versions of Erlang/OTP, from now ejabberd softly rejects compilation with Erlang/OTP lower than 27.

What does softly mean? If you really want to compile ejabberd with Erlang/OTP lower than 27 at your own risk, you can bypass that soft requirement by defining this option (Erlang/OTP 25.0 included Erlang Run-Time System 13.0, and that is the number to provide in that option):

./configure --with-min-erlang=13.0

Rebar/Rebar3: Update binaries to work with Erlang/OTP 26-29

ejabberd source code includes Rebar and Rebar3 binaries, in case you don't have installed in your system. But those programs only support four Erlang releases (26 up to 29).

If you want to compile ejabberd with Erlang 25, then you need to grab a compatible Rebar3 (or Rebar) binary: either install one from your operating system, or you can download the old binaries included with ejabberd 26.04 (those still supported Erlang 25):

https://github.com/processone/ejabberd/raw/26.04/rebar
https://github.com/processone/ejabberd/raw/26.04/rebar3

ChangeLog

Security fixes

This release contains fixes for those issues:

  • It's possible to craft PLAIN auth request and authenticate as one user, but then open session for different one.
  • mod_caps persistent cache can be poisoned by using legacy version requests.
    This cache was only used to determine list of nodes that should trigger notifications in PubSub presence-based delivery.
  • SQL injection in mod_pubsub handling of paging requests.
  • Possible atom exhaustion that can be triggered by issuing REST requests to mod_http_api
  • It was possible to make ejabberd send redirect response for OAuth requests to unvetted url. This required enabling ejabberd to act as OAuth provider (by adding request handler for ejabberd_oauth in http listener). As part of this fix we changed oauth_client_id_check default value to db
  • using ejabberd as OAuth provider will be only allowed by clients
    that were previously registered with oauth_add_client_password or oauth_add_client_implicit commands.
  • Tokens generated by mod_bosh, captcha, mod_auth_fast, mod_http_upload and mod_invites used not cryptographically strong random number generators.
  • Files server by mod_http_upload didn't have XSS prevention headers.
  • Issues in authentication of SIP requests.
  • Request to web_admin were lacking CSRF protection.
  • It was possible to skip captcha verification in mod_register_web.
  • mod_conversejs allowed putting unescaped value from url in page content.

Core

  • Fixes delete_old_messages_batch command when used on pgsql
  • Adds export_db_ext which allows exporting db content to json files
  • Use constant time functions when doing password checks
  • Optimize room_unused_* commands when room hibernation is configured
  • We no longer add flag requesting client certificate for tls connections
    where certificate authentication is not enabled

Modules

  • mod_auth_fast: Fixes exception for session that didn't set user agent
  • mod_invites: Add page for creating invites.
  • mod_invites: Fix generation of CSRF tokens.
  • mod_invites: Update to changes in latest XEP-0401
  • mod_http_upload: Attach custom headers from config when serving files.

Full Changelog

26.04...26.07

Acknowledgments

We would like to thank for the security reports provided by:

the contributions to the source code by:

and the translation by:

And also to all the people contributing in the ejabberd chatroom, issue tracker...

Improvements in ejabberd Business Edition

Customers of the ejabberd Business Edition, in addition to all those bugfixes, also get the following changes:

Changes in SQL schema

This release modifies the push_customizations table in the SQL database schemas to support the new push notifications mute option (see below). This task is performed automatically by ejabberd by default.

However, if your configuration file has disabled update_sql_schema toplevel option, you must perform the SQL schem...

Read more

26.04

Choose a tag to compare

@github-actions github-actions released this 20 Apr 14:10

Release notes copied from the original ejabberd 26.04 announcement post:

We are publishing this security release ejabberd 26.04, which includes options to limit XML parser, and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.

Contents:

New limits options for XML parser

This release adds new options that limit max memory used by XML parser used to process XMPP payloads, to prevent potential Denial of Service attack. The default values for pre-auth provide sufficient protection for ejabberd against non-authenticated users on c2s and s2s, so there is no need to change your configuration.

The option max_stanza_elements sets a limit on the maximum number of XML elements that an individual stanza can contain. By default, this option is set to infinity.

The pair of options pre_auth_max_stanza_elements and pre_auth_max_stanza_size define separate limits for sessions that haven't authenticated yet. The session will switch to the limits defined by the options max_stanza_elements and max_stanza_size after the client has successfully authenticated. The default values for these options are: 32 for pre_auth_max_stanza_elements and 8192 for pre_auth_max_stanza_size.

All those options are recognized inside listener sections, and can be applied to ejabberd_c2s and ejabberd_s2s_in listeners.

ChangeLog

Core

  • Add new listener options to limit xml parser accepted input
  • Improve leave_cluster command to work even in own node
  • New predefined keyword DATABASE_PATH that points to the Mnesia spool dir
  • Support HOST keyword in sql_database toplevel option, set nice default value
  • Provide more details in log messages when using SQLite
  • Update documentation of jwt_key to match the Docs site
  • ejabberd_config: New default_ram_db/3 clause that checks module support
  • ejabberd_sm: Remove session_counter, used for get_vh_session_number now removed

Modules

  • mod_http_fileserver: Use integer in ejabberd_hooks:add as expected by "make hooks"
  • mod_invites: Add --enable-bootstrap=no to configure options to bypass download (#4558)
  • mod_invites: don't crash in get_invite_by_invitee_t for sql backend (#4566)
  • mod_invites: quick howto for creating integrity check checksums
  • mod_invites: remove dependency on jquery
  • mod_mqtt: Define RAM callbacks as optional
  • mod_mqtt: Use default_ram_db only if it really supports RAM storage
  • mod_roster: Fix bug introduced in 26.03 in commit d5c1440 (#4564)
  • mod_roster_sql: Cast approved integer as boolean when exporting Mnesia to SQL
  • mod_shared_roster_sql: Fix typo introduced 10 years ago in commit 0ea0ba3

Container and Installers

  • Bump Erlang/OTP 28.4.2
  • make-binaries: Bump OpenSSL to 3.5.6

Full Changelog

26.03...26.04

Acknowledgments

We would like to thank the contributions to the source code, documentation, and translation provided for this release by:

And also to all the people contributing in the ejabberd chatroom, issue tracker...

ejabberd 26.04 download & feedback

As usual, the release is tagged in the Git source code repository on GitHub.

The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.

For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.

The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.

If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.

26.03

Choose a tag to compare

@github-actions github-actions released this 25 Mar 17:13

Release notes copied from the original ejabberd 26.03 announcement post:

We are pleased to announce another bugfix release: ejabberd 26.03. This brings support for roster pre-approval, and more than 100 commits with bugfixes all around, many of them dedicated to the new mod_invites, including also many security fixes.

If you are upgrading from a previous version, there is a change in the SQL schemas, please read below. There are no changes in configuration, API commands or hooks.

Contents:

Changes in SQL schema

This release adds a new column to the rosterusers table in the SQL database schemas to support roster pre-approval. This task is performed automatically by ejabberd by default.

However, if your configuration file has disabled update_sql_schema toplevel option, you must perform the SQL schema update manually yourself. Those instructions are valid for MySQL, PostgreSQL and SQLite, both default and new schemas:

ALTER TABLE rosterusers ADD COLUMN approved boolean NOT NULL AFTER subscription;

SASL channel binding changes

This version adds ability to configure handling of client flag "wanted to use channel-bindings but was not offered one".
By default ejabberd will abort connections that present this flag, as that could mean that between server and client is
rogue MITM proxy that strips exchanged data with informations that are required for this.

This can cause problems for servers that use proxy server that terminated TLS connection (there is MITM proxy, but approved by server admin). To be able to handle this situation, we added code that ignore this flag, if server admin disable channel-binding handling by disabling -PLUS auth mechanisms in config file:

disable_sasl_mechanisms:
  - SCRAM-SHA-1-PLUS
  - SCRAM-SHA-256-PLUS
  - SCRAM-SHA-512-PLUS

We also ignore this flag for SASL2 connections if offered authentication methods filtered by available user passwords did disable all -PLUS mechanisms.

ChangeLog

Core

  • Fix mysql authentication for tls connections that required auth plugin switch
  • Improve handling of scram "wanted to use channel-bindings but was not offered one" flag
  • Add ability for mod_options values to depend on other options
  • Don't fail to classify stand-alone chat states
  • Fix some warnings compiling with Erlang/OTP 29 (#4527)
  • ejabberd_ctl: Document how to set empty lists in ejabberdctl and WebAdmin
  • ejabberd_http: Add handling of Etag and If-Modified-Since headers to files served by mod_http_upload
  • ejabberd_http: Ignore whitespaces at end of host header
  • SQL: Add ability to mark that column can be null in e_sql_schema
  • Tests: Add tests for sasl2
  • Tests: Make table cleanup in test more robust

Modules

  • mod_fast_auth: Offered methods are based on available channel bindings
  • mod_http_api: Always hide password in log entries
  • mod_mam: Call store_mam_message hook for messages that user_mucsub_from_muc_archive was filtering out
  • mod_mam_sql: Only provide the new XEP-0431 fulltext field, not old custom withtext
  • mod_muc_room: Fix duplicate stanza-id in muc mam responses generated from local history (#4544)
  • mod_muc_room: Fix hook name in commit 7732984 (#4526)
  • mod_pubsub_serverinfo: Don't use gen_server:call for resolving pubsub host
  • mod_roster: Add support for roster pre-approval (#4512)
  • mod_roster: Fix display of groups in WebAdmin when it's a list
  • mod_roster: in WebAdmin page, first execute SET actions, later GET
  • mod_roster_mnesia: Improve transformation code

mod_invites

  • Makefile: Run invites-deps only when files are missing
  • Fix path to bootstrap files
  • Check at start time the syntax of landing_page option (#4525)
  • Send 'Link' http header (#4531)
  • Set meta.pre-auth to skip redirect_url if token validated (#4535)
  • Many security fixes (#4539)
  • Add favicon and change color to match ejabberd branding
  • Enable dark mode
  • Add support for webchat_url
  • Migrate to bootstrap5 and update jquery
  • No inline scripts
  • Make format csrf token
  • Add csrf token to failed post
  • Include js/css deps in static dir
  • Correct hashes for bootstrap 4.6.2
  • Hint at type for landing_page opt
  • Many more security fixes (#4538)
  • Check CSRF token in register form
  • Add integrity hashes to scripts and css
  • Comment unused resources
  • Add security headers
  • Remove debug log of whole query parameters (including pw)
  • Don't crash on unknown host from http host header
  • Make creating invite transactional
  • Set overuse limits (#4540)
  • Fix broken path when behind proxy with prefix (#4547)

Container and Installers

  • Bump Erlang/OTP 28.4.1
  • make-binaries: Bump libexpat to 2.7.5
  • make-binaries: Bump zlib to 1.3.2
  • make-binaries: Enable missing crypto features (#4542)

Translations

  • Update Bulgarian translation
  • Update Catalan and Spanish translations
  • Update Chinese Simplified translation
  • Update Czech translation
  • Update French translation
  • Update German translation

Acknowledgments

We would like to thank the contributions to the source code, documentation, and translation provided for this release by:

And also to all the people contributing in the ejabberd chatroom, issue tracker...

Improvements in ejabberd Business Edition

Customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes, also get the following changes:

  • Add p1db backend for mod_auth_fast
  • Fix issue when cleaning MAM messages stored in p1db
  • mod_unread fixes
  • Web push fixes

Full Changelog

26.02...26.03

ejabberd 26.03 download & feedback

As usual, the release is tagged in the Git source code repository on GitHub.

The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.

For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.

The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.

If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.

26.02

Choose a tag to compare

@github-actions github-actions released this 11 Feb 10:12

Release notes copied from the original ejabberd 26.02 announcement post:

Contents:

ChangeLog

  • Fixes issue with adding hats data in presences send by group chats (#4516)
  • Removes mod_muc_occupantid modules, and integrates its functionality directly into mod_muc (#4521)
  • Fixes issue with reset occupant-id values after restart of ejabberd (#4521)
  • Improves handling of mediated group chat invitations in mod_block_stranger (#4523)
  • Properly install mod_invites templates in make install call (#4514)
  • Better errors in mod_invites (#4515)
  • Accessibility improvements in mod_invites (#4524)
  • Improves handling of request with invalid url encoded values in request handled by ejabberd_http
  • Improves handling of invalid responses to disco queries in mod_pubsub_serverinfo
  • Fixes conversion of MUC room configs from ejabberd older than 21.12
  • Fixes to autologin in WebAdmin

If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.

Notice that mod_muc now incorporates the feature from mod_muc_occupantid, and that module has been removed. You can remove mod_muc_occupantid in your configuration file as it is unnecessary now, and ejabberd simply ignores it.

Check also the commit log: 26.01...26.02

Acknowledgments

We would like to thank the contributions to the source code and translations provided by:

And also to all the people contributing in the ejabberd chatroom, issue tracker...

Improvements in ejabberd Business Edition

Customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes, also get the following change:

  • Change default_ram_db from mnesia to p1db when using p1db cluster_backend

ejabberd 26.02 download & feedback

As usual, the release is tagged in the Git source code repository on GitHub.

The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.

For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.

The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.

If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.

26.01

Choose a tag to compare

@github-actions github-actions released this 21 Jan 21:23

Release notes copied from the original ejabberd 26.01 announcement post:

We are pleased to announce ejabberd 26.01. This release addresses real operational pain points: export your data from one database backend and import it into another, and let your users invite others without opening the gates to spam.

This release is the result of three months of development, implementing those new features, and fixing bugs.

Release Highlights:

If you are upgrading from a previous version, there are no mandatory changes in SQL schemas, configuration, API commands or hooks. However new mod_invites uses a new table in databases, see below.

Other contents:

Below is a detailed breakdown of the improvements and enhancements:

Database Serialization

This feature adds new way for migrating data between database backends by exporting data from one backend to a file and importing that into different backend (or possibly to same backend but on different machine).

Migrating data using this can be executed by first exporting all data with export_db command, changing configuration of ejabberd and switching modules to use new database backend, and then importing previously exported data using import_db command.

This mechanism works by calling those new command from ejabberdctl, for exporting data:

  • ejabberdctl export_db <host name> <path to directory where exported files should be placed>
  • ejabberdctl export_db_abort <host name>
  • ejabberdctl export_db_status <host name>

and for importing:

  • ejabberdctl import_db <host name> <path to directory with exported data>
  • ejabberdctl import_db_abort <host name>
  • ejabberdclt import_db_status <host name>

Exporting and importing work in background after starting them from ejabberdctl (commands executed by ejabberdctl have time limit for how long they can work, with this setup there should be not issue with export or import getting aborted by that), and current progress of background operation can be tracked by calling corresponding *_db_status command. Operation in progress can be also aborted by executing *_db_abort command.

Roster Invites and Invite-based Account Registration

Until now the canonical method to register an account in ejabberd was to let anybody register accounts using In-Band Registration (IBR) (mod_register) or Web Registration (mod_register_web), and then try to limit abuse with access limitations or CAPTCHAs. Often this process got abused, with the result that account registration had to be disabled and rely on manual registration by administrators.

The new mod_invites implements support for invite-based account registration: administrators can generate invitation URLs, and send them to the desired users (by email or whatever). Then the user that receives an invitation can visit this invitation URL to register a new account.

On top of that, mod_invites lets you create Roster Invites: you can send a link to some other person so they can connect to you in a very user-friendly and intuitive way that doesn't require any further interaction. If account creation is allowed, these links will also allow to setup an account in case the recipient doesn't have one yet.

Relevant links:

Quick setup:

  1. If using SQL storage for the modules and have disabled the update_sql_schema toplevel option, then create manually the SQL table, see below.

  2. If you plan to use the landing page included with mod_invites, install JavaScript libraries jQuery version 3.7.1 and Bootstrap version 4.6.2. This example configuration will assume they are installed in /usr/share/javascript. The ejabberd container image already includes those libraries. Some quick examples, in case you need some help:

    • Debian and related:

      apt install libjs-jquery libjs-bootstrap4
    • AlpineLinux and other operating systems where you can install npm, for example:

      apk -U add --no-cache nodejs npm ca-certificates
      
      npm init -y \
        && npm install --silent jquery@3.7.1 bootstrap@4.6.2
      
      mkdir -p /usr/share/javascript/jquery
      mkdir -p /usr/share/javascript/bootstrap4/{css,js}
      cp node_modules/jquery/dist/jquery.min.js /usr/share/javascript/jquery/
      cp node_modules/bootstrap/dist/css/bootstrap.min.css /usr/share/javascript/bootstrap4/css/
      cp node_modules/bootstrap/dist/js/bootstrap.min.js /usr/share/javascript/bootstrap4/js/
    • Generic method using the included script:

      tools/dl_invites_page_deps.sh /usr/share/javascript
  3. Configure ejabberd to serve the JavaScript libraries in path /share; serve mod_invites in any path of your selection; and enable mod_invites with some basic options. Remember to setup mod_register to allow registering accounts using mod_invites. For example:

    listen:
      - port: 5443
        ip: "::"
        module: ejabberd_http
        tls: true
        request_handlers:
          /invites: mod_invites
          /share: mod_http_fileserver
    
     modules:
      mod_http_fileserver:
        docroot:
          /share: /usr/share/javascript
      mod_invites:
        access_create_account: configure
        landing_page: auto
      mod_register:
        allow_modules:
          - mod_invites
  4. There are many ways to generate invitations:

    • Login with an admin account, then you can execute Ad-Hoc Commands like "Invite User" and "Create Account"
    • If mod_adhoc_api is enabled, you can execute equivalent API Commands generate_invite and generate_invite_with_username
    • Run those API Commands from the command-line, for example: ejabberdctl generate_invite localhost
  5. All those methods give you an invitation URL that you can send it to the desired user, and looks like

    https://localhost:5443/invites/Yrw5nuC1Kpxy9ymbRzmVGzWQ
    
  6. The destination user (or yourself) can visit that invitation URL and follow the instructions to register the account and download a compatible client.

If the user has installed already a compatible XMPP client, you don't no need to install JavaScript libraries and setup a landing page. In that case, when generating an invitation you will get only the XMPP URI; when the user opens that URI in a web browser, it will automatically open the XMPP client and the corresponding registration window.

Probably you don't want to expose the port directly, then you need to setup Nginx or Apache to act as a "reverse" proxy and change your landing_page parameter accordingly, for example just https://@HOST@/invites/{{ invite.token }}

Notice that the landing page can be fully translated using the existing ejabberd localization feature.

SQL table for mod_invites

There is a new table invite_token in SQL schemas, used by the new mod_invites. If you want to use this module, there are two methods to update the SQL schema of your existing database:

If using MySQL or PosgreSQL, you can enable the option update_sql_schema and ejabberd will take care to update the SQL schema when needed: add in your ejabberd configuration file the line update_sql_schema: true

Notice that support for MSSQL in mod_invites has not yet been implemented or tested.

If you are using other database,...

Read more

25.10

Choose a tag to compare

@github-actions github-actions released this 28 Oct 17:20

Release notes copied from the original ejabberd 25.10 announcement post:

Release Highlights:

If you are upgrading from a previous version, there are no mandatory changes in SQL schemas, configuration, API commands or hooks.

Other contents:

Below is a detailed breakdown of the improvements and enhancements:

New option archive_muc_as_mucsub in mod_mam

When this option is enabled incoming groupchat messages for users that have MucSub subscription to a room from which message originated will have those messages archived after being converted to mucsub event messages.

Removed support for Erlang/OTP older than 25.0

The ejabberd 24.12 release announcement explained that support for Erlang/OTP older than 25.0 was discouraged, it would be deprecated in future releases, and completely removed sometime after ejabberd 25.01. That explanation was mentioned several times in the subsequent ejabberd releases.

The initial reason to require Erlang/OTP 25 was that this version is the lowest we can easily use nowadays for running the CI tests.

Other reasons to remove support for Erlang lower than 25 are: to support maybe expression, and to remove duplicate code.

In order to support both new and very old Erlang/OTP versions, ejabberd source code included many duplicate code. All that duplicate code that is nowadays useless will be removed in a future ejabberd release.

Support for the new Erlang 'maybe' expression

The new maybe expression is supported since Erlang/OTP 25 (requires being enabled), and it is enabled by default since 27.

Now that ejabberd requires Erlang/OTP 25, and it enables the maybe expression, this can be used freely in ejabberd source code and modules.

See:

Rename 'New' SQL schema to 'Multihost', and 'Default' to 'Singlehost'

When ejabberd first got support for SQL storage, it only supported one vhost, so it made sense to not store the host in the SQL tables. Additionally, the SQL schema in ejabberd followed that of jabberd14, which didn't support multiple vhosts either.

When ejabberd got support for multiple vhosts, if several of them want to use SQL storage, the solution is to configure a different SQL database for each vhost using the host_config toplevel option.

However, when there are many vhosts configured in ejabberd, all of them using SQL storage, it is preferable to setup one single SQL database, and store the vhost in the tables. When that feature was added to ejabberd, it got the name of "new SQL schema". And the previous SQL schema was called "legacy", "old", and nowadays "default".

The problem with the terms "default" and "new" is that they are circumstantial, and do not really describe the schema features or purposes.

Now those terms have been renamed:

  • "default SQL schema" ⟹ "singlehost SQL schema"
  • "new SQL schema" ⟹ "multihost SQL schema"

Right now all names are supported, the previous (obsolete) and the renamed (preferred). No changes are needed in your existing configuration file or building instructions, but it is preferable if you can update your setup to the new terms:

When preparing configuration, the old and new arguments are:

./configure --enable-new-sql-schema
./configure --enable-multihost-sql-schema

When configuring ejabberd, the old and new toplevel options are:

new_sql_schema: true
sql_schema_multihost: true

When developing source code, the old and new functions are:

ejabberd_sql:use_new_schema()
ejabberd_sql:use_multihost_schema()

New API Commands

Several ejabberd modules implement new API Commands, most of them inspired by XEP-0133:

Added more Ad-Hoc Commands from XEP-0133

XEP-0133 describes 31 administrative tasks that should be available as ad-hoc commands.

ejabberd already implemented many of those ad-hoc commands in mod_configure, but there were a few missing that nowadays are fairly easy to implement: this new ejabberd release supports all of them... except 5.

The five ad-hoc commands from XEP-0133 that are not supported are:

  • 6. Get User Password, because it was already retracted in the XEP and should not be implemented
  • 12. Edit Whitelist, because the corresponding feature is not implemented in ejabberd
  • 27. Set Welcome Message, because in ejabberd this message is set in the configuration file, option welcome_message of mod_register
  • 28. Delete Welcome Message, for similar reason
  • 29. Edit Admin List, because in ejabberd the administrative rights to accounts are granted in the configuration file, toplevel option acl.

On the other hand, ejabberd implements more than 200 API commands in all over its source code, providing those and many other administrative tasks. And you can execute those API commands using the command line, ReST calls, XML-RPC, WebAdmin, ... and ad-hoc commands too!!! See the available API frontends.

Nowadays, all the ad-hoc commands described in XEP-0133 have a similar API command in ejabberd that you can execute using ad-hoc commands too:

Ad-hoc command in XEP-0133 Status in ejabberd 25.10 Equivalent API command
Add User 〽️ (no vCard arguments) register
Delete User ✅ unregister
Disable User ✅ ban_account
Re-Enable User ✅ unban_account
End User Session 〽️ (argument) kick_session
Get User Password (retracted) ▶️ (retracted) check_password
Change User Password ✅ change_password
Get User Roster 〽️ (result syntax) get_roster
Get User Last Login Time ✅ get_last
Get User Statistics ✅ user_sessions_info
Edit Blacklist ▶️ add_blocked_domain
Edit Whitelist ❌ -
Get Number of Registered Users ✅ stats
Get Number of Disabled Users ✅ count_banned
Get Number of Online Users ✅ stats
Get Number of Active Users ✅ [status_num](https://docs.ejabberd.im/developer/ejabberd-api/admi...
Read more

25.08

Choose a tag to compare

@github-actions github-actions released this 22 Aug 14:31

Release notes copied from the original ejabberd 25.08 announcement post:

Release Highlights:

This release includes the support for Hydra rooms in our Matrix gateway, which fixes high severity protocol vulnerabilities.

If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.

Other contents:

Below is a detailed breakdown of the improvements and enhancements:

Improvements in Matrix gateway

The ejabberd Matrix gateway now supports Hydra rooms (Matrix room version 12). This fix some high severity protocol vulnerabilities. The state resolution has been partially rewritten in our gateway.

A double colon is used for separating a matrix server from a room ID in JID with Hydra rooms.

Other changes to the matrix gateway:

  • The new option notary_servers of mod_matrix_gw can now be used to set a list of notary servers.
  • Add leave_timeout option to mod_matrix_gw (#4386)
  • Don't send empty direct Matrix messages (thanks to snoopcatt) (#4420)

Fixed ACME in Erlang/OTP 28.0.2

The ejabberd 25.07 release notes mentioned that Erlang/OTP 28.0.1 was not yet fully supported because there was a problem with ACME support.

Good news! this problem with ACME is fixed and tested to work when using Erlang/OTP 28.0.2, the latest p1_acme library, and ejabberd 25.08.

If you are playing with ejabberd and Erlang/OTP 28, please report any problem you find. If you are running ejabberd in production, better stick with Erlang/OTP 27.3, this is the one used in installers and container images.

New mod_providers to serve XMPP Providers file

mod_providers is a new module to serve easily XMPP Providers files.

The standard way to perform this task is to first generate the Provider File, store in the disk with the proper name, and then serve the file using an HTTP server or mod_http_fileserver. And repeat this for each vhost.

Now this can be replaced with mod_providers, which automatically sets some values according to your configuration. Try configuring ejabberd like:

listen:
  -
    port: 443
    module: ejabberd_http
    tls: true
    request_handlers:
      /.well-known/xmpp-provider-v2.json: mod_providers

modules:
  mod_providers: {}

Check the URL https://localhost:443/.well-known/xmpp-provider-v2.json, and finetune it by setting a few mod_providers options.

Improved Unicode support in configuration

When using non-latin characters in a vhost served by ejabberd, you can write it in the configuration file as unicode, or using the IDNA/punycode. For example:

hosts:
  - localhost1
  - locälhost2
  - xn--loclhost4-x2a
  - 日本語

host_config:
  "locälhost2":
    modules:
      mod_disco: {}
      mod_muc:
        host: "conference3.@HOST@"
  "xn--loclhost4-x2a":
    modules:
      mod_disco: {}
      mod_muc:
        host: "conference4.@HOST@"

This raises a problem in mod_http_upload if the option put_url contains the @HOST@ keyword. In that case, please use the new predefined keyword HOST_URL_ENCODE.

This change was also applied to ejabberd.yml.example.

New option conversejs_plugins to enable OMEMO

mod_conversejs gets a new option conversejs_plugins that points to additional local files to include as scripts in the homepage.

Right now this is useful to enable OMEMO encryption.

Please make sure those files are available in the path specified in conversejs_resources option, in subdirectory plugins/. For example, copy a file to path /home/ejabberd/conversejs-x.y.z/package/dist/plugins/libsignal-protocol.min.js and then configure like:

modules:
  mod_conversejs:
    conversejs_resources: "/home/ejabberd/conversejs-x.y.z/package/dist"
    conversejs_plugins: ["libsignal-protocol.min.js"]

If you are using the public Converse client, then you can set "libsignal", which gets replaced with the URL of the public library. For example:

modules:
  mod_conversejs:
    conversejs_plugins: ["libsignal"]
    websocket_url: "ws://@HOST@:5280/websocket"

Easier erlang node name change with mnesia_change

ejabberd uses by default the distributed Mnesia database. Being distributed, Mnesia enforces consistency of its file, so it stores the Erlang node name, which may include the hostname of the computer.

When the erlang node name changes (which may happen when changing the computer name, or moving ejabberd to another computer), then mnesia refused to start with an error message like this:

2025-08-21 11:06:31.831594+02:00 [critical]
  Erlang node name mismatch:
  I'm running in node [ejabberd2@localhost],
  but the mnesia database is owned by [ejabberd@localhost]
2025-08-21 11:06:31.831782+02:00 [critical]
  Either set ERLANG_NODE in ejabberdctl.cfg
  or change node name in Mnesia

To change the computer hostname in the mnesia database, it was required to follow a tutorial with 10 steps that starts ejabberd a pair of times and runs the mnesia_change_nodename API command.

Well, now all this tutorial is implemented in one single command for the ejabberdctl command line script. When mnesia refuses to start due to an erlang node name change, it mentions that new solution:

$ echo "ERLANG_NODE=ejabberd2@localhost" >>_build/relive/conf/ejabberdctl.cfg

$ ejabberdctl live
2025-08-21 11:06:31.831594+02:00 [critical]
  Erlang node name mismatch:
  I'm running in node [ejabberd2@localhost],
  but the mnesia database is owned by [ejabberd@localhost]
2025-08-21 11:06:31.831782+02:00 [critical]
  Either set ERLANG_NODE in ejabberdctl.cfg
  or change node name in Mnesia by running:
  ejabberdctl mnesia_change ejabberd@localhost

Let's use the new command to change the erlang node name stored in the mnesia database:

$ ejabberdctl mnesia_change ejabberd@localhost

==> This changes your mnesia database from node name 'ejabberd@localhost' to 'ejabberd2@localhost'

...

==> Finished, now you can start ejabberd normally

Great! Now ejabberd can start correctly:

$ ejabberdctl live
...
2025-08-21 11:18:52.154718+02:00 [info]
  ejabberd 25.07.51 is started in the node ejabberd2@localhost in 1.77s

Notice that the command mnesia_change must start and stop ejabberd a pair of times. For that reason, it cannot be implemented as an API command. Instead, it is implemented as an ejabberdctl command directly in the ejabberdctl command line script.

Colorized interactive log

When ejabberd starts with an erlang shell using Mix, it prints error lines in a remarkable color: orange for warnings and red for errors. This helps to detect those lines when reading the log interactively.

Now this is also supported when using Rebar3. To test it, start ejabberd either:

  • ejabberdctl live: to start interactive mode with erlang shell
  • ejabberdctl foreground: to start in server mode with attached log output

You will see log lines colorized with:

  • green+white for informative log messages
  • grey for debug
  • yellow for warnings
  • red for errors
  • magenta for messages coming from other Erlang libraries (xmpp, OTP library), not ejabberd itself

Document API Tags in modules

Many ejabberd modules implement their own API commands, and now the documentation of those modules mention which tags contain their commands.

See for example at the end of modules [...

Read more

25.07

Choose a tag to compare

@github-actions github-actions released this 11 Jul 15:26

Release notes copied from the original ejabberd 25.07 announcement post:

We are pleased to announce a new ejabberd release: ejabberd 25.07, with three months of work and more than 110 commits to bring new modules, new features, improvements and bugfixes.

Release Highlights:

This release focus on integration in a wider federated network, with support for spam fighting features, better compliance with Matrix network and native support for PubSub Server Information to have your server count as part of the wider XMPP network (for example, you can register your server on XMPP Network Graph.

If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.

Other contents:

Below is a detailed breakdown of the improvements and enhancements:

Workaround for zip module in unpatched Erlang

A vulnerability was published three weeks ago that affects the zip library included in Erlang/OTP: CVE-2025-4748: Absolute path in zip module.

The ejabberd installers and the ejabberd container image already use a patched version Erlang/OTP 27.3.4.1, but the ecs container image uses Erlang/OTP 26.2.

ejabberd 25.07 includes a specific protection that workarounds that vulnerability regardless of what Erlang/OTP version you are using.

Erlang/OTP 28 supported

Updating ejabberd to support Erlang/OTP 28 has required quite some work due to the replacement of ancient ASN.1 modules from Erlang/OTP public_key library.

Improvements were done on ejabberd, fast_xml, p1_acme, xmpp libraries, and also rebar/rebar3 binaries were recompiled.

However, there is still one last problem not yet solved which implies that ACME support is broken when using Erlang/OTP 28.0.1. The fix will probably be included in the next Erlang/OTP 28 release.

Erlang/OTP 25 required

The minimum Erlang/OTP version supported since now is 25.0.

However, we are aware there are still a few specific cases where older Erlang/OTP versions are being used. For that reason, the source code support for those versions is still available, and static source code analysis tools like xref and dialyzer are still run with Erlang/OTP 20 in runtime.yml.

If you really need to use ejabberd with Erlang/OTP 20 - 24, you can bypass the version check during compilation with this ./configure option: ./configure --with-min-erlang=9.0.5

New mod_antispam with RTBL support

mod_antispam is a new module that filters spam messages and subscription requests received from remote servers based on Real-Time Block Lists (RTBL), text lists of known spammer JIDs and/or URLs mentioned in spam messages.

This module is based in mod_spam_filter which was originally published in ejabberd-contrib. If you were using that module, you can update your configuration and start using mod_antispam instead.

New mod_pubsub_serverinfo

mod_pubsub_serverinfo adds support for XEP-0485: PubSub Server Information to expose S2S information over the Pub/Sub service.

This module was originally published in ejabberd-contrib. If you were using that module, you can remove it, as now it's included in ejabberd.

Improvements in Matrix gateway

While we are preparing another big update for the Matrix gateway. The most important change is that we added support to a larger number of room versions. It allows users to let them join a lot of rooms that were already created a while back and running an older version of the room protocol.

Here is the main list of changes to the matrix gateway:

  • mod_matrix_gw: Support older Matrix rooms versions starting from version 4
  • mod_matrix_gw: Don't send empty messages in Matrix rooms (#4385)
  • mod_matrix_gw: Fix key validation in mod_matrix_gw_s2s:check_signature
  • mod_matrix_gw: When encoding JSON, handle term that is key-value list (#4379)

XEP-0431: Full Text Search in MAM

Support for XEP-0431: Full Text Search in MAM has been added. For now, it only works if mod_mam is using the MySQL storage backend.

New rest_proxy options

With those new options you can make modules using rest.erl module (like ejabberd_oauth_rest) use HTTP proxy when performing HTTP requests.

The related new top level options are:

  • rest_proxy: Address of a HTTP Connect proxy
  • rest_proxy_port: Port of a HTTP Connect proxy
  • rest_proxy_username: Username used to authenticate to HTTP Connect proxy (optional)
  • rest_proxy_password: Password used to authenticate to HTTP Connect proxy (optional)

New auth_password_types_hidden_in_scram1 option

This option was added to help with adding new password types in auth_stored_password_types option to existing installations. Adding new password type made server advertise it to clients, but that caused problems for users that didn't have new password type stored, and which clients used SASL1 authentication, if client tried to authenticate with it, authentications would fail.

With this new option, server admin can choose which password types should not be presented to SASL1 clients (they still will be offered to SASL2 clients for users that have password compatible with this type), to later after users update password to have new type, being able to enable them.

This option takes list of password types from auth_stored_password_types that should be disabled

auth_password_types_hidden_in_scram1:
  - scram_sha512
  - scram_sha256

New hosts_alias option

The new hosts_alias toplevel option is used by the ejabberd_http listener to resolve domain names into vhosts served by ejabberd.

For example, ejabberd is serving the vhost redacted.lan, but you configured DNS so xmpp.redacted.lan resolves to that host. If you configure in ejabberd:

hosts:
  - redacted.lan

hosts_alias:
  xmpp.redacted.lan: redacted.lan

listen:
  -
    port: 443
    ip: "::"
    tls: true
    module: ejabberd_http
    request_handlers:
      "/bosh": mod_bosh
      "/ws": ejabberd_http_ws
      "/conversejs": mod_conversejs

modules:
  mod_bosh:
  mod_conversejs:
    bosh_service_url: "https://xmpp.redacted.lan/bosh"
    websocket_url: "wss://xmpp.redacted.lan/ws"

then ejabberd_http will accept https://xmpp.redacted.lan/conversejs and deliver it to vhost redacted.lan

In previous ejabberd releases, an option called default_host was documented for the ejabberd_http listener, but it didn't work at all correctly.

New predefined keywords

A few months ago, ejabberd 25.03 introduced new predefined keywords like HOST, HOME, VERSION and SEMVER.

And now two more predefined keywords are added:

  • CONFIG_PATH: Path to the configuration directory, for example "/home/ejabberd/opt/ejabberd/conf"
  • LOG_PATH: Path to the log directory, for example "/home/ejabberd/opt/ejabberd/logs"

Those keywords are specially u...

Read more

25.04

Choose a tag to compare

@github-actions github-actions released this 16 Apr 18:48

Release notes copied from the original ejabberd 25.04 announcement post:

Just a few weeks after previous release, ejabberd 25.04 is published with an important security fix, several bug fixes and a new API command.

Release Highlights:

If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.

Other contents:

Below is a detailed breakdown of the improvements and enhancements:

mod_muc_occupantid: Fix handling multiple occupant-id

Fixed issue with handling of user provided occupant-id in messages and presences sent to muc room. Server was replacing just first instance of occupant-id with its own version, leaving other ones untouched. That would mean that depending on order in which clients send occupant-id, they could see value provided by sender, and that could be used to spoof as different sender.

New kick_users API command

There is a new API command kick_users that disconnects all the client sessions in a given virtual host.

Acknowledgments

We would like to thank the contributions to the source code, documentation, and translation provided for this release by:

And also to all the people contributing in the ejabberd chatroom, issue tracker...

Improvements in ejabberd Business Edition

For customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes:

  • Bugfix on max_concurrent_connections for mod_gcm, mod_webhook and mod_webpush

ChangeLog

This is a more complete list of changes in this ejabberd release:

Security fixes

  • mod_muc_occupantid: Fix handling multiple occupant-id

Commands API

  • kick_users: New command to kick all logged users for a given host

Bugfixes

  • Fix issue with sql schema auto upgrade when using sqlite database
  • Fix problem with container update, that could ignore previous data stored in mnesia database
  • Revert limit of allowed characters in shared roster group names, that will again allow using symbols like :
  • Binary installers and ejabberd container image: Updated to Erlang/OTP 27.3.2

Full Changelog

25.03...25.04

ejabberd 25.04 download & feedback

As usual, the release is tagged in the Git source code repository on GitHub.

The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.

For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.

The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.

If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.