# Liquibase Community 5.0.4 Release

**URL:** https://forum.liquibase.org/t/liquibase-community-5-0-4-release/10916
**Category:** General Discussion
**Created:** [August 24, 2026, 9:52pm UTC](https://forum.liquibase.org/t/liquibase-community-5-0-4-release/10916 "2026-08-24T21:52:00Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Pete](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/pete/32/184_2.png) [@Pete](https://forum.liquibase.org/u/Pete)
#### Post date: [August 24, 2026, 9:52pm UTC](https://forum.liquibase.org/t/liquibase-community-5-0-4-release/10916/1 "2026-08-24T21:52:00Z")

</div>

This one’s a security release, and it’s a meaty one. Credentials are now redacted from error messages and logs, passwords get cleared from memory once we’re done with them, and there are new opt-in lockdown flags if you’re running ChangeLogs from less-trusted sources. We also closed off an XML entity trick and fixed a reflected XSS vulnerability in the status servlet.

**🙌 Thank You, Contributors**

29 people contributed to this release, 23 of them for the first time. Thank you for filing issues, submitting PRs, testing, and reviewing! Couldn’t do any of this without that.

Full details, including 30+ fixes across Oracle, PostgreSQL, MySQL/MariaDB, and diff-changelog, are in the release notes.

[Release notes](https://docs.liquibase.com/community/release-notes/liquibase-community-5-0-4-release-notes)

[Get the latest version](https://www.liquibase.com/download-community)

---

<div class="post-metadata">

### Author: ![Pete](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/pete/32/184_2.png) [@Pete](https://forum.liquibase.org/u/Pete)
#### Post date: [August 24, 2026, 9:52pm UTC](https://forum.liquibase.org/t/liquibase-community-5-0-4-release/10916/2 "2026-08-24T21:52:23Z")

</div>


