NOW LIVE! ColdFusion 2023.4 and ColdFusion 2021.10 August updates
We are pleased to announce the availability of ColdFusion (2023 release) Update 4 and ColdFusion (2021 release) Update 10. These updates introduce the ColdFusion serial filter that can be used to allow or disallow Java classes or packages for the deserialization of Wddx packets.
What is ColdFusion serial filter?
The cfserialfilter.txt file ensures protection against insecure Wddx deserialization attacks. On the other hand, the already existing serialfilter.txt blocks Java deserialization by disallowing certain Java classes or packages.
How do I download the updates?
Head over to the update pages to download the updates:
What do these updates contain?
Learn more about these updates from the following tech notes:
What else?
- Docker images for ColdFusion 2021 and 2023 will be pushed to AWS ECR and Docker Hub shortly.
- CFFiddle will be updated with ColdFusion 2021 Update 10 and ColdFusion 2023 Update 4 shortly.
Please install these updates and provide us with your feedback.

