...
| Scroll Ignore | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
This release includes the following enhancements.
Release Initial release date: October 14, 2025 Automatic Identification of Manual Tests Impacted by Application ChangesYou can now identify an optimized subset of manual tests that need to be run to sufficiently test recent application changes or perform manual regression testing for release. This allows your team to focus testing on only a specific set of tests while still having the confidence that sufficient testing was done. You can see a real-time view of the execution status of each manual test for a given application in a given environment - passed, failed, incomplete, impacted (needs retesting), or not executed. This view automatically updates as you execute tests or whenever the application changes. If the underlying code that is associated with a previously executed manual test changes, the view will automatically update the test status to show that it is impacted and needs retesting. With this summary, you can focus your efforts on manual tests that are impacted or haven't been run yet. If a test is shown as passing and is not impacted - you know that you don't need to run the test again, even if the build has been updated since you ran the test. In addition, Manual Testing in CTP now requires a separate license. conditionalcontent | Product: (SVC) | Product: (SVC) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015AC49EDCB8ED8A16FC0C95 | |||||||||||
See Manual Testing for more information. | ||||||||||||
| Conditional Content | Product: (SOAtest) | Product: (SOAtest) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015A9054C886C0AC137B8C01 | |||||||||||
| Conditional Content | Product: (SOAVirt, Virtualize) | Product: (SOAVirt, Virtualize) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015CF6008A11EEF43AC91334 0A010204015A9054C88802B9600247DF | |||||||||||
| Conditional Content | Product: (SOAtest, Virtualize) | |||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015A9054C886C0AC137B8C01 0A010204015A9054C88802B9600247DF | |||||||||||
| Conditional Content | Product: (SVC) | Product: (SVC) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015AC49EDCB8ED8A16FC0C95 | |||||||||||
| Conditional Content | Product: (SOAVirt, SOAtest) | Product: (SOAVirt, SOAtest) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015CF6008A11EEF43AC91334 0A010204015A9054C886C0AC137B8C01 | |||||||||||
See Creating Tests with the AI Assistant for more information. | ||||||||||||
| Conditional Content | Product: (SOAVirt, Virtualize) | Product: (SOAVirt, Virtualize) | ||||||||||
| sv-attr:0A010204015A9054C88481D043445E2F | 0A010204015CF6008A11EEF43AC91334 0A010204015A9054C88802B9600247DF |
| Anchor | ||||
|---|---|---|---|---|
|
The new Attachments tool allows you to add MIME attachments to an outgoing message before it is sent. This tool is primarily used to add binary attachments to a SOAP message according to the "SOAP with Attachments" (SwA) specification. This replaces the SwA functionality that was removed in the 2024.1 release. See Attachments Tool for more information.
Additional Updates
- SOAtest and Virtualize now ships with Eclipse 2025-09.
- Support for Windows 10 has now ended.
- You can now specify a request or response for the asynchronous socket listener and transport using hex values in a String, making it easier to configure the payloads. See Asynchronous Socket Transport and Asynchronous Socket Listener for more information.
- CTP users with an LLM Integration license can now access the Parasoft Intelligent Digital Assistant (IDA) from the Help menu in CTP. The Parasoft IDA is an LLM-powered chatbot designed to answer user's questions about Parasoft products.
Conditional Content Product: (Virtualize) Product: (Virtualize) sv-attr:0A010204015A9054C88481D043445E2F 0A010204015A9054C88802B9600247DF It is no longer necessary to pass a license to the Java or .NET coverage tools when creating a static coverage file for usage in application coverage workflows.
Conditional Content Product: (SOAVirt, SOAtest) Product: (SOAVirt, SOAtest)sv-attr:0A010204015A9054C88481D043445E2F 0A010204015CF6008A11EEF43AC91334 0A010204015A9054C886C0AC137B8C01 It is no longer necessary to pass a license to the Java or .NET coverage tools when creating a static coverage file for usage in application coverage workflows.
- Parasoft Search now scans environments in .tst and .pva files.
- SOAtest reports now include errors for .tst files that did not run because SOAtest couldn't open them.
- Standalone tools now resolve variables in the input tab text mode.conditionalcontent
Product: (SOAVirt, SOAtest) Product: (SOAVirt, SOAtest) sv-attr:0A010204015A9054C88481D043445E2F 0A010204015CF6008A11EEF43AC91334 0A010204015A9054C886C0AC137B8C01 Remote OS Command Injection (Time Based) rule added to supported Penetration Testing Rules.
Conditional Content Product: (Virtualize) Product: (Virtualize) sv-attr:0A010204015A9054C88481D043445E2F 0A010204015A9054C88802B9600247DF Remote OS Command Injection (Time Based) rule added to supported Penetration Testing Rules.
Resolved PRs and FRs
SOAtest and Virtualize
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| LT-1614 | Cannot load reports over 2GB |
| SOA-18611 | YAML .tst with large traffic in Traffic Viewers takes long time to open |
| SOA-18640 | FTP Client throwing exception: Algorithm negotiation fail |
| SOA-18651 | Some test assets no longer open after being resaved |
| SOA-18715 | Leading "." not ignored in the "Domain" attribute of the "Set-Cookie" header |
| SOA-18743 | Only one data source row used for individually runnable test with parameterized output tool |
| SOA-18796 | Ignore Chrome 140 requests to https://www.google.com/async/folae?async=_fmt:pb |
| SOA-18852 | Empty string not accepted in Form Input for "dateTime" if "Enforce schema type" disabled |
| VIRT-7866 | Open API definition with wild card content creates Form JSON view with XML errors |
| VIRT-7971 | "Generate Data Repository Data Source" option not available in responder when status code is parameterized |
| VIRT-7973 | Cache failed authentication credentials to avoid frequent polling of CTP/PSTsec |
| VIRT-7981 | Parasoft JDBC Driver - recording select that joins tables with same columns without alias submits result that are missing columns |
CTP
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CTP-10188 | Limit history in new test execution jobs to 10 runs by default |
| CTP-10365 | When creating PVA in CTP, HTTP endpoint is not created |
| CTP-10439 | Resolve ${dtp_project} variable in EM component coverage build ID |
| CTP-10481 | Aggregate hit statistic summaries in the background to speed up report load time |
Updates in 2025.3.1
SOAtest and Virtualize
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2025-66614 | Critical vulnerability resolved by updating to tomcat version 10.1.52 |
| SOA-19034 | Disabled test suites set test variables |
| VIRT-8076 | Hybrid mode improved to be more robust when the Virtualize server is offline |
CTP
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CTP-10633 | |
| HTTP listener setting is not correctly applied and always resets to Virtualize server port | |
| CTP-10640 | |
| Lazy load test execution job histories when expanding a job in the tree | |
| CTP-10675 | |
| Aggregate hit statistic data in the background every 30 minutes for the utilization report | |
| CTP-10677 | |
| Optimize loading large number of test execution jobs on the resource permissions page | |
| CTP-10699 | |
| Lazy load folders and sub-folders in the Virtual Assets page |
Updates in 2025.3.2
SOAtest and Virtualize
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-29145 | Critical vulnerability resolved by updating to tomcat version 10.1.54 |
| CVE-2026-34197 | High-severity vulnerability resolved by updating to ActiveMQ version 5.19.5 |
| SOA-19243 | Data source payloads containing environment variables no longer resolve |
CTP
Resolved FRs and PRs
| scroll-tablelayout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CTP-10827 | |
| Test execution jobs with long error messages use up lots of memory in CTP |
Updates in 2025.3.3
SOAtest and Virtualize
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-29062 | High-severity vulnerability resolved by updating to jackson-core 3.1.2 |
| CVE-2026-33701 | Critical vulnerability resolved by updating opentelemetry to 2.28.1 |
| CVE-2026-35568 | High-severity vulnerability resolved by updating to mcp-core 1.1.3 |
| CVE-2026-39304 CVE-2026-40466 CVE-2026-41044 CVE-2026-45505 | High-severity vulnerabilities resolved by updating activemq to 5.19.7 |
| CVE-2026-41293 CVE-2026-43515 | Critical vulnerability resolved by updating tomcat to 10.1.55 |
| CVE-2026-41838 CVE-2026-41842 CVE-2026-41848 CVE-2026-41850 CVE-2026-41851 | High-severity vulnerabilities resolved by updating spring framework to 6.2.19 |
| CVE-2026-42402 CVE-2026-42403 CVE-2026-42404 | High-severity vulnerabilities resolved by updating neethi to 3.2.2 |
| CVE-2026-44930 | Critical vulnerability resolved by updating CXF to 4.1.7 |
| SOA-19368 | Data source variables no longer resolve when they are used inside another column from the same data source. |
CTP
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-22732 | |
| Critical vulnerability resolved by updating to spring-security-core version 6.5.9 | |
| CVE-2026- | Cannot load reports over 2GB |
| SOA-18611 | YAML .tst with large traffic in Traffic Viewers takes long time to open |
| SOA-18640 | FTP Client throwing exception: Algorithm negotiation fail |
| SOA-18651 | Some test assets no longer open after being resaved |
| SOA-18715 | Leading "." not ignored in the "Domain" attribute of the "Set-Cookie" header |
| SOA-18743 | Only one data source row used for individually runnable test with parameterized output tool |
| SOA-18796 | Ignore Chrome 140 requests to https://www.google.com/async/folae?async=_fmt:pb |
| SOA-18852 | Empty string not accepted in Form Input for "dateTime" if "Enforce schema type" disabled |
| VIRT-7866 | Open API definition with wild card content creates Form JSON view with XML errors |
| VIRT-7971 | "Generate Data Repository Data Source" option not available in responder when status code is parameterized |
| VIRT-7973 | Cache failed authentication credentials to avoid frequent polling of CTP/PSTsec |
| VIRT-7981 | Parasoft JDBC Driver - recording select that joins tables with same columns without alias submits result that are missing columns |
| 22737 | High-severity vulnerability resolved by updating to spring-core version 6.2.17 |
| CVE-2026-33937 | Critical vulnerability resolved by updating to handlebars.js version 4.7.9 |
Updates in 2025.3.4
SOAtest and Virtualize
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-9563 | High-severity vulnerability by updating parsson to 1.1.9 |
| CVE-2026-53917 CVE-2026-50734 | High-severity vulnerabilities by updating activemq to 5.19.8 |
| CVE-2026-54512 CVE-2026-54513 | High-severity vulnerabilities by updating jackson-databind to 2.21.4 |
| CVE-2026-55276 CVE-2026-53434 CVE-2026-59083 CVE-2026-59084 | Critical vulnerabilities resolved by updating tomcat to 10.1.57 |
| VIRT-8474 | SOAVirt REST API - Progressive performance decreases over time when creating extensionTools |
CTP
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-33701 | Critical vulnerability resolved by updating opentelemetry to 2.28.1 |
| CVE-2026-39304 CVE-2026-40466 CVE-2026-41044 CVE-2026-45505 | High-severity vulnerabilities resolved by updating activemq to 6.2.6 |
| CVE-2026-41838 CVE-2026-41842 CVE-2026-41848 CVE-2026-41850 CVE-2026-41851 | High-severity vulnerabilities resolved by updating spring framework to 6.2.19 |
| CVE-2026-42402 CVE-2026-42403 CVE-2026-42404 | High-severity vulnerabilities resolved by updating neethi to 3.2.2 |
| CVE-2026-44930 | Critical vulnerability resolved by updating CXF to 4.1.6 |
| CVE-2026-4800 | Critical vulnerability resolved by updating lodash to 4.18.1 |
| SOA-19415 | java.lang.NoClassDefFoundError: javax/xml/ws/http/HTTPException |
Updates in 2025.3.5
SOAtest and Virtualize
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-8763 CVE-2026-58062 | Critical vulnerabilities resolved by updating bc-fips to 2.1.3 |
| CVE-2026-54225 CVE-2026-64958 CVE-2026-65432 | High-severity vulnerabilities resolved by updating CXF to 4.1.8 |
| CVE-2026-59878 | High-severity vulnerability resolved by updating activemq to 5.19.9 |
| CVE-2026-66142 CVE-2026-66143 CVE-2026-66144 | High-severity vulnerabilities resolved by updating neethi to 3.2.3 |
CTP
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-9563 | High-severity vulnerability by updating parsson to 1.1.9 |
| CVE-2026-53917 CVE-2026-50734 | High-severity vulnerabilities by updating activemq to 6.2.7 |
| CVE-2026-54399 CVE-2026-54428 | High-severity vulnerabilities by updating httpcore to 5.4.3 |
| CVE-2026-54512 CVE-2026-54513 | High-severity vulnerabilities by updating jackson-databind to 2.21.4 |
Updates in 2025.3.6
CTP
Resolved FRs and PRs
| Scroll Table Layout | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| ID | Description |
|---|---|
| CVE-2026-8763 CVE-2026-58062 | Critical vulnerabilities resolved by updating bc-fips to 2.1.3 |
| CVE-2026-54225 CVE-2026-64958 CVE-2026-65432 | High-severity vulnerabilities resolved by updating CXF to 4.1.8 |
| CVE-2026-59878 | High-severity vulnerability resolved by updating activemq-client 6.2.8 |
| CVE-2026-66142 CVE-2026-66143 CVE-2026-66144 | High-severity vulnerabilities resolved by updating neethi to 3.2.3 |