In this release: 
Release date: October 29, 2025 EnhancementsTest Failure ClassificationDashboard Improvements — Widget Discovery and Configuration Enhancements- New Add Widget experience: Introduced a redesigned workflow for discovering and adding widgets.
- Separate configuration UI: Added a dedicated interface for configuring widget settings featuring a live preview that updates instantly as settings are modified.
- Thumbnails for all widgets: All widgets now display thumbnails for easier discovery.
- Fuzzy search: Enabled discovery of widgets when search terms include partial matches.
MCP Server Endpoint - Enables large language models (LLMs) and AI-powered coding assistants that support the Model Context Protocol (MCP), such as GitHub Copilot or Windsurf, to connect directly to DTP.
- Available tools include:
- getTestCountResults: Returns test count results for a given build and optional filter.
- getFailedTestCases: Returns a list of failed or incomplete test cases.
- getTestCasesHistory: Provides more details about failed tests. Retrieves the history of test cases based on provided test case IDs and the specified filter ID.
- getFailedTestCasePredictedLabels: Provides more details about failed tests. Returns a map of test case IDs to their predicted labels for the provided test cases.
- When used together, teams leveraging MCP can quickly gain AI-driven insights into test failures, test stability, and potential root causes.
Important Note for UpgradesIn certain Amazon AWS EC2 environments, the machineId may change after upgrading. If this happens, you will need to acquire a new license for DTP and will need to acquire new network licenses for pre-existing tools. Other Notes- Build Audit Report: In order to improve report generation time and remove redundant data that is available elsewhere in the Build Audit Report under most circumstances, the "Overview of findings by authors" report preference is now disabled by default. SOAtest users should enable this option if they want to include details about failed tests in this report.
- CVE match support for C/C++test: Users can leverage CVE Match in Violations Explorer to identify security violations with the highest likelihood of real security risk.
- Technical Support Archive improvements: Users can specify a time range (log files modified within last x days) when creating an archive.
- Integration with Azure services:
- Added support for new work item creation in Japanese locale.
- Added support for Microsoft Entra Authentication (OIDC) on Azure PostgreSQL.
- Integration with Jira: Updated to support Jira Cloud API changes introduced by Atlassian (CHANGE-2046).
- Test Configuration Editor enhancements:
- Filtering by categories: only see the rules in the selected categories (built-in Parasoft and industry standard categories are available).
- Fuzzy search: enabled searching for rules when search terms include partial matches.
- License Server enhancements:
- New setting: Restrict access to automation licenses. When enabled, License Server will deny access to licenses with automation features unless those features are explicitly requested. This setting is enabled by default.
- Starting with version 2025.2, automation licenses will be granted only to tools that explicitly request the automation feature. This prevents desktop instances from consuming tokens intended for automation use. Both the Parasoft tool and License Server must be version 2025.2 or later and Restrict access to automation licenses setting must be enabled for this behavior to take effect.
- Contributing Developers - Usage Data: License Server now captures and displays additional information about the author of the latest commit in the git repository.
- New setting: Delete Contributing Developers Usage Data older than one year. When enabled, License Server will automatically delete usage data sent from Parasoft C/C++test CT and Parasoft C/C++test Standard after one year. This setting is enabled by default.
- In addition, the License Server setting "Grant license token to login username" is now enabled by default in new installations. Users upgrading to 2025.2 will have their current setting preserved.
- Floating licenses have been relabeled as "concurrent" licenses. No functionality has changed.
- Updated
licenseserver/usage API to support filtering license usage by license.
- SOAtest API coverage widget and report: Provides visibility into how well your tests cover resources and operations.
- Filter Configuration enhancements:
- Access to Parasoft Intelligent Digital Assistance (IDA): DTP users with an LLM Integration license can now access Parasoft IDA from the Help menu in DTP. The Parasoft IDA is an LLM-powered chatbot, trained on product documentation and knowledge base, designed to answer your questions about DTP.
- Added support for CWE 4.18 and CWE Top 25 2024 (C++test).
- CERT Conformance Testing Plan report has been updated to reflect changes in how CERT defines Remediation Cost.
Deprecated or No Longer Supported- Support for Windows 10 has ended.
Software Shipped with DTPThe following software is shipped with DTP 2025.2: - Apache Tomcat: 10.1.48
- Java Azul OpenJDK 17.0.16+8 (17.62.17)
Resolved PRs and FRs
| ID | Description |
|---|
| DTP-29053 | Edit Group dialog in Project Settings should list available users | | DTP-29199 | Include option to add Violation ID when exporting to CSV |
Updates in 2025.2.2Resolved PRs and FRs
| ID | Description |
|---|
| CVE-2025-66614 | Vulnerability resolved by upgrading to tomcat 10.1.52 | | CVE-2026-22732 | Vulnerability resolved by upgrading to spring-security 6.5.9 |
Updates in 2025.2.3Resolved PRs and FRs
| ID | Description |
|---|
| CVE-2026-25896 | Vulnerability resolved by upgrading to fast-xml-parser 5.5.8 | | CVE-2026-33228 | Vulnerability resolved by upgrading to flatted 3.4.2 | | CVE-2026-33937 | Vulnerability resolved by upgrading to handlebars 4.7.9 |
Updates in 2025.2.4Resolved PRs and FRs
| ID | Description |
|---|
| CVE-2025-62718 | Vulnerability resolved by upgrading to axios 1.15.0 | | CVE-2026-4800 | Vulnerability resolved by upgrading to lodash 4.18.1 | | CVE-2026-29145 | Vulnerability resolved by upgrading to Tomcat 10.1.54 |
Updates in 2025.2.5Resolved PRs and FRs
| ID | Description |
|---|
| CVE-2026-2332 | Vulnerability resolved by upgrading to Jetty 12.0.34 | CVE-2026-41691 CVE-2026-48713 | Vulnerability resolved by upgrading to i18next-fs-backend 2.6.6 | | CVE-2026-41691 | Vulnerability resolved by upgrading to i18next-http-backend 3.0.6 | | CVE-2026-41842 | Vulnerability resolved by upgrading to Spring 6.2.19 | | CVE-2026-42043 | Vulnerability resolved by upgrading to axios 1.15.2 | | CVE-2026-43515 | Vulnerability resolved by upgrading to Tomcat 10.1.56 | | CVE-2026-48714 | Vulnerability resolved by upgrading to i18next-http-middleware 3.9.7 | | CVE-2026-47838 | Vulnerability resolved by upgrading to Spring Security 6.5.11 | CVE-2026-54512 CVE-2026-54513 | Vulnerability resolved by upgrading Jackson to 2.21.4 |
Updates in 2025.2.6- Upgraded NodeJS to version 18.20.8
Resolved PRs and FRs
| ID | Description |
|---|
CVE-2025-66168 CVE-2026-34197 CVE-2026-39304 CVE-2026-40466 CVE-2026-41044 CVE-2026-42588 CVE-2026-45505 CVE-2026-49157 CVE-2026-49432 CVE-2026-49434 CVE-2026-49877 CVE-2026-50734 CVE-2026-53916 CVE-2026-53917 CVE-2026-54475 | Vulnerability resolved by upgrading ActiveMQ to version 6.2.7 to address | | CVE-2026-39244 | Vulnerability resolved by upgrading adm-zip to version 0.6.0 | | CVE-2026-52746 | Vulnerability resolved by upgrading jsonata to version 2.2.1 | | CVE-2026-53914 | Vulnerability resolved by upgrading kotlin-stdlib to version 2.4.20 | CVE-2026-55276 CVE-2026-53434 CVE-2026-59083 CVE-2026-59084 | Vulnerability resolved by upgrading Tomcat to version 10.1.57 | | CVE-2026-59724 | Vulnerability resolved by upgrading socket.io to version 4.8.3 | | CVE-2026-59869 | Vulnerability resolved by upgrading js-yaml to version 4.3.0 |
Updates in 2025.2.7- Upgraded Azul JRE to 17.0.20.1+1
- Upgraded Apache Tomcat to 10.1.59
Resolved PRs and FRs
| ID | Description |
|---|
| CVE‐2026‐8763 | Vulnerability resolved by upgrading Bouncy Castle Java FIPS to 2.1.3 | | CVE-2026-59870 | Vulnerability resolved by upgrading js-yaml to 4.3.1 | | CVE-2026-59878 | Vulnerability resolved by upgrading ActiveMQ to 6.2.8 | | CVE-2026-68497 | Vulnerability resolved by upgrading Jackson to 2.21.6 | | CVE-2026-69185 | Vulnerability resolved by upgrading socket.io-parser to 4.2.7 | | CVE-2026-73566 | Vulnerability resolved by upgrading tar to 7.5.22 | | GHSA-2fvj-hgj9-j2gr | Vulnerability resolved by upgrading Jetty to 12.0.37 | | GHSA-gcfj-64vw-6mp9 | Vulnerability resolved by upgrading axios to 1.18.1 |
|