Confluence 11.0 release notes
8 October 2026
We're excited to present Confluence 11.0Highlights
- Rate Limiter Settings Enabled By Default
- Rate-limit REST endpoints with annotations
- Confluence Mobile Web Deprecation
- AUI 11
- Asynchronous Macro Execution
- Modernizing and Securing Plugin Data Storage
- Enhanced Security with New Content Security Policy
- Enhanced protection against SSRF
- Custom HTML Editing Now Disabled by Default
- Journal Index Queue Improvements
- Standardize JNDI path validation
- Platform Upgrades for Stability and Resilience
- Logging Modernization to log4j2.xml
- Synchrony logging configuration now uses Log4j 2
- Look and Feel Layouts and Customization Editing Now Disabled by Default
- Restore From Local Drive Now Disabled by Default
- Removal of support for transformed apps
- Sign SAML authentication requests
- V3 Attachment Storage Removal
Further Information
This Confluence release supports only Data Center licenses. If you have a Server license, check out your options for upgrading.
Thanks for your feedback
More than 600 votes satisfied!
Rate Limiter Settings Enabled By Default
For: ADMINS
Confluence 11.0 enables rate limiting by default for automation and application requests. This helps protect Confluence from request bursts that can affect instance stability and availability.
Existing configurations are preserved: If rate limiting is already enabled on your Confluence instance, upgrading to Confluence 11.0 does not change your existing rate-limiting mode or configured limits.
After upgrading, review your rate-limiting configuration in the administration interface. The default limits are intended to suit typical instances, but you can adjust or disable them to match your traffic patterns and integration requirements.
Important for administrators: If you use high-volume automation or integrations, validate their request rates after upgrading and tune the configured limits as needed.
Rate-limit REST endpoints with annotations
For: ADMINS
We've added the ability to rate limit individual REST API endpoints, so a single script, automation, or integration can no longer degrade your instance by hammering one expensive endpoint. Limits apply per user, per node, and requests that exceed them receive an HTTP 429 response with a Retry-After header telling the user when to try again.
As an administrator you can tune or switch off any of these limits using JVM system properties in the com.atlassian.ratelimiting.api.* namespace, without waiting for an app update. This complements the existing rate limiting in your admin settings, which caps a user's total traffic rather than their use of a specific endpoint.
Confluence Mobile Web Deprecation
For: ADMINS
We have disabled the legacy Confluence mobile web interface in Confluence 11.0. This change does not affect the Confluence Data Center mobile app.
When users access Confluence from a mobile browser, Confluence now prompts them to either:
download the Confluence Data Center mobile app, or
continue to the desktop version of Confluence in their browser.
Existing links to the former mobile interface redirect to the corresponding standard Confluence page where possible.
AUI 11
For: ADMINS
We’re introducing AUI 11 with the next major versions of our Data Center products, bringing a refreshed visual experience that aligns more closely with Atlassian Cloud. The update includes refreshed badges, banners, and application headers, a modernised icon set, and updated typography using Atlassian fonts and design system themes.
If you use Marketplace apps or custom in-house apps with a frontend, ensure they’re compatible with the new major version before upgrading.
Asynchronous Macro Execution
For: ADMINS EXPERIMENTAL
Confluence Data Center now supports asynchronous macro execution — a major performance capability that changes how macros are rendered on a page.
Previously, every macro on a Confluence page was executed sequentially on the same HTTP request thread. The browser couldn't receive the page until every last macro had finished — meaning a single slow macro (e.g. a Jira query or a blog-posts roll-up) could block an entire page load for all users.
With this release, macros can be configured to execute asynchronously and concurrently in a dedicated thread pool. The HTTP request thread is freed immediately, and macro results are assembled as they complete. For pages with multiple slow macros, this can dramatically reduce perceived load time.
Configuration required: Yes (opt-in per macro, admin setup)
Concurrent execution
Multiple macros on the same page can now execute in parallel rather than sequentially, significantly reducing total page render time.
Deduplication
If multiple users request the same page simultaneously, identical macro executions (same macro, same parameters, same content) can be deduplicated — one execution runs and its result is shared, avoiding redundant parallel work.
Configurable timeouts and rate limits
Administrators can set per-macro time limits and concurrency limits via the REST API, with global defaults configurable via JVM system properties. If a macro exceeds its time limit, Confluence can signal it to stop gracefully.
Result caching (opt-in)
Macro results can be cached per-user on each node, so repeat visits to the same page don't re-execute expensive macros. Cache TTL and size are configurable.
Execution cancellation
Administrators can cancel in-flight macro executions in real time — by execution ID, by macro name, or all at once — via REST API. Macro developers can implement graceful cancellation support.
Observability
Active macro executions are visible in real time, both via REST API and (on clustered setups) in the Confluence Clustering UI. A scheduled analytics job publishes execution statistics for monitoring.
Safe fallback
If the async thread pool is saturated (queue full or queue latency exceeded), macros fall back to synchronous execution automatically. No requests are dropped.
How to get started
This feature is disabled by default and requires administrator configuration:
Enable the dark feature
atlassian.macros.async.executionin Confluence Dark FeaturesUse the REST API (
PUT /rest/asyncmacros/latest/execution-controls) to configure which macros run asynchronouslyOptionally tune thread pool and timeout settings via JVM system properties
Modernizing and Securing Plugin Data Storage
For: ADMINS
Removal of legacy structures for storing plugin data will secure Confluence for long term stability. After making these legacy systems read-only in Confluence 10.0, we have removed them entirely in Confluence 11.0. This includes the Removal of Bandana, and the removal of OpenSymphony PropertySet (osProperty). For security reasons, Confluence 11.0 will also no longer bundle the XStream library.
Direct access to the Bandana database table and OpenSymphony PropertySet will no longer be possible in Confluence 11.0. Please ensure all Apps that currently use Bandana are migrated to alternative storage (for example, Active Objects or SAL Plugin Settings) before upgrading to Confluence 11.
To make this feasible, upgrade to Confluence 11.0 will be supported only from the latest Confluence 10.2.x release (that is, customers must upgrade to the latest 10.2.13+ before upgrading to 11.0).
Migrating data will no longer be possible in Confluence 11.0 - you must complete migration before you upgrade.
For migration guidance, refer to Preparing for Confluence 10.0 for more information.
The BANDANA table is deprecated and will be removed automatically in a future release. You can drop it now by setting -Dconfluence.enable-drop-bandana-table=true before the upgrade. Back up the table before doing so if you want to retain the data.
Enhanced Security with New Content Security Policy
For: ADMINS
In Confluence 11, the content security policy (CSP) for the "script-src" directive has been introduced. The following adjustments apply:
- All direct and indirect uses of eval are blocked.
- All inline scripts are blocked.
- Scripts loaded from other domains must be allowed via the CSP script-src header.
- Script tags with inline code must include a nonce attribute.
- Keyboard shortcuts with operation type execute are no longer supported.
How is script-src CSP enabled
Confluence 11 enables this by default alongside existing policies. Only system administrators can disable this feature via the configuring of system properties:
http.header.security.content.security.policy.strictness.enabled
(e.g. -Dhttp.header.security.content.security.policy.strictness.enabled=false)
The CSP report-only mode is disabled when the property CSP is enabled (set to true).
There is also a system property http.header.security.content.security.scriptsrc.additional.urls that let admins to allow external scripts if they are needed.
Enhanced protection against SSRF
For: ADMINS
We’re introducing two security enhancements for Confluence, Jira Software, and Jira Service Management Data Center to strengthen protection against Server-Side Request Forgery (SSRF) attacks. These changes help block unauthorized outbound requests to sensitive destinations, ensuring your instance remains secure.
Key changes include:
New default outbound denylist: We’ve added a built-in denylist that automatically blocks requests to dangerous destinations, such as cloud metadata services (AWS, Google Cloud, Azure), private networks, and insecure protocols (for example,
file://andshell://).Extended allowlist enforcement: Several platform components that previously bypassed the allowlist, including OAuth2, Gadgets, Webhooks, and the Universal Plugin Manager (UPM), now strictly follow your allowlist configuration.
DNS resolution checking: The denylist now resolves domain names to their IP addresses to prevent bypass attempts via DNS rebinding.
These protections are enabled by default. They provide immediate security against SSRF attacks without requiring extra configuration. While you can disable the denylist using the -Dssrf.denylist.enabled=false JVM system property, we don’t recommend this for production environments.
While a denylist blocks known-dangerous destinations, we recommend configuring a comprehensive allowlist. An allowlist is the most effective defense against SSRF because it limits outbound requests only to the specific, trusted destinations your instance needs to function.
Custom HTML Editing Now Disabled by Default
For: ADMINS
To improve security, editing custom HTML is now disabled by default. If you need to enable custom HTML, set the confluence.custom.html.config.enabled system property to true. Only system administrators can enable this feature. How to configure system properties
Journal Index Queue Improvements
For: ADMINS
The content index queue is now processed fairly across content types instead of strictly in queue order. Entries are grouped by content type (pages and blogs, attachments, comments, user profiles, custom content, other). As a result, A bulk operation on one content type — a mass attachment upload, a space import — can no longer delay indexing of everything queued behind it. Queue depth per content type is shown on the Content indexing admin page.
This change applies to the content index journal (main_index) only; other journals keep the linear path.
To turn off the fair Index queue, disable the confluence.fair.journal.index.queue dark feature.
Concurrent Processing
Due to the grouping of entries we can now process the entries in batches concurrently, increasing performance. A number of worker threads are made from the CPUs available to the JVM (capped at 50) and the index queue gives each worker at least 100 entries each to process.
To fall back to serial processing, disable the confluence.fair.journal.index.queue.parallel.processing dark feature — no restart is needed.
Standardize JNDI path validation
For: ADMINS
We’re standardizing how our products validate and use Java Naming and Directory Interface (JNDI) paths. Inconsistent checks across different products can sometimes allow crafted inputs to trigger unintended code execution. By unifying these validation processes, we're reducing the risk that a misconfiguration or an overlooked pathway could become a security entry point.
This change helps protect your data and ensures service reliability by aligning all products on a single, safe approach to JNDI lookups.
Platform Upgrades for Stability and Resilience
For: ADMINS
We have been busy at work upgrading the Confluence 11 platform to set Confluence up for success in the long term. In most cases these changes are transparent. However, if you use Marketplace apps or custom in-house apps, ensure they are compatible with the new major version before upgrading. Some of the more notable changes can be seen below.
Update to jQuery 4
We’re upgrading to jQuery 4 to align on jQuery versions across all Data Center products. This means a significant jQuery version uplift for products containing older versions of jQuery.
Java 25 is now the minimum supported version
Starting from Confluence 11, Java 25 is the minimum supported version for both compile and runtime environments. At the same time, all components run on JDK 25.
Upgrade to React 19
We're upgrading to React 19 across all Data Center products to keep our frontend dependencies secure and compliant. This change ensures we can continue upgrading other critical frontend libraries in the future.
Modernize your outgoing network connections (HttpClient 5)
We're modernizing how our products make outgoing network connections by removing an older networking component that's no longer actively maintained: Apache HttpClient 4. This change reduces long-term security and reliability risks and ensures our technology remains supported and aligned with current standards.
Jakarta 11 and Spring 7 upgrade
We’re updating our Jakarta and Spring dependencies to continue meeting your demands for secure and compliant products. This change ensures we stay aligned with security policies and receive the latest updates.
Upgrade to Jackson 3
We’ve upgraded the Jackson library to ensure your instance and apps are secure, compliant, and compatible with the latest industry standards.
For most customers, this change won't affect how you use your apps. However, if you use or develop extensions, take note of the following:
We've notified Marketplace partners of this change. They're responsible for updating their apps to ensure continued compatibility.
If you've developed custom, in-house apps or integrations, your development team must update the Jackson 2 libraries to version 3 in your codebase.
Logging Modernization to log4j2.xml
For: ADMINS
From Confluence 11.0, Log4j 1 configuration and API have been removed for security and modernization. As a result of this, the log4j.properties format will no longer be used and is replaced by log4j2.xml. Below are the affected files:
Up to 10.2.x
<CONFLUENCE-INSTALL>/confluence/WEB-INF/classes/log4j.properties<CONFLUENCE-INSTALL>/confluence/WEB-INF/classes/log4j-diagnostic.properties
From Confluence 11.0
<CONFLUENCE-INSTALL>/confluence/WEB-INF/classes/log4j2.xml<CONFLUENCE-INSTALL>/confluence/WEB-INF/classes/log4j2-diagnostic.xml
Any log4j.properties left in place after an upgrade is ignored, not merged. Confluence logs a warning at startup if it finds these log4j property files. If you customised logging, re-apply those changes to log4j2.xml when upgrading, then delete log4j.properties to silence the warning. Setting log levels at runtime through Logging and Profiling in the admin UI is unchanged.
Synchrony logging configuration now uses Log4j 2
For: ADMINS
Synchrony 7.0.13 (bundled in Confluence 11.0) no longer supports Log4j 1 configuration files or the legacy log4j.configuration system property.
If you do not use a custom Synchrony logging configuration, no action is required. Synchrony uses its bundled Log4j 2 configuration by default.
If you currently use a custom synchrony-log4j.properties file, convert it to a Log4j 2 XML configuration file and configure it using
log4j2.configurationFile.
Confluence-managed Synchrony
Create a Log4j 2 XML configuration file, then add the following to your synchrony-args.properties file:
log4j2.configurationFile=file:///absolute/path/to/synchrony-log4j2.xml
Standalone Synchrony
Create a Log4j 2 XML configuration file, then add the following to OPTIONAL_OVERRIDES in your start-synchrony.sh or start-synchrony.bat script:
OPTIONAL_OVERRIDES="-Dlog4j2.configurationFile=file:///absolute/path/to/synchrony-log4j2.xml"
Look and Feel Layouts and Customization Editing Now Disabled by Default
For: ADMINS
To improve security, configuring Look and Feel customization is now disabled by default. Admins can only view existing layout configurations. To enable look and feel customization, set the confluence.custom.look.and.feel.enabled system property to true. Only system administrators can enable this feature.
Look and Feel customization will be disabled by default at both Global and Space level. Setting the system property to true will enable customization at both the places.
In addition to this, for Space level stylesheet configuration ensure that “Custom Stylesheets for Spaces” is enabled in Security Configuration.
How to configure system properties
Restore From Local Drive Now Disabled by Default
For: ADMINS
To improve application security, restoring of data from local drives is now disabled by default. To enable restoring of data from local drive , set confluence.restore.from.local.drive.enabled system property to true. Only system administrators can enable this feature via the configuring of system properties.
Removal of support for transformed apps
For: ADMINS
We’re removing support for the transformed app format to improve the performance and reliability of Data Center products. Starting with this release, the Universal Plugin Manager (UPM) will no longer install or enable apps using this older format, and we’ve removed the infrastructure that converted these formats at startup. This change helps your instance start faster and reduces the risk of stability issues.
Before you upgrade, ensure your Marketplace apps are compatible with <product name+version>. If you use custom in-house apps, you must migrate them to the transformerless format. The following guides might help you in this process:
Sign SAML authentication requests
For: ADMINS
We’re implementing signed Security Assertion Markup Language (SAML) authentication requests to strengthen your instance’s security. When SAML is enabled, the authentication plugin generates a certificate and private key during startup. The private key signs SAML authentication requests, and you can download the certificate to upload to your Identity Provider (IdP). This lets the IdP verify the authenticity and integrity of each request.
To enable signing SAML authentication requests, go to the Authentication methods page and select Sign requests. Explore SAML single sign-on for Atlassian Data Center applications
V3 Attachment Storage Removal
For: ADMINS
Confluence 8.1 introduced the v4 attachment layout and a background migration that moved attachment data from ver003 to v4. Confluence 11.0 removes version 3 (ver003) attachment storage entirely: the storage implementation, the automatic V3 → V4 migration, and the related APIs.
Note that the V3 → V4 migration no longer runs in Confluence 11.0 and must have been completed prior to upgrading
Supported platforms changes
This section contains a run-down of all the changes that have been made to supported platforms since the last Confluence LTS release. See the complete list of supported platforms
We’ve confirmed support for:
JDK 25
MySQL 8.4
Oracle AI Database 26ai (rebranded from Oracle 23ai)
PostgreSQL 17
OpenSearch 2.11 through to 12.19
This version of Confluence runs only on Java 25.
End of support announcements
We've removed support for:
PostgreSQL 16
Aurora PostgreSQL 16
MS SQL Server 2019
Oracle 19c
- Java 21
We’ve deprecated support for:
- MySQL 8.4
- MS SQL Server 2022
For more information on these notices, see End of Support Announcements for Confluence.
App developers
Head to Preparing for Confluence 11.0 to find out more about changes under the hood. These include but are not limited to:
Jsoup Upgrade
Frontend AMD and WRM Resources Removal
JQuery plugins removal
Removing Bundled Joda time
Atlassian Keyboard Shortcuts Upgrade
Upgrade steps
Always test the upgrade in a test environment before upgrading in production.
To upgrade Confluence to the latest version:
From the Administration menu , select Manage apps, and then Confluence update check to verify the compatibility of your user-installed apps with the target application version.
- From the Administration menu , select General Configuration, and then Plan your upgrade and the version you want to upgrade to. This will run the pre-upgrade checks.
- From the Administration menu , select General Configuration, and then Troubleshooting and support tools to check your license validity, application server, database setup, and more.
- If your version of Confluence is more than one version behind, read the release notes and upgrade guides for all releases between your version and the latest version.
- Back up your installation directory, home directory, and database.
- Download the latest version of Confluence.
- Follow the instructions in the Upgrade Guide.
Update configuration files after upgrading
The contents of configuration files such as server.xml, web.xml , setenv.bat / setenv.sh, and confluence-init.properties change from time to time.
When upgrading, we recommend manually reapplying any additions to these files (such as proxy configuration, datasource, JVM parameters) rather than simply overwriting the file with the file from your previous installation; otherwise you will miss out on any improvements we have made.
Upgrade instructions
You must first upgrade to the latest Confluence 10.2 release first before upgrading to Confluence 11.0.
Follow the usual upgrade instructions to upgrade your site.
Been a while since your last upgrade? Check out our upgrade matrix for a bird's-eye view of the most important changes since Confluence 10.2 LTS .
Don't forget to renew your software maintenance. Renew now
Resolved issues
For full details of bugs fixed and suggestions resolved, head to our public issues tracker on Jira.
Issues resolved in 11.0.0
Released on 08 October 2026
Credits
Our wonderful customers...
You play an important role in making Confluence better. Thanks to everyone who participated in interviews with us, made suggestions, voted, and reported bugs!
