Koha 25.11.09 released
RELEASE NOTES FOR KOHA 25.11.09
30 Sep 2026
Koha is the first free and open source software library automation
package (ILS). Development is sponsored by libraries of varying types
and sizes, volunteers, and support companies from around the world. The
website for the Koha project is:
Koha 25.11.09 can be downloaded from:
Installation instructions can be found at:
- Koha Wiki
- OR in the INSTALL files that come in the tarball
Koha 25.11.09 is a bugfix/maintenance release with security patches.
It includes 42 bugfixes (5 security).
System requirements
You can learn about the system components (like OS and database) needed for running Koha on the community wiki.
Security bugs
- 37441 ShowAlerts msg not escaped in tools uploads
- 42674 OS command injection via
jobidin Task Scheduler (tools/scheduler.pl) - 43424 REST Basic Auth bypasses account lockout (8.1 HIGH)
- 43426 admin/item_circulation_alerts.pl cud-toggle performs no authentication check at all (7.5 HIGH)
- 43470 REST Basic Auth allows silent 2FA secret takeover
Bugfixes
About
Other bugs fixed
- 42453 “About Koha” breaks if Elasticsearch is used but unavailable
Accessibility
Other bugs fixed
- 42231 Fix accessibility issues in OPAC summary table
This fixes some accessibility issues on the patron’s OPAC summary section: Form elements must have labels.
- Checked out “Renew” checkbox: adds a hidden label for screen readers
- Add note pop-up window for “Report a problem” (when the AllowCheckoutNotes
system preference is enabled): adds a hidden label for screen readers
It also hides the item title on the report a problem and suspend hold pop-up windows.
Acquisitions
Other bugs fixed
- 42225 On sites with many vendors spent.pl cannot load
This improves the SQL for the spent by fund report (Acquisitions > [All available funds section of the page] > [select amount in the spent column for a fund that has a link]).
This fixes an issue where there was a VERY large number of vendors in a system (260k + !!!), which resulted in a database error:
ERROR 1038 (HY001): Out of sort memory, consider
increasing server sort buffer size - 42571 Sending EDI order results in variable not available warnings
- 42757 Suggester is not passed by purchase-suggestions.pl
This fixes “Suggested by” when making a suggestion for a patron from Patrons > [Selected patron] > Purchase suggestions.“Suggested by” was being recorded as the logged in librarian, instead of the patron that made the suggestion.
Architecture, internals, and plumbing
Other bugs fixed
- 42551 C3 merge error when syntax checking some installed plugins
Cataloging
Other bugs fixed
- 42512 MARC control field length detection prevents editing of records with invalid MARCXML
- 42874 z3950_auth_search is losing index parameter
Circulation
Other bugs fixed
-
41358 action logs info column should always store JSON
Sponsored by OpenFifth
- 41889 /checkouts?checked_in=1 errors when patron_id is null
Command-line Utilities
Other bugs fixed
- 42640 Script search_for_data_inconsistencies.pl should use binmode UTF-8
ERM
Other bugs fixed
- 42825 ERM Local Title – Start date (started_on) not saved for package resources
This fixes adding a title to a package when creating a new title for ERM – the start date for the title was not saved (ERM > eHoldings > Titles > New title > Packages > Add new package).
- 42933 ERM – Error adding a license to an agreement when leaving non-mandatory fields empty
This fixes an issue for the ERM module when adding a license to an agreement. The status field for the license was not shown as required. This generated an error message if you attempted to add a license without selecting a value for the status field: “Something went wrong: Error: Expected string – got null.”. The status field is now marked as required.(Related to Bug 38201 – VueJS architecture rethink, added to Koha 25.11.)
Hold requests
Critical bugs fixed
- 42999 $valid_items flag contamination in reserve/request.pl causes non-holdable items to appear as available after the first holdable item in the loop
This fixes placing holds using the staff interface for a specific item, where there is an item that has a “Not for loan” status.
Previously, you could select the item that is not for loan.
Now the item that is not for loan has an “X Not for loan” in red in the hold column, and you can’t select it.
- 43033 Holds queue allocate with transport cost matrix can choose impossible holds
Other bugs fixed
- 42357 Holds table is missing patron name
This fixes the holds table for a bibliographic record in the staff interface. It now shows the patron’s name in addition to the patron’s card number.
(Use existing system HidePatronName system preference to hide patron names, for example for privacy reasons at circulation desks.)
- 42909 Suspend class missing from suspended holds on request.pl
This fixes the holds table for a record in the staff interface to restore the “suspend” class to the table row for suspended holds, allowing styling by libraries.
ILL
Other bugs fixed
- 42617 ILL availability pagination not working
MARC Authority data support
Other bugs fixed
-
42920 Looking up authority records in Advanced editor appends 20 extra spaces
Sponsored by Chetco Community Public Library
OPAC
Critical bugs fixed
- 42654 Regression: Section missing from OPAC course reserve detail page
This fixes the course reserves page and navigation in the OPAC so that if a course has a value in the section field, then this value is now shown on the OPAC course detail page after the course name in the page title, breadcrumb, and main heading.
Example: Course reserves for ‘Course name’ – Section
Other bugs fixed
- 41796 “Forgot your password” link is not visible if OpacResetPassword is enabled but OpacPasswordChange is disabled
- 42066 CSRF-token sometimes missing from pages
- 42159 With OPACAuthorIdentifiersAndInformation information lacking from field 110/111
This fixes the “Author information” tab in the OPAC details page so that it now shows information from authority records where:
– the authority record 024 has identifier data, and
– the identifiers option is selected for the OPACAuthorIdentifiersAndInformation system preference.The “Author information” tab now shows the authority record information where it is used in a bibliographic record’s 110 (Corporate name) and 111 (Meeting name).
- 42912 Javascript error on opac-readingrecord when no Circulation history
Patrons
Other bugs fixed
- 41946 Superlibrarian should be able to set protected status on patron creation
Plugin architecture
Other bugs fixed
- 42430 Fix issue with stale plugin methods after plugin upgrade
Point of Sale
Critical bugs fixed
- 41819 Refunds via the Cash registers page should not result in PAYOUTS if the transaction type is ‘Account Credit’
SIP2
Critical bugs fixed
- 42664 Changes to SIP2 accounts may not applied immediately
Searching – Elasticsearch
Critical bugs fixed
- 42669 es_indexer_daemon.pl silently marks jobs finished on indexing failure and doesn’t recover from NoNodes
The Elasticsearch indexer daemon (es_indexer_daemon.pl) was silently marking background indexing jobs as “finished” even when Elasticsearch was unreachable, causing records to disappear from search results with no indication of failure. Additionally, after a brief ES outage (e.g. a Docker restart), the daemon’s connection pool would mark the node as dead with exponential backoff, leaving it permanently stuck until manually restarted. The daemon now resets jobs to “new” on NoNodes errors so they are automatically retried once connectivity is restored, recreates the ES client to reset the connection pool, and correctly marks jobs as “failed” for other indexing errors.
Staff interface
Critical bugs fixed
- 41604 Impossible to hide Checkin column in issues-table in circ/circulation.pl
- 42349 Incorrect filter by recalls
This fixes the holdings table on the record details page. The status column filter now works correctly when selecting the “Recalled” option, and lists recalls placed for a specific item.
Previously, the “Recalled” filter did not work and all items for the record were listed instead.
- 42868 Bookings are storing incorrect timezone values
Other bugs fixed
- 42339 Canceling a Record display customization directs to the HTML customizations
This fixes the record display customizations page (Tools > Additional tools > Record display customizations). When you cancel adding a new entry you are now returned to the list of record display customizations, instead of the list of HTML customizations.
System Administration
Other bugs fixed
-
42568 Match maxlength attributes to marc_order_accounts column sizes
Sponsored by Athens County Public Libraries
-
42618 Incorrect sidebar menu link to MARC order accounts
Sponsored by Athens County Public Libraries
Test Suite
Other bugs fixed
- 42937
$Test::Strict::TEST_STRICT = 0;no longer needed in t/db_dependent/00-strict.t
Z39.50 / SRU / OpenSearch Servers
Other bugs fixed
- 42321 Z3950/SRU Search should handle empty results from search targets better
Documentation
The Koha manual is maintained in Sphinx. The home page for Koha
documentation is
-
Koha Documentation
As of the date of these release notes, the Koha manual is available in the following languages: - French (83%)
- German (84%)
- Greek (90%)
- Hindi (62%)
- Portuguese (53%)
- Portuguese (Brazil) (42%)
The Git repository for the Koha manual can be found at
Translations
Complete or near-complete translations of the OPAC and staff
interface are available in this release for the following languages:
– Arabic (ar_ARAB) (89%)
– Armenian (hy_ARMN) (100%)
– Azerbaijani (64%)
– Bulgarian (bg_CYRL) (100%)
– Chinese (Simplified Han script) (81%)
– Chinese (Traditional Han script) (94%)
– Czech (65%)
– Dutch (89%)
– English (100%)
– English (New Zealand) (60%)
– English (USA)
– Finnish (99%)
– French (100%)
– French (Canada) (97%)
– German (99%)
– Greek (64%)
– Hindi (92%)
– Italian (80%)
– Khmer (Central) (58%)
– Norwegian Bokmål (69%)
– Persian (fa_ARAB) (90%)
– Polish (100%)
– Portuguese (Brazil) (99%)
– Portuguese (Portugal) (88%)
– Russian (92%)
– Slovak (58%)
– Spanish (96%)
– Swedish (88%)
– Telugu (63%)
– Turkish (78%)
– Ukrainian (73%)
– Uzbek (64%)
– Western Armenian (hyw_ARMN) (58%)
Partial translations are available for various other languages.
The Koha team welcomes additional translations; please see
For information about translating Koha, and join the koha-translate
list to volunteer:
The most up-to-date translations can be found at:
Release Team
The release team for Koha 25.11.09 is
– Release Manager: Pedro Amorim
-
QA Manager: Lisette Scheer
-
QA Team:
- Marcel de Rooy
- Martin Renvoize
- Jonathan Druart
- Laura Escamilla
- Lucas Gass
- Tomás Cohen Arazi
- Lisette Scheer
- Nick Clemens
- Paul Derscheid
- Emily Lamancusa
- David Cook
- Matt Blenkinsop
- Andrew Fuerste-Henry
- Brendan Lawlor
- Pedro Amorim
- Kyle M Hall
- Aleisha Amohia
- David Nind
- Baptiste Wojtkowski
- Jan Kissig
- Katrin Fischer
- Thomas Klausner
- Julian Maurice
- Owen Leonard
- Lucas Gass
-
Documentation Manager: Aude Charillon
-
Documentation Team:
- Philip Orr
- Caroline Cyr La Rose
- David Nind
- Marion Durand
-
Translation Manager: Jonathan Druart
-
Wiki curators:
- George Williams
- Thomas Dukleth
-
Release Maintainers:
- 26.05 — Lucas Gass
- 25.11 — Baptiste Wojtkowski
- 25.05 — Wainui Witika-Park
- 24.11 — Fridolin Somers
-
Release Maintainer assistants:
- 26.05 –Jacob O’Mara
- 25.05 — Alex Buckley & Aleisha Amohia
Credits
We thank the following libraries, companies, and other institutions who are known to have sponsored
new features in Koha 25.11.09
– Athens County Public Libraries
– Chetco Community Public Library
– [OpenFifth](https://openfifth.co.uk)
We thank the following individuals who contributed patches to Koha 25.11.09
– Pedro Amorim (1)
– Tomás Cohen Arazi (1)
– Nick Clemens (4)
– Paul Derscheid (3)
– Jonathan Druart (16)
– Laura Escamilla (2)
– Lucas Gass (3)
– Kyle M Hall (8)
– Andreas Jonsson (1)
– Janusz Kaczmarek (2)
– Jan Kissig (3)
– Owen Leonard (2)
– Martin Renvoize (13)
– Phil Ringnalda (1)
– Adolfo Rodríguez (2)
– Marcel de Rooy (1)
– Lisette Scheer (1)
– Fridolin Somers (1)
– Lari Taskula (1)
– Hammat Wele (2)
– Baptiste Wojtkowski (5)
We thank the following libraries, companies, and other institutions who contributed
patches to Koha 25.11.09
– Athens County Public Libraries (2)
– [BibLibre](https://www.biblibre.com) (6)
– [ByWater Solutions](https://bywatersolutions.com) (18)
– Chetco Community Public Library (1)
– [Hypernova Oy](https://www.hypernova.fi) (1)
– Independant Individuals (2)
– Koha Community Developers (16)
– Kreablo AB (1)
– [LMSCloud](https://www.lmscloud.de) (3)
– [OpenFifth](https://openfifth.co.uk) (14)
– Rijksmuseum, Netherlands (1)
– [Solutions inLibro inc](https://inlibro.com) (2)
– [Theke Solutions](https://theke.io) (1)
– Wildau University of Technology (3)
– [Xercode](https://xebook.es) (2)
We also especially thank the following individuals who tested patches
for Koha
– Aleisha Amohia (2)
– Pedro Amorim (3)
– Tomás Cohen Arazi (1)
– Nick Clemens (4)
– David Cook (3)
– Paul Derscheid (5)
– Roman Dolny (2)
– Jonathan Druart (8)
– Laura Escamilla (3)
– Andrew Fuerste-Henry (1)
– Lucas Gass (59)
– Victor Grousset (1)
– Bo Gustavsson (1)
– Emily Lamancusa (1)
– Brendan Lawlor (3)
– Chris Mathevet (1)
– David Nind (33)
– Sanjar Tulkinov Anvar o’g’li (1)
– Lawrence O’Regan-Lloyd (1)
– Martin Renvoize (16)
– Phil Ringnalda (5)
– Jason Robb (2)
– Caroline Cyr La Rose (1)
– Lisette Scheer (13)
– Edith Speller (1)
– Baptiste Wojtkowski (60)
We regret any omissions. If a contributor has been inadvertently missed,
please send a patch against these release notes to koha-devel@lists.koha-community.org.
Revision control notes
The Koha project uses Git for version control. The current development
version of Koha can be retrieved by checking out the main branch of:
The branch for this version of Koha and future bugfixes in this release
line is 25.11.x.
Bugs and feature requests
Bug reports and feature requests can be filed at the Koha bug
tracker at:
He rau ringa e oti ai.
(Many hands finish the work)
Autogenerated release notes updated last on 30 Sep 2026 16:03:15.
