Critical Security Notice: Upgrade to OneDev 16.8.5

We have fixed a critical authentication bypass vulnerability in OneDev 16.8.5. The vulnerability affects OneDev 16.7.0 through 16.8.4 running on Java 25 or later.
After a request authenticated with an access token, a later unauthenticated request could inherit the token user's identity and permissions. If an administrator's token was used, this could give an anonymous user administrator access. Disabling anonymous access does not prevent this vulnerability.
Upgrade to OneDev 16.8.5 as soon as possible. The fix restores authentication state after each request, preventing it from leaking into subsequent requests.
If you cannot upgrade immediately, run OneDev on Java 21 or an earlier supported version and restart the server. Installations running Java 21 or earlier are not affected by this issue.