Jellyfin 10.7.0 → 12.1
55 versions, 3 with breaking changes, 6 with upstream notes or warnings only, 1 required stop
Required stops
- 10.10.7
You MUST be running Jellyfin 10.10.7 before upgrading to 10.11.0! You may be fine with Jellyfin 10.9.11 but this is less-extensively tested. Upgrading from any other versions is NOT supported and WILL fail; upgrade to 10.10.7 first, then upgrade to 10.11.0.
Source: https://jellyfin.org/posts/jellyfin-release-10.11.0/, also https://jellyfin.org/posts/jellyfin-release-12.0/ (checked 2026-09-26)
Version by version, oldest first
10.7.1 – 10.7.2: no action items (2 versions)
10.7.3 2021-05-05
Note
- [All] Security advisory https://github.com/jellyfin/jellyfin/security/advisories/GHSA-rgjw-4fwc-9v96: Remove dangerous endpoints that allow unauthenticated enumeration and access to private HTTP resources. NOTE: This is an API-breaking change. The major security risk outweights the issue of changing the endpoints. These were used only when fetching remote images.
10.7.4 – 10.8.12: no action items (17 versions)
10.8.13 2023-11-29
Notice
- NOTICE: The customizable FFmpeg binary path in the WebUI/API has been REMOVED for security reasons. Please see the corresponding blog post here for further details.
10.9.0 2024-05-11
Breaking — from the release blog
Key Release Notes/Breaking Changes
There are several key changes with 10.9.0 that administrative users should be aware of, before getting into the more specific changes.
- As always, ensure you back up your Jellyfin data and configuration directories before upgrading. With a major release, it's possible you will hit a bug and want to revert, and to do so, you will need to restore from a backup.
- Ubuntu users: We have dropped support for non-LTS Ubuntu releases with 10.9.0. That is, we have not built 10.9.0 packages for any releases except 20.04 LTS, 22.04 LTS, and 24.04 LTS, and we will not publish builds for any new non-LTS releases going forward. For an explanation of why, please see our previous blog post. If you use another release, please upgrade to 24.04 LTS or switch to the Docker container.
- Fedora/CentOS/RHEL/etc. users: We have dropped our official RPM packages and suggest switching to the 3rd-party RPMFusion repository or the Docker container. Support for RHEL-like distributions has been a major pain point for us for a very long time, and we feel that letting the community over at RPMFusion handle this is in our best interest going forward, similar to how Arch, Gentoo, etc. packages are handled. For more details, please see our previous blog post.
- Docker users: We now offer GitHub Container Registry (GHCR) as an alternative container registry in addition to Docker Hub. You can pull images from the new registry via URIs like
ghcr.io/jellyfin/jellyfin:latest. Don't worry, we have no plans to drop Docker Hub as a container registry, but we feel providing both gives users more choice and flexibility.
- Docker users: If you encounter problems loading your homepage, you may need to remove the
DOTNET_SYSTEM_GLOBALIZATION_INVARIANTenvironment variable from your container, as this is no longer valid in Jellyfin 10.9.0. For more details please see these issues.
- Nginx reverse proxy users: If you have a block in your nginx config that begins with
location ~ ^/web/$ {and the comment# location block for /web - This is purely for aesthetics [...], please remove that block as it will cause occasional issues with 404's and/or slow performance on 10.9.z.
Note — from the release blog
- DLNA support is now provided by a plugin and has been removed from the core server. This has several major benefits: first, it can be updated independently of the server to some degree; second, it will not be enabled for anyone unless they want it and explicitly install the plugin; and third, it reduces the potential of security holes around DLNA due to both previous benefits. If you wish to use (or continue to use) DLNA, please install the plugin after upgrading.
Note — from the release blog
- The EasyPassword (PIN) feature has been removed as this was a big security risk especially for administrator accounts; QuickConnect login is still supported however.
From jellyfin.org/posts/jellyfin-release-10.9.0/#api--security
Note — from the release blog
- Our minimum FFmpeg version has been bumped from 4.0 to 4.4 to take advantage of many new features. For users of our Jellyfin FFmpeg build (Docker,
.deb/Debuntu repo, and Windows installs), you're already on a newer version with FFmpeg 6.0.1, but this minimum change would affect any other platforms.
From jellyfin.org/posts/jellyfin-release-10.9.0/#core-server--networking
Note — from the release blog
- The
--ffmpegcommand-line flag is now the primary method of setting FFmpeg paths, and configuration of the FFmpeg paths viaencoding.xmlis now deprecated. All official packaging will revert to defaults unless explicitly set before upgrade.
From jellyfin.org/posts/jellyfin-release-10.9.0/#transcoding--ffmpeg
10.9.1 – 10.9.11: no action items (11 versions)
10.10.0 2024-10-26
Breaking — from the release blog
- Most clients should continue to work as-is without any issues or any forced upgrades, though this may change in the future. The sole exception is Jellyfin4Kodi, which currently has issues due to point 5 below, though a fix is hopefully forthcoming shortly.
- We have deprecated Raspberry Pi V4L2 hardware transcoding support, and are looking to deprecate 32-bit ARM support (i.e.
armv7orarmhf) in general for 10.10.0 and later, with a goal to remove 32-bit ARM support in 10.11.0. Older, slow ARM systems have always been tricky platforms for us: they're popular but extremely poor in performance, and this has caused a lot of people a lot of headaches. With the RPi5 entirely removing a hardware acceleration engine, and most ARM single-board computers now supporting ARM64, we are taking this action now to ensure it's widely known. If you are running Jellyfin on old ARM hardware, now is the time to start looking at an upgrade. See PR #1148.
- We now use the system temporary storage engine (e.g.
/tmpon Linux) for storing short-lived transient temporary files, to allow us to leverage temporary ramdisks and the like and avoid cluttering potentially slow storage. This may cause issues if you specifically depended on the previous behaviour. Note that this does not include transcoding temporary files. See PR #12226.
- The server will now refuse to start if
ffmpegcannot be found, is an incorrect version, or does not function properly (missing extensions, etc.). With how criticalffmpegis to Jellyfin, this has become very important to avoid mis-reported issues. This can be explicitly bypassed if needed. See PR #12463.
- Network paths in libraries have been fully removed and will no longer work. This functionality has been deprecated for a long time, and most of it was removed in 10.9.0, but this removes the remainder. See PR #12446. Third-party clients relying on this functionality should be able to re-implement it as required.
- Systems with Trickplay enabled may see a relatively long migration occurring during the upgrade. If Jellyfin seems to hang starting up after upgrading, please observe the logs and wait for the migration to complete. This helps enable the functionality below.
10.10.1 – 10.10.6: no action items (6 versions)
10.10.7 2025-04-05
Required stop
Note
Important Notes
- Configurations behind a reverse proxy that did not explicitly configure trusted proxies will not work after this release. This was never a supported configuration, so please ensure you correct your configuration before upgrading. See the updated docs here for more information.
10.11.0 2025-10-20
Quoted from jellyfin.org/posts/jellyfin-release-10.11.0/
Warning
WARNING: There are very important release notes to review before upgrading! Please find all the details in our blog post on the release.
Note — from the release blog
TL; DR
IT IS VERY IMPORTANT THAT YOU READ THIS SECTION BEFORE UPGRADING TO JELLYFIN 10.11.0! Failure to do so may cause issues! Always feel free to ask for help in our chat if you are unclear or run into trouble.
- As always for major upgrades, ensure you STOP Jellyfin and take a FULL MANUAL BACKUP OF YOUR DATA AND CONFIG DIRECTORIES before upgrading! While the upgrade process should be seamless and has guardrails, we've seen a lot of strange bugs during RC testing and it's better to be safe than sorry.
- You MUST be running Jellyfin 10.10.7 before upgrading to 10.11.0! You may be fine with Jellyfin 10.9.11 but this is less-extensively tested. Upgrading from any other versions is NOT supported and WILL fail; upgrade to 10.10.7 first, then upgrade to 10.11.0.
- The initial upgrade will include MULTIPLE LONG-RUNNING MIGRATIONS that may take up to several hours depending on your library size and state. DO NOT CANCEL OR INTERRUPT THE SYSTEM during these migrations; let them run overnight if possible on very large libraries. You can use the new Startup UI and Log Viewer (see below) from your local network to view the progress during the upgrade, and please see the section below for more details on "why".
- The upgrade will make a backup of your existing
library.dbfile namedlibrary.db.old. This file can be used to recover should the upgrade fail. Once you have successfully upgraded and Jellyfin 10.11.0 is running smoothly, you may delete this backup. If you need to try the migrations again due to a failure, stop Jellyfin, rename this file back tolibrary.db, then start Jellyfin again, and the migration will be re-attempted.
- If you have adjusted the Library Page Size to anything other than the default of 100, we recommend putting it back for performance reasons before upgrading.
- After upgrading, we strongly recommend running a full library scan to ensure that all data is correctly populated. Failure to do so may result in weird bugs if any metadata entries were corrupt or not properly migrated (rare but possible). Additionally, users should also perform a scan for missing metadata on their Music libraries, as this may be necessary for proper music functionality after the upgrade. While it may not be strictly required, performing this additional scan on other libraries is recommended to ensure everything functions correctly.
- Jellyfin 10.11.0 is NOT compatible with 32-bit ARM systems (
armhf), like 1st and 2nd generation Raspberry Pis or other low-end or old SBCs, or any ARM system running a 32-bit operating system. You must be running an ARM64 operating system to run Jellyfin 10.11.0 on ARM systems. See below for more information.
- This release also fixes several security bugs, both for ourselves and from upstream projects like DotNET. We do recommend upgrading to 10.11.0 as soon as possible.
- As always with major Jellyfin releases, bugs will exist, even after 6 months of RC testing. This is a second reminder to take a full backup before upgrading, as this is the only way to downgrade back to a previous version if you find that you need to.
Note — from the release blog
Removal of ARM32 (armhf) support
In Jellyfin 10.10.0, we deprecated ARM32 support and have fully removed it from Jellyfin 10.11.0; Jellyfin now requires an ARM64 operating system to run on ARM platforms. In practical terms, this means dropping support for very old or very low-end ARM SBCs (Raspberry Pi 1/2, etc.). We found consistently that these very old SBCs were absolutely terrible at running Jellyfin, even without transcoding, and we decided that dropping support would streamline our release processes and help ensure that users get the best experience out of the box. If you are still running on one of these systems, or on a newer ARM SBC that isn't running a 64-bit operating system, you will need to upgrade your hardware and/or reinstall a 64-bit operating system in order to upgrade to Jellyfin 10.11.0.
Note — from the release blog
Deprecation of internal TLS/SSL support
We are announcing the deprecation of internal TLS/SSL support in Jellyfin, which we are planning to remove in Jellyfin 10.12.0. The current internal TLS mechanisms are cumbersome and do not integrate well with external systems e.g. Let's Encrypt's certbot, which means manual work and manual restarts whenever a certificate needs to be updated. In addition, compiling in TLS support means dependencies on external libraries that complicate our packaged Linux binaries. We have always recommended running Jellyfin behind a reverse proxy, all of which provide far better integration for TLS/SSL, so with our next release we will be removing this functionality. For anyone running a production-grade Internet-facing instance using TLS without a reverse proxy, now is the time to get that set up. Even with this removal, we are planning to still provide manual configuration options for the built-in Kestrel TLS system, which would serve as an alternative way to configure TLS, but it will not be exposed through the frontend UX and would be recommended only for very advanced, specific usecases; normal instances should move to reverse proxies.
Note — from the release blog
Free Space Checks
Jellyfin now actively checks the available free space for its configuration and data directories. If you have less than 2GB of free space in each data directory, Jellyfin now refuses to start to prevent data corruption. Additionally, checks are implemented to prevent certain path misconfigurations that are known to cause issues.
10.11.1 – 10.11.6: no action items (6 versions)
10.11.7 2026-03-31
Warning
WARNING: This release contains several extremely important security fixes. These vulnerabilities will be disclosed in 14 days as per our security policy. Users of all versions prior to 10.11.7 are advised to upgrade immediately.
10.11.8 2026-04-05
Note
Note: This release fixes several regressions from 10.11.7, with the goal to get people onto an updated release due to the forthcoming (t-minus 9 days) release of the GHSAs/CVEs that were fixed in 10.11.7. Please upgrade to this release as soon as you can.
10.11.9 – 10.11.11: no action items (3 versions)
12.0 2026-09-08
Note
Notes on Updating
Before upgrading from an earlier version, a full backup of the data directory is strongly recommended, as this release includes database changes that prevent rolling back without a full restore.
Direct upgrades from 10.10.7 and 10.11.x to 12.0 are supported; intermediate upgrades are not required. Users running releases older than 10.10.7 are strongly encouraged to upgrade to 10.10.7 before migrating to 12.0.
Installed repository plugins (anything not built-in) should also be removed before migrating. Plugins will likely need time to adapt to the new database changes, so re-adding them afterward is the safest approach for testing.
Official plugins compatible with Jellyfin are available through the stable plugin repository. If you have changed to the unstable plugin repository please change it back.
- Go to Dashboard -> Plugins -> Manage Repositories
- Update the Plugin Repository URL to: https://repo.jellyfin.org/files/plugin/manifest.json
After migrating please perform the following steps.
- Perform a full library scan to restore alternative versions
If you run into issues, please prefix bug reports with "[12.0]".
Note
Packaging
- Debian Bullseye and Ubuntu Focal packages are no longer built
Breaking
Breaking and behavior changes
- Legacy route prefixes removed (
/emby/*and/mediabrowser/*). Old third-party clients that rely on them will stop working - Legacy authorization is now disabled by default, and a migration disables it on existing installs as well
- Removed obsolete API routes:
POST /Users/{userId}/EasyPassword(the EasyPassword feature is gone),GET /Items/{itemId}/CriticReviews,GET /Environment/NetworkShares,POST /System/MediaEncoder/Path,GET /LiveTv/Recordings/Groups/{groupId}, andGET /QuickConnect/Initiate - The global subtitle configuration has been removed, subtitle settings are configured per library
.oggis no longer treated as a video extension and is audio only,.aifcis now recognized as audio, and.aiffis no longer treated as an image- Symlinks are only resolved at playback time
- Sorting by name now uses
SortNameandCleanName, and the same cleaning logic is applied toForcedSortName. Library ordering may change compared to 10.11 - Image endpoints no longer upscale beyond the source resolution, so low resolution artwork renders at its real size instead of being enlarged
- Username capitalization can now be changed. Usernames are stored in a normalized column with a unique index, so installs with usernames that differ only by case need to be corrected before upgrading
Note — from the release blog
TL; DR
Info
IT IS VERY IMPORTANT THAT YOU READ THIS SECTION BEFORE UPGRADING TO JELLYFIN 12.0! Failure to do so may cause issues! Always feel free to ask for help in our chat if you are unclear or run into trouble.
This release changes the database schema and actively rewrites data on first boot, so a backup is the only way back to your previous version.
- As always for major upgrades, ensure you STOP Jellyfin and take a FULL MANUAL BACKUP OF YOUR DATA AND CONFIG DIRECTORIES before upgrading!
- You must be running Jellyfin 10.10.7 or any 10.11.x release before upgrading to 12.0. Upgrading directly from 10.11.x is fully supported and no intermediate step is needed. If you are on anything older than 10.10.7, upgrade to 10.10.7 first, then upgrade to 12.0.
- Check your usernames before upgrading. Usernames are now case insensitive, so two accounts can't have names that only differ by capitalization. If you have users that match this pattern the database migration will fail.
- A full library scan is REQUIRED after upgrading. As part of fixing how alternate versions are stored, versions that Jellyfin grouped automatically, not ones you merged yourself, are cleared during the upgrade. Until you run the scan those versions will look like they are missing.
- The first scan after upgrading will take significantly longer than normal, and some movies may appear as newly added. This is expected. Jellyfin now checks every item in your library against the files on disk to clear out leftovers from previous versions, and anything that was previously filed incorrectly gets corrected as it goes. Do not stop the server while migrations are running.
- Once installed, please ensure you hard refresh (e.g. Ctrl+Shift+R or similar) and/or clear your web cache for your Jellyfin instance if you notice any UX anomalies. Bad cached assets are the #1 cause of such issues.
- Remove any third-party plugins before upgrading. Plugins built for 10.11 will not load on 12.0 and need updated builds from their authors, so give them time to catch up before adding them back. Official plugins have been updated for 12.0 support.
- Very old third-party clients will stop working. Support for the legacy
/emby/and/mediabrowser/addresses has been removed, and the deprecated way of signing in is now disabled, including on existing servers. Clients that have not seen an update in years are the ones at risk here.
- This release contains security fixes, so we recommend upgrading rather than staying on an older release once you are ready.
- As always with major Jellyfin releases, bugs will exist. Please prefix bug reports with "[12.0]" so we can triage them quickly, and see point 1 one more time: take a backup.
Note — from the release blog
Changes you may notice after upgrading
A few things behave differently than they did on 10.11, beyond the legacy client removals covered above:
- Subtitle settings are now configured per library rather than once for the whole server, so the old server-wide subtitle options no longer exist.
- Sorting is more consistent, which does mean some libraries will be ordered slightly differently than you are used to.
- Artwork is no longer stretched past its real size. Low resolution posters now appear at their actual size instead of being blown up to fit, which looks smaller but sharper.
.oggfiles are treated as audio, not video. If you had.oggvideo files, they will be re-sorted on the next scan.- Usernames can now be changed between upper and lower case. As part of that, two accounts can no longer have names that differ only by capitalization. If your server has usernames that differ only by capitalization, the database migration will fail.
- Symlinked media is followed when something is played rather than when the library is scanned.
Note — from the release blog
Deprecation of internal TLS/SSL support
In the 10.11.0 release notes we announced that internal TLS/SSL support would be removed in this release. That removal has been postponed to a future version. The reasoning has not changed - we continue to recommend running Jellyfin behind a reverse proxy - so if you are running an Internet-facing instance using Jellyfin's built-in TLS, this is extra time to migrate, not a reprieve.
Note
- All themes now derive from a shared base theme built on CSS variables, including Dark, Light, WMC, Blue Radiance, Apple TV, and Purple Haze. Custom themes may need to be adjusted
12.1: no action items (1 version)
Release notes from github.com/jellyfin/jellyfin/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important/stop/notice note, or a plain note, is shown (a note that only says when security advisories will be published is not); read the full notes for anything else. Jellyfin's release notes mark breaking changes only from 12.0 (“Breaking and behavior changes”). Sections titled Important Release Notes, Important Notes, Notes on Updating and the 10.4.1 Base URL change, and a Packaging section (12.0: platforms no longer built) are quoted as “Note”; so is the Release Notes section of x.y.0 releases. In patch releases, whose Release Notes list bug fixes, only paragraphs with a bold WARNING, STOP, NOTICE or NOTE marker are quoted. From the release blog (jellyfin.org/posts, 10.9.0 onward) the Breaking Changes sections are quoted as “Breaking”, and the TL; DR, Removal of …, Deprecation of …, Free Space Checks and Changes you may notice after upgrading sections as “Note”; four bullets of the 10.9.0 “The Big Changes” lists that remove or reset something (DLNA, PIN login, minimum FFmpeg, FFmpeg path) are quoted as “Note” too.