Not every dangerous file looks dangerous. Some are simply built wrong, malformed or manipulated in ways that slip past signature and reputation checks. MetaDefender Core v5.22.0 adds a new engine that inspects a file's internal structure for exactly that.
This release also publishes the OPSWAT MetaDefender Core app on Splunkbase, moves the database to PostgreSQL 18.6 with a FIPS 140-3 compliant build, and tightens control over quarantined files and hash allowlists. The sections below walk through the most significant additions.
Stronger Detection and Content Integrity
Introducing the File Structure Validation Engine
MetaDefender Core v5.22.0 introduces the File Structure Validation engine, which checks whether a file's internal structure matches what its declared type should look like. Files that are malformed, truncated, or deliberately manipulated to smuggle content past inspection are flagged before they reach downstream processing.

The engine aligns with Deep CDR™ Technology on how processing failures and sanitization edge cases are handled, and it can send embedded objects back through the scan process so nothing inside a complex file goes unexamined. Validation results are also included in the executive report export, in both PDF and CSV.
Faster Archive Processing with Result Reuse
MetaDefender Core can now reuse prior processing results for files inside archives, so content that has already been scanned is not scanned again on repeat submissions. For workflows that handle large or frequently resubmitted archives, this cuts scan time and reduces load without weakening inspection.
Integrations and Compliance
OPSWAT MetaDefender Core App on Splunkbase
The OPSWAT MetaDefender Core app is now published on Splunkbase. Teams that run Splunk can install a supported app that brings Core scan activity, threats, and processing data into Splunk with ready-made dashboards, rather than building the integration themselves.

PostgreSQL 18.6 and a FIPS 140-3 Compliant Database
The bundled and remote database moves to PostgreSQL 18.6, keeping deployments on a current, supported version. The bundled PostgreSQL is also built to be FIPS 140-3 compliant, which matters for government and regulated environments that require validated cryptography in every component of the stack.

Read more: OPSWAT Completes FIPS 140-3 Validation
Security and Operations
Encrypted Quarantine Downloads
Files held in quarantine can now be downloaded encrypted. When an analyst retrieves a captured file for investigation, it is protected during download, reducing the risk of exposing a sensitive or malicious artifact.
Skip by Hash Approval Expiry with Auto-Removal
Skip by Hash approvals can now be given an expiration date and removed automatically when they lapse. This keeps allowlists from accumulating stale entries over time, so a file skipped today does not stay skipped indefinitely without review.
Resource-Utilization Email Alerts
Administrators can now receive email alerts when RAM or CPU utilization crosses configured thresholds, so operations teams can respond to resource pressure before it slows or disrupts scanning.
Also in This Release
Version 5.22.0 rounds out with several smaller refinements. Workflows can stop processing a file when its type does not match expectations, users can be required to change their password on first login, Active Directory and LDAP directory-name and attribute fields now accept up to 256 characters, the Troubleshooting page shows log-rotation status, and the dashboard and processing history no longer count cancelled or timed-out objects as failed. The release also standardizes OpenTelemetry (OPTEL) metrics and includes security hardening and bug fixes that improve day-to-day reliability.
Previously Released
Upgrading from an earlier version? MetaDefender Core v5.21.0 was a major update. Here is a quick reminder of what it delivered:
- A completely redesigned user interface and dashboard with four focused tabs: Security, System, Processing, and Usage.
- A unified CVEs dashboard consolidating SBOM and Vulnerability engine findings.
- A redesigned File Details report and clearer processing timeline.
- Centralized Skip by Hash management via My OPSWAT Central Management.
- Stricter Proactive DLP controls for unsupported and sensitive content.
No customer action is required from v5.21.0. For the complete history, see the release notes.
Next Steps
Ready to get started with MetaDefender Core v5.22.0? Check out these helpful resources:
- Visit opswat.com/products/metadefender/core
- Upgrade to MetaDefender Core v5.22.0
- Access the release notes
Have questions? Reach us at support@opswat.com
