Skip to content

Bump netty, snappy, karaf to address known CVEs on activemq-5.19.x#2031

Open
jbonofre wants to merge 1 commit into
apache:activemq-5.19.xfrom
jbonofre:dependency-cve-updates
Open

Bump netty, snappy, karaf to address known CVEs on activemq-5.19.x#2031
jbonofre wants to merge 1 commit into
apache:activemq-5.19.xfrom
jbonofre:dependency-cve-updates

Conversation

@jbonofre
Copy link
Copy Markdown
Member

@jbonofre jbonofre commented May 20, 2026

Dependency bumps in pom.xml to address known CVEs on activemq-5.19.x:

Not bumped here (require separate evaluation):

  • zookeeper 3.4.14 — line is EOL; jumping to 3.9.x is a breaking-change risk for replicated leveldb paths
  • spring 5.3.39 — 5.3.x OSS EOL; April 2026 CVEs (CVE-2026-22740/22741/22745) have no OSS patch in Maven Central
  • jetty 9.4.58.v20250814 — already the latest 9.4.x published to Maven Central

- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)
- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)
- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)
@jbonofre jbonofre changed the title Bump netty, snappy, karaf to address known CVEs Bump netty, snappy, karaf to address known CVEs on activemq-5.19.x May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants