[ 
https://issues.apache.org/jira/browse/CASSJAVA-132?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103799#comment-18103799
 ] 

Bret McGuire commented on CASSJAVA-132:
---------------------------------------

[~janehe] pointed out that this CVE is very much disputed; more info at 
https://github.com/HdrHistogram/HdrHistogram/issues/222.  Prolly wanna hold on 
doing too much here until we (a) get better agreement on severity here and (b) 
have an HdrHistogram release which claims to actually fix the problem (none are 
planned as of this writing per comments on the issue above).

> Update HdrHistogram to address low CVE
> --------------------------------------
>
>                 Key: CASSJAVA-132
>                 URL: https://issues.apache.org/jira/browse/CASSJAVA-132
>             Project: Apache Cassandra Java driver
>          Issue Type: Improvement
>          Components: Core
>            Reporter: Bret McGuire
>            Priority: Normal
>
> https://nvd.nist.gov/vuln/detail/CVE-2026-14686
> Looks like we need to go to 2.2.2.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to