[
https://issues.apache.org/jira/browse/CASSANDRA-21678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115956#comment-18115956
]
Stefan Miklosovic commented on CASSANDRA-21678:
-----------------------------------------------
We will return to this when we are going to release something. It might happen
that something newer would be released in zstd-jni and we would just play this
"catch up" game unnecessarily.
> Update zstd-jni to 1.5.7-14 or later
> -------------------------------------
>
> Key: CASSANDRA-21678
> URL: https://issues.apache.org/jira/browse/CASSANDRA-21678
> Project: Apache Cassandra
> Issue Type: Task
> Components: Feature/Compression
> Reporter: Éder Costa
> Assignee: Arvind Kandpal
> Priority: Normal
> Time Spent: 50m
> Remaining Estimate: 0h
>
> Update zstd-jni to 1.5.7-14 or later is required to remove the vulnerable
> code.
> CVEs: CVE-2026-87795 CVE-2026-87825 and CVE-2026-87823
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]