[ 
https://issues.apache.org/jira/browse/CASSANDRA-21678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115956#comment-18115956
 ] 

Stefan Miklosovic commented on CASSANDRA-21678:
-----------------------------------------------

We will return to this when we are going to release something. It might happen 
that something newer would be released in zstd-jni and we would just play this 
"catch up" game unnecessarily. 


> Update zstd-jni to 1.5.7-14 or later 
> -------------------------------------
>
>                 Key: CASSANDRA-21678
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-21678
>             Project: Apache Cassandra
>          Issue Type: Task
>          Components: Feature/Compression
>            Reporter: Éder Costa
>            Assignee: Arvind Kandpal
>            Priority: Normal
>          Time Spent: 50m
>  Remaining Estimate: 0h
>
> Update zstd-jni to 1.5.7-14 or later is required to remove the vulnerable 
> code.
> CVEs: CVE-2026-87795 CVE-2026-87825 and CVE-2026-87823



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to