Hello Apache Geode Developer Community,

As we prepare the 2.0.3 maintenance release, we wanted to take a moment to 
share an update and invite your input.

This release has been shaped by focused efforts to remediate critical security 
vulnerabilities, and we are committed to ensuring the release notes accurately 
and clearly reflect the improvements that matter most to our community. Your 
perspective is a valuable part of that process.

If there are specific tickets or pull requests you feel should be highlighted, 
we would greatly appreciate you replying to this thread with the details. 
Together, we want the release notes to represent our collective progress as 
faithfully as possible.

Thank you for your continued support and contributions.

================ BEGIN OF RELEASE NOTE ==============

2.0.3

This maintenance release addresses security vulnerabilities across several 
dependencies, including Apache Shiro, Eclipse Jetty, Jackson, Micrometer, 
HttpCore5, Bouncy Castle, Reactor Core, and Log4j.

Highlights
-Apache Shiro Major Upgrade: Remediated CVE-2026-49268 by upgrading Shiro from 
2.1.0 to 3.0.0 across all modules (GEODE-10607 #8033, GEODE-10591 #8017)
-Jetty Security Patches: Remediated CVE-2026-10050 by upgrading Jetty from 
12.0.33 to 12.0.37 (GEODE-10605 #8031)
-Jackson Security Patches: Remediated GHSA-2m67-wjpj-xhg9 and CVE-2026-19032 by 
upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10589 #8015, GEODE-10621 #8048)
-Micrometer Security Patches: Remediated CVE-2026-40984 and CVE-2026-59296 by 
upgrading Micrometer from 1.14.0 to 1.16.7 (GEODE-10592 #8018, GEODE-10619 
#8044)
-HttpCore5 Remediation: Remediated CVE-2026-54428 by upgrading HttpCore5 and 
HttpCore5-H2 from 5.3.6 to 5.4.3 (GEODE-10590 #8016)
-Bouncy Castle Remediation: Remediated CVE-2026-8763 in the bcprov-jdk18on 
transitive dependency, 1.84 to 1.85 (GEODE-10606 #8032)
-Reactor Core Remediation: Remediated CVE-2026-47857 by pinning Reactor Core, a 
transitive dependency of spring-shell-core, from 3.6.10 to 3.8.7 (GEODE-10622 
#8049)
-Log4j Upgrade: Upgraded Log4j from 2.25.4 to 2.25.5 to address a reported 
advisory (GEODE-10604 #8030)

================== END OF RELEASE NOTE ==============

Best regards,
Jinwoo Hwang (he/him/his)
Apache Geode / SASĀ® Research and Development
http://JinwooHwang.com<http://jinwoohwang.com/>

Reply via email to