Hello Apache Geode Developer Community, As we prepare the 2.0.3 maintenance release, we wanted to take a moment to share an update and invite your input.
This release has been shaped by focused efforts to remediate critical security vulnerabilities, and we are committed to ensuring the release notes accurately and clearly reflect the improvements that matter most to our community. Your perspective is a valuable part of that process. If there are specific tickets or pull requests you feel should be highlighted, we would greatly appreciate you replying to this thread with the details. Together, we want the release notes to represent our collective progress as faithfully as possible. Thank you for your continued support and contributions. ================ BEGIN OF RELEASE NOTE ============== 2.0.3 This maintenance release addresses security vulnerabilities across several dependencies, including Apache Shiro, Eclipse Jetty, Jackson, Micrometer, HttpCore5, Bouncy Castle, Reactor Core, and Log4j. Highlights -Apache Shiro Major Upgrade: Remediated CVE-2026-49268 by upgrading Shiro from 2.1.0 to 3.0.0 across all modules (GEODE-10607 #8033, GEODE-10591 #8017) -Jetty Security Patches: Remediated CVE-2026-10050 by upgrading Jetty from 12.0.33 to 12.0.37 (GEODE-10605 #8031) -Jackson Security Patches: Remediated GHSA-2m67-wjpj-xhg9 and CVE-2026-19032 by upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10589 #8015, GEODE-10621 #8048) -Micrometer Security Patches: Remediated CVE-2026-40984 and CVE-2026-59296 by upgrading Micrometer from 1.14.0 to 1.16.7 (GEODE-10592 #8018, GEODE-10619 #8044) -HttpCore5 Remediation: Remediated CVE-2026-54428 by upgrading HttpCore5 and HttpCore5-H2 from 5.3.6 to 5.4.3 (GEODE-10590 #8016) -Bouncy Castle Remediation: Remediated CVE-2026-8763 in the bcprov-jdk18on transitive dependency, 1.84 to 1.85 (GEODE-10606 #8032) -Reactor Core Remediation: Remediated CVE-2026-47857 by pinning Reactor Core, a transitive dependency of spring-shell-core, from 3.6.10 to 3.8.7 (GEODE-10622 #8049) -Log4j Upgrade: Upgraded Log4j from 2.25.4 to 2.25.5 to address a reported advisory (GEODE-10604 #8030) ================== END OF RELEASE NOTE ============== Best regards, Jinwoo Hwang (he/him/his) Apache Geode / SASĀ® Research and Development http://JinwooHwang.com<http://jinwoohwang.com/>
