The Apache Geode community is pleased to announce the availability of Apache Geode 2.0.3.
Geode is a data management platform that provides a database-like consistency model, reliable transaction processing and a shared-nothing architecture to maintain very low latency performance with high concurrency processing. Apache Geode 2.0.3 addresses security vulnerabilities across multiple dependencies, including Apache Shiro, Eclipse Jetty, Jackson, Micrometer, HttpCore5, Bouncy Castle, Reactor Core, and Log4j. Highlights -Apache Shiro Major Upgrade: Remediated CVE-2026-49268 by upgrading Shiro from 2.1.0 to 3.0.0 across all modules (GEODE-10607 #8033, GEODE-10591 #8017) -Jetty Security Patches: Remediated CVE-2026-10050 by upgrading Jetty from 12.0.33 to 12.0.37 (GEODE-10605 #8031) -Jackson Security Patches: Remediated GHSA-2m67-wjpj-xhg9 and CVE-2026-19032 by upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10589 #8015, GEODE-10621 #8048) -Micrometer Security Patches: Remediated CVE-2026-40984 and CVE-2026-59296 by upgrading Micrometer from 1.14.0 to 1.16.7 (GEODE-10592 #8018, GEODE-10619 #8044) -HttpCore5 Remediation: Remediated CVE-2026-54428 by upgrading HttpCore5 and HttpCore5-H2 from 5.3.6 to 5.4.3 (GEODE-10590 #8016) -Bouncy Castle Remediation: Remediated CVE-2026-8763 in the bcprov-jdk18on transitive dependency, 1.84 to 1.85 (GEODE-10606 #8032) -Reactor Core Remediation: Remediated CVE-2026-47857 by pinning Reactor Core, a transitive dependency of spring-shell-core, from 3.6.10 to 3.8.7 (GEODE-10622 #8049) -Log4j Upgrade: Upgraded Log4j from 2.25.4 to 2.25.5 to address a reported advisory (GEODE-10604 #8030) Users are encouraged to upgrade to this latest release. For the full list of changes please review the release notes at: https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-2.0.3 Release artifacts and documentation can be found at the project website: https://geode.apache.org/releases/ https://geode.apache.org/docs/guide/20/about_geode.html We sincerely thank all contributors whose time, effort, and collaboration made this release possible. Best regards, Jinwoo Hwang (he/him/his) Apache Geode / SASĀ® Research and Development http://JinwooHwang.com<http://jinwoohwang.com/>
