It’s not just Netty. Some prometheus stuff just got flagged on master and Jetty 
9.x is still flagged on branch-3.9.

I’m planning to make release on both release lines 3.8.x and 3.9.x and I’m not 
sure I can keep up with the pace of these updates.

Shall we release without requiring a clean Owasp build? Releases will soon get 
outdated anyways in that regard.

Andor




> On Sep 2, 2026, at 11:06, David Smiley <[email protected]> wrote:
> 
> Sigh.... Netty is a CVE generator, more so than any project I can think
> of.  All the better to unblock users of ZK that don't need/want Netty.
> ZOOKEEPER-4835 is coming to a ZK version soon, hopefully.
> 
> On Wed, Sep 2, 2026 at 11:10 AM Andor Molnár <[email protected]> wrote:
> 
>> Merged.
>> 
>> Thanks David!
>> 
>> 
>> 
>>> On Sep 2, 2026, at 08:00, Dávid Paksy <[email protected]> wrote:
>>> 
>>> HI Andor,
>>> 
>>> I created https://issues.apache.org/jira/browse/ZOOKEEPER-5086 and a
>> new PR
>>> for this.
>>> 
>>> Best Regards,
>>> Dávid
>>> 
>>> Andor Molnár <[email protected]> ezt írta (időpont: 2026. szept. 1., K,
>>> 17:00):
>>> 
>>>> Hi team,
>>>> 
>>>> Netty 4.1.136 is already flagged with:
>>>> 
>>>> 09:31:46 [ERROR] netty-transport-4.1.136.Final.jar
>>>> (pkg:maven/io.netty/[email protected],
>>>> cpe:2.3:a:netty:netty:4.1.136:*:*:*:*:*:*:*): CVE-2026-62380(6.3)
>>>> 
>>>> Could somebody please create a patch to address it?
>>>> 
>>>> Andor
>>>> 
>>>> 
>>>> 
>> 
>> 

Reply via email to