[
https://issues.apache.org/jira/browse/HBASE-30382?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115535#comment-18115535
]
Arvind Kandpal commented on HBASE-30382:
----------------------------------------
HI [~zhangduo], Can you check and review the patch
([https://github.com/apache/hbase/pull/8652])
> Update zstd-jni to 1.5.7-14 or later
> ------------------------------------
>
> Key: HBASE-30382
> URL: https://issues.apache.org/jira/browse/HBASE-30382
> Project: HBase
> Issue Type: Task
> Reporter: Arvind Kandpal
> Assignee: Arvind Kandpal
> Priority: Major
> Labels: pull-request-available
>
> Update zstd-jni to 1.5.7-14 or later is required to remove vulnerable code.
> CVEs: CVE-2026-87795, CVE-2026-87823, CVE-2026-87825
> HBase currently depends on zstd-jni 1.5.7-2 (hbase-compression-zstd module).
> Verified only pom.xml (root, zstd-jni.version property) needs updating;
> hbase-compression-zstd/pom.xml inherits via the property.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)