[
https://issues.apache.org/jira/browse/HBASE-30470?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18125731#comment-18125731
]
Xavier Fernandis commented on HBASE-30470:
------------------------------------------
Thanks [~nihaljain.cs] for reviewing and merging the PR.
> [hbase-thirdparty] Bump netty to 4.1.139.Final and netty-tcnative to
> 2.0.84.Final
> ---------------------------------------------------------------------------------
>
> Key: HBASE-30470
> URL: https://issues.apache.org/jira/browse/HBASE-30470
> Project: HBase
> Issue Type: Task
> Components: security, thirdparty
> Reporter: Xavier Fernandis
> Assignee: Xavier Fernandis
> Priority: Major
> Labels: pull-request-available
> Fix For: thirdparty-4.1.15
>
>
> Upgrade the shaded netty dependency from 4.1.135.Final to 4.1.139.Final.
> Also bump netty-tcnative-boringssl-static from 2.0.75.Final to 2.0.84.Final,
> which is the version pinned by netty-parent 4.1.139.Final
> refer :
> [https://github.com/netty/netty/commit/4265638378eb3c10495faff994bb30c440864050]
> fixes the following
> - CVE-2026-59899 - HttpContentEncoder unbounded per-channel queue via
> HTTP/1.1 pipelining (DoS). Affects netty < 4.1.136.Final, so
> 4.1.135.Final
> is vulnerable. Fixed in 4.1.136.Final.
> https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww
> https://nvd.nist.gov/vuln/detail/CVE-2026-59899
> - GHSA-pvjx-v7vp-62vq (no CVE assigned) - HttpServerCodec unbounded
> per-connection queue via HTTP/1.1 pipelining (DoS, High). Affects netty
> <= 4.1.137.Final. Fixed in 4.1.138.Final.
> https://github.com/netty/netty/security/advisories/GHSA-pvjx-v7vp-62vq
> - CVE-2026-93494 - ByteBuf leak in StompSubframeDecoder
> (netty-codec-stomp)
> when the terminating NUL byte never arrives (DoS, High, CVSS 7.5).
> Affects netty <= 4.1.137.Final. Fixed in 4.1.138.Final.
> https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j
> https://nvd.nist.gov/vuln/detail/CVE-2026-93494
--
This message was sent by Atlassian Jira
(v8.20.10#820010)