[ 
https://issues.apache.org/jira/browse/HBASE-30470?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18125731#comment-18125731
 ] 

Xavier Fernandis commented on HBASE-30470:
------------------------------------------

Thanks [~nihaljain.cs]  for reviewing and merging the PR. 

 

> [hbase-thirdparty] Bump netty to 4.1.139.Final and netty-tcnative to 
> 2.0.84.Final
> ---------------------------------------------------------------------------------
>
>                 Key: HBASE-30470
>                 URL: https://issues.apache.org/jira/browse/HBASE-30470
>             Project: HBase
>          Issue Type: Task
>          Components: security, thirdparty
>            Reporter: Xavier Fernandis
>            Assignee: Xavier Fernandis
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: thirdparty-4.1.15
>
>
> Upgrade the shaded netty dependency from 4.1.135.Final to 4.1.139.Final. 
> Also bump netty-tcnative-boringssl-static from 2.0.75.Final to 2.0.84.Final, 
> which is the version pinned by netty-parent 4.1.139.Final
> refer :  
> [https://github.com/netty/netty/commit/4265638378eb3c10495faff994bb30c440864050]
> fixes the following
>  - CVE-2026-59899 - HttpContentEncoder unbounded per-channel queue via
>       HTTP/1.1 pipelining (DoS). Affects netty < 4.1.136.Final, so 
> 4.1.135.Final
>       is vulnerable. Fixed in 4.1.136.Final.
>       https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww
>       https://nvd.nist.gov/vuln/detail/CVE-2026-59899
>     - GHSA-pvjx-v7vp-62vq (no CVE assigned) - HttpServerCodec unbounded
>       per-connection queue via HTTP/1.1 pipelining (DoS, High). Affects netty
>       <= 4.1.137.Final. Fixed in 4.1.138.Final.
>       https://github.com/netty/netty/security/advisories/GHSA-pvjx-v7vp-62vq
>     - CVE-2026-93494 - ByteBuf leak in StompSubframeDecoder 
> (netty-codec-stomp)
>       when the terminating NUL byte never arrives (DoS, High, CVSS 7.5).
>       Affects netty <= 4.1.137.Final. Fixed in 4.1.138.Final.
>       https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j
>       https://nvd.nist.gov/vuln/detail/CVE-2026-93494



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to