Badreddine Itani created ZOOKEEPER-5056:
-------------------------------------------

             Summary: Netty CVE vunrabilities in zookeeper 3.9.5
                 Key: ZOOKEEPER-5056
                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5056
             Project: ZooKeeper
          Issue Type: Bug
          Components: security
    Affects Versions: 3.9.5
            Reporter: Badreddine Itani


We are installing Zookeeper 3.9.5 on a production server.

Our security scan detected the following critical vulnerabilities (3): 
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42579]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42581]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42584]

Additionally the following high vulnerabilities (7):
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-33870]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-33871]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42578]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42583]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42585]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-42587]
 * [https://nvd.nist.gov/vuln/detail/CVE-2026-44248]

I will open a Pull request to upgrade the netty version from 
{*}'{*}{*}4.1.130.Final'{*} to 
*'4.1.135.Final'*



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to