Badreddine Itani created ZOOKEEPER-5056:
-------------------------------------------
Summary: Netty CVE vunrabilities in zookeeper 3.9.5
Key: ZOOKEEPER-5056
URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5056
Project: ZooKeeper
Issue Type: Bug
Components: security
Affects Versions: 3.9.5
Reporter: Badreddine Itani
We are installing Zookeeper 3.9.5 on a production server.
Our security scan detected the following critical vulnerabilities (3):
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42579]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42581]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42584]
Additionally the following high vulnerabilities (7):
* [https://nvd.nist.gov/vuln/detail/CVE-2026-33870]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-33871]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42578]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42583]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42585]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-42587]
* [https://nvd.nist.gov/vuln/detail/CVE-2026-44248]
I will open a Pull request to upgrade the netty version from
{*}'{*}{*}4.1.130.Final'{*} to
*'4.1.135.Final'*
--
This message was sent by Atlassian Jira
(v8.20.10#820010)