[
https://issues.apache.org/jira/browse/ZOOKEEPER-5056?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Badreddine Itani updated ZOOKEEPER-5056:
----------------------------------------
Summary: Netty CVE vulnerabilities in zookeeper 3.9.5 (was: Netty CVE
vunrabilities in zookeeper 3.9.5)
> Netty CVE vulnerabilities in zookeeper 3.9.5
> --------------------------------------------
>
> Key: ZOOKEEPER-5056
> URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5056
> Project: ZooKeeper
> Issue Type: Bug
> Components: security
> Affects Versions: 3.9.5
> Reporter: Badreddine Itani
> Priority: Major
>
> We are installing Zookeeper 3.9.5 on a production server.
> Our security scan detected the following critical vulnerabilities (3):
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42579]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42581]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42584]
> Additionally the following high vulnerabilities (7):
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-33870]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-33871]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42578]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42583]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42585]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-42587]
> * [https://nvd.nist.gov/vuln/detail/CVE-2026-44248]
> I will open a Pull request to upgrade the netty version from
> {*}'{*}{*}4.1.130.Final'{*} to
> *'4.1.135.Final'*
--
This message was sent by Atlassian Jira
(v8.20.10#820010)