Skip to content

[fix][sec] Upgrade Jetty to address CVE-2026-5795 - #25532

Merged
lhotari merged 1 commit into
apache:masterfrom
lhotari:lh-upgrade-jetty-12.1.8
Apr 15, 2026
Merged

[fix][sec] Upgrade Jetty to address CVE-2026-5795#25532
lhotari merged 1 commit into
apache:masterfrom
lhotari:lh-upgrade-jetty-12.1.8

Conversation

@lhotari

@lhotari lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member

Motivation

There's yet another recent CVE in Jetty, CVE-2026-5795.

Modifications

Upgrade Jetty to 12.1.8

Additional details

Jetty project doesn't support 9.4.x any more. The fixed version 9.4.61 is released only for paying customers. The same applies for the fix for CVE-2026-2332.

@lhotari lhotari added this to the 4.3.0 milestone Apr 15, 2026
@lhotari
lhotari requested a review from merlimat April 15, 2026 16:34
@lhotari

lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member Author

Fix for 9.4.x is only available for paying customers. More details at #25527 (comment) . @merlimat We'll have some trouble with Pulsar 4.0.x. Perhaps we should migrate to Jetty 12 also on 4.0 LTS?

@lhotari

lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member Author

Fix for 9.4.x is only available for paying customers. More details at #25527 (comment) . @merlimat We'll have some trouble with Pulsar 4.0.x. Perhaps we should migrate to Jetty 12 also on 4.0 LTS?

@merlimat I'll give this a try with Claude Code.

@lhotari

lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member Author

The Jetty 12 backport for branch-4.0 is #25534

@lhotari
lhotari merged commit e05c212 into apache:master Apr 15, 2026
43 checks passed
lhotari added a commit that referenced this pull request Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants