Fixed CVEs

This release resolves 3105 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.3.6.4-1 to 3.3.6.5-1.


Detailed List of CVE Fixes

For detailed information about CVEs addressed in this release, see ODP 3.3.6.5-1 CVE Fixes.

You can see the summary of CVEs addressed by components and severity level.



CVE Fix Descriptions

Airflow

  • OSV-16696 — Bumped up Airflow Python dependencies (Mako 1.3.12, PyJWT 2.12.0, Pygments 2.20.0, aiohappyeyeballs 2.5.0) to address ODP 3.3.6.4 CVEs.

Celeborn

  • OSV-22793 — Fix ByteBuf.release() ambiguity for Netty 4.1.135.Final.

  • OSV-22793 — Increasing Netty version to 4.1.135.Final.

  • OSV-22805 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479.

  • OSV-22807 — Bumped up commons-lang3 to 3.18.0, Jetty to 9.4.57.v20241219, to address ODP 3.3.6.4 CVEs.

  • OSV-22808 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

Cruise-control

  • OSV-23145 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-23147 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

  • OSV-23150 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-23151 — Increasing Netty version to 4.1.135.Final.

  • OSV-23152 — Bumped up Log4j to 2.25.4 to address CVE-2025-68161.

Cruise-control3

  • OSV-23170 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-23171 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-23176 — Bumped up vertx to 4.5.24 to address CVE-2024-1023/CVE-2024-1300/CVE-2025-11965/CVE-2025-11966/CVE-2026-1002.

  • OSV-23186 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

Druid

  • OSV-21527 — Bumped up BouncyCastle to 1.84.

  • OSV-21529 — Bumped up PostgreSQL JDBC to 42.7.11 to address CVE-2026-42198.

  • OSV-21534 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-21535 — Bumped up azure-sdk-bom/azure-identity to 1.2.25 to address CVE-2024-35255.

  • OSV-21536 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21543 — Increasing Netty version to 4.1.135.Final.

  • OSV-21548 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479.

  • OSV-21549 — Bumped up Rhino to 1.7.15.1 to address CVE-2025-66453.

  • OSV-21559 — Bumped up async-http-client to 3.0.10 to address CVE-2026-40490/CVE-2026-45300.

  • OSV-21562 — Bumped up commons-compress to 1.26.0 to address CVE-2024-25710/CVE-2024-26308.

  • OSV-21566 — Bumped up plexus-utils to 3.6.1 to address CVE-2025-67030.

  • OSV-21569 — Bumped up Jetty to 9.4.57.v20241219 to address CVE-2024-13009/CVE-2024-6763.

  • OSV-21615 — Bumped up aircompressor to 2.0.3 to address CVE-2025-67721.

Flink

  • OSV-21617 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-21623 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-22210 — Bumping aws-java-sdk version to 1.12.797 to fix CVE-2025-58057.

  • OSV-22227 — Bumping up okio-jvm to 3.4.0 to fix CVE-2023-3635.

  • OSV-22228 — Bumping up jackson-core to 2.18.6 to fix CVE-2025-52999.

  • OSV-22243 — Increasing Netty version to 4.1.135.Final.

  • ODP-7456 | OSV-22227 — Bump Kotlin stdlib to 1.8.0 to align with okio-jvm:3.4.0.

Hbase

  • OSV-21633 — Increasing Netty version to 4.1.135.Final.

  • OSV-21643 — Bumped up okio-jvm to 3.4.0 to address CVE-2023-3635.

  • OSV-21646 — Bumped up jakarta.mail to 1.6.8.

  • OSV-21648 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-21668 — Bumped up opentelemetry-javaagent to 2.26.1 to address CVE-2026-33701.

  • OSV-22190 | OSV-19098 — Upgrade to hbase-thirdparty 4.1.13.

  • OSV-22212 — Bump opentelemetry.version from 1.49.0 to 1.62.0.

Hbase-connectors

  • OSV-24138 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-24161 — Bumped up commons-lang3 to 3.18.0 to address ODP 3.3.6.4 CVEs.

  • OSV-24186 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

Hive

Note: The source header for this section read "ss CVEs" (a truncated fragment of "CVE Fixes") with no entries listed directly under it. The actual OSV-* entries were interleaved into the middle of the "Bug Fix" list further down the page — almost certainly a column-order artifact from the PDF. I've reassembled the CVE entries here by pulling out every OSV-*-prefixed line from that block, in the order they appeared; the remaining ODP-*/OCR-* lines are listed in bug-fixes.md. Confirm this reconstruction against the original source.

  • OSV-21252 — Bumped up async-http-client to 3.0.10 to address CVE-2026-40490.

  • OSV-21185 — Bumped up commons-configuration2 to 2.15.0 to address [source text cut off after "addre"].

  • OSV-21155 — Increasing Netty version to fix CVE-2026-42583.

  • OSV-21153 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-21174 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479.

  • OSV-21150 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21258 — Bumped up grpc-netty-shaded to 1.75.0 to address CVE-2025-55163.

  • OSV-21268 — Bumped up aircompressor to 2.0.3 to address CVE-2025-67721.

Hue

See the note in improvements.md — the OSV-* entries below followed immediately after "ODP-6942" with no clear header boundary in the source. Placed here as CVE Fixes since each is explicitly tagged "CVE."

  • ODP-7306 | OSV-21147 — Bump Django to 4.2.30 and restore Mako 1.3.12 (#37).

  • OSV-21120 — Bumped up djangorestframework-simplejwt to 5.5.1 [source text cut off after "to…"].

  • OSV-21098 — Bumped up pyasn1 to 0.6.3 to address CVE-2026-30922 (#24).

  • OSV-21099 — Bumped up Markdown to 3.8.1 to address CVE-2025-69534 (#25).

  • OSV-21116 — Bumped up urllib3 to 2.7.0 to address CVE-2026-44431/CVE-2026-44432 (#26).

  • OSV-21118 — Bumped up requests to 2.33.0 to address CVE-2024-47081/CVE-2026-25645 (#27).

  • OSV-21121 — Bumped up PyJWT to 2.12.0 to address CVE-2026-32597 (#29).

  • OSV-21124 — Bumped up djangorestframework to 3.15.2 to address CVE-2024-21520 (#30).

  • OSV-21125 — Bumped up cryptography to 44.0.1 to address CVE-2024-12797/GHSA-h4gh-qq45-vh27 (#31).

  • OSV-21135 — Bumped up cbor2 to 5.9.0 to address CVE-2026-26209 (#32).

  • OSV-21136 — Bumped up sqlparse to 0.5.4 to address GHSA-27jp-wm6q-gp25 (#33).

  • OSV-21147 — Bumped up Mako to 1.3.12 to address CVE-2026-41205/CVE-2026-44307 (#34).

  • OSV-21100 — Bumped up python-ldap to 3.4.5 to address CVE-2025-61911/CVE-2025-61912 (#35).

Impala

  • OSV-22244 — Bumped up Netty to 4.1.133.Final to address CVE-2025-58056/CVE-2025-58057/CVE-2025-67735/CVE-2026-33870/CVE-2026-41417/CVE-2026-42580/CVE-2026-42581/CVE-2026-42583/CVE-2026-42584/CVE-2026-42585/CVE-2026-42587.

  • OSV-22274 — Bumped up OpenTelemetry to 1.62.0 to address CVEs.

  • OSV-22301 — Bumped up okio to 3.4.0 to address CVE-2023-3635.

  • OSV-22302 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-22311 — Bumped up PostgreSQL to 42.7.11 to address CVE-2026-42198.

  • OSV-22313 — Bumped up Jetty to 9.4.57.v20241219 to address CVEs.

  • OSV-22321 — Bumped up commons-lang3 to 3.18.0 to address CVEs.

  • OSV-22331 — Bumped up commons-compress to 1.26.0 to address CVEs.

  • OSV-22336 — Bumped up Spring Framework to 5.3.39 to address CVE-2024-38808.

  • OSV-22342 — Bumped up Log4j to 2.25.4 to address CVE-2025-68161.

  • OSV-22359 — Bumped up grpc-netty-shaded to 1.75.0 to address CVEs.

  • OSV-22363 — Bumped up commons-configuration2 to 2.15.0 to address CVEs.

  • OSV-22369 — Bumped up logback to 1.5.25 to address CVE-2026-1225.

  • OSV-22375 — Bumped up sqlparse to 0.5.4 to address CVE-2023-30608/CVE-2024-4340/GHSA-27jp-wm6q-gp25.

Jupyterhub

  • ODP-7305 — Keep Jupyterhub 5.2.1; bump jupyterlab_server to 2.28.0.

  • OSV-22979 — Bumped up idna to 3.15 to address CVE-2026-45409.

  • OSV-22980 — Bumped up mistune to 3.2.1 to address CVE-2026-33079/CVE-2026-44897.

  • OSV-22984 — Bumped up h11 to 0.16.0 to address CVE-2025-43859.

  • OSV-22985 — Bumped up Mako to 1.3.12 to address CVE-2026-41205/CVE-2026-44307.

  • OSV-22987 — Bumped up nbconvert to 7.17.1 to address CVE-2026-39377/CVE-2026-39378.

  • OSV-22989 — Bumped up ray to 2.55.0 to address CVE-2026-41486.

  • OSV-22990 — Bumped up pyasn1 to 0.6.3 to address CVE-2026-23490/CVE-2026-30922.

  • OSV-22993 — Bumped up cryptography to 44.0.1 to address CVE-2024-12797.

  • OSV-22995 — Bumped up jupyterlab to 4.5.7 to address CVE-2024-39700/CVE-2025-59842/CVE-2026-40171/CVE-2026-42266/CVE-2026-42557.

  • OSV-23000 — Bumped up Pygments to 2.20.0 to address CVE-2026-4539.

  • OSV-23002 — Bumped up urllib3 to 2.7.0 to address CVE-2026-44431/CVE-2026-44432.

  • OSV-23004 — Bumped up oauthenticator to 17.4.0 to address CVE-2026-33175.

  • OSV-23005 — Bumped up notebook to 7.5.6 to address CVE-2026-40171/CVE-2026-42557.

  • OSV-23007 — Bumped up jupyterhub to 5.4.5 to address CVE-2026-33709/CVE-2026-40864.

  • OSV-23009 — Bumped up requests to 2.33.0 to address CVE-2026-25645.

  • OSV-23012 — Bumped up aiohttp to 3.13.4 to address CVE-2026-22815/CVE-2026-34513/CVE-2026-34514/CVE-2026-34515/CVE-2026-34516/CVE-2026-34517/CVE-2026-34518/CVE-2026-34519/CVE-2026-34520/CVE-2026-34525.

  • OSV-23022 — Bumped up pillow to 12.2.0 to address CVE-2026-25990/CVE-2026-40192/CVE-2026-42308/CVE-2026-42310/CVE-2026-42311.

  • OSV-23028 — Bumped up tornado to 6.5.5 to address CVE-2024-52804/CVE-2025-47287/CVE-2025-67724/CVE-2025-67725/CVE-2025-67726/CVE-2026-31958/CVE-2026-35536/GHSA-78cv-mqj4-43f7.

  • OSV-23036 — Bumped up PyJWT to 2.12.0 to address CVE-2026-32597.

Kafka

  • OSV-21706 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21721 — Bumped up Jackson to 2.18.6 to address CVE-2020-8840.

  • OSV-22426 — Increasing Netty version to 4.1.135.Final.

Kafka3

  • OSV-22435 — Bumped up lz4-java to 1.8.1 to address CVE-2025-12183.

  • OSV-22436 — Bumped up plexus-utils to 3.6.1 to address CVE-2025-67030.

  • OSV-22437 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

Knox

  • OSV-21272 — Bump Netty to 4.1.135.Final (Netty 4.1.1* CVEs).

  • OSV-21274 — Bumped up Spring Framework to 5.3.39 to address CVE-2024-38808/CVE-2024-38809.

  • OSV-21275 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-21279 — Bumped up PostgreSQL to 42.7.11 to address CVE-2026-42198.

  • OSV-21280 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21286 — Bumped up nimbus-jose-jwt to 9.37.4 [source text cut off after "to address CVE-…"].

  • OSV-21303 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-21308 — Bumped up jakarta.mail to 1.6.8 to address CVE-2025-7962.

  • OSV-21311 — Bumped up mina-core to 2.0.28 to address CVE-2026-41409/CVE-2026-41635.

Kudu

  • OSV-21391 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21414 — Bumped up Netty4 to 4.1.135.Final to address CVE-2026-42578.

  • OSV-21416 — Bumped up commons-compress to 1.26.0 to address CVE-2024-25710/CVE-2024-26308.

  • ODP-7168 — Bump log4j2 to 2.25.4 for vulnerability fix.

Livy

  • OSV-21776 — Increasing Netty version to 4.1.135.Final.

  • OSV-21784 — Bumped up commons-configuration2 to 2.15.0, okio to 3.4.0 [source text cut off after "okio 3.4.0…"].

  • OSV-21784 — Also bump commons-configuration2 to 2.15.0.

  • OSV-21785 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

Note: The source lists OSV-21784 twice with different wording (a bundled bump, then a standalone "also bump" note). Reproduced as-is — confirm whether this is one ticket described twice or two distinct entries that should share different IDs.

Nifi

  • OSV-21420 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-21421 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-21449 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-21466 — Increasing Netty version to 4.1.135.Final.

  • OSV-21493 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

  • OSV-21505 — Bumped up logback to 1.3.16 to address CVE-2024-12798/CVE-2024-12801/CVE-2025-11226.

  • OSV-21511 — Bumped up jakarta.mail to 1.6.8 to address CVE-2025-7962.

  • ODP-7169 — Bump log4j2 to 2.25.4 for vulnerability fix.

Nifi2

  • OSV-23361 — Bumped up Spring Boot to 3.5.14 to address CVEs.

  • OSV-23349 — Bumped up Spring Framework to 6.2.18 to address CVEs.

  • OSV-23347 — Bumped up Netty to 4.2.13.Final to address CVE-2026-42577.

  • OSV-23348 — Bumped up Jetty to 12.1.8 to address CVE-2026-1605/CVE-2026-2332/CVE-2026-5795.

  • OSV-23360 — Bumped up Spring Security to 6.5.10 to address CVE-2026-22732/CVE-2026-22746/CVE-2026-22748/CVE-2026-22751.

  • OSV-23363 — Bumped up undertow-core to 2.3.21.Final to address CVE-2024-3884/CVE-2024-4027/CVE-2025-12543.

  • OSV-23382 — Bumped up logback to 1.5.25 to address CVE-2026-1225.

  • OSV-23388 — Bumped up Jackson to 2.21.1 to address GHSA-72hv-8253-57qq.

ODP-Ambari

  • OSV-24197 — Bumped up Spring LDAP to 2.4.4 to address CVE-2024-38829.

  • OSV-24198 — Bumped up Netty to 4.1.135.Final to address CVE-2026-41417.

  • OSV-24202 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2024-29131.

  • OSV-24205 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-24206 — Bumped up Spring Framework to 6.2.19 to address CVE-2024-38809.

  • OSV-24211 — Bumped up Spring Security to 6.0.8 [source text cut off after "to address CVE-2…"].

  • OSV-24214 — Bumped up Nimbus JOSE JWT to 9.37.4 to address CVE-2025-53864.

  • OSV-24224 — Bumped up Mina to 2.0.28 to address CVE-2026-41409.

  • OSV-24249 — Bumped up Logback to 1.3.16 to address CVE-2024-12798.

  • OSV-24279 — Bumped up commons-io to 2.15.1 to address CVE-2021-29425.

  • OSV-24391 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-24398 — Bumped up PostgreSQL JDBC to 42.7.13 to address CVE-2026-42198.

Oozie

  • OSV-21820 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479.

  • OSV-21822 — Bumped up batik/xmlgraphics/xalan/c3p0/jgit to address Oozie-owned CVEs.

  • OSV-21996 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

Ozone

  • OSV-22071 — Increasing Netty version to 4.1.135.Final.

  • OSV-22074 — Bumped up Spring Framework to 5.3.39 to address CVE-2024-38808.

  • OSV-22100 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-22131 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-22144 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-22146 — Bumped up Netty to 4.1.133.Final to address CVE-2026-42578.

  • ODP-7495 — Bumping commons-io to 2.22.0 due to a CVE.

Ozone2

Note: In the source, these four entries each ended with "to address" and no CVE ID — the actual CVE numbers (CVE-2025-68161, CVE-2026-45205, CVE-2026-45292, CVE-2026-42578) appeared later on the page, after the unrelated "phoenix" section, as an orphaned list of four lines. I've matched each CVE number back to its entry, in order, and cross-checked each pairing against identical fixes elsewhere in this changelog (for example, Log4j 2.25.4 → CVE-2025-68161 also appears under cruise-control). Confirm this reconstruction before publishing.

  • OSV-23532 — Bumped up Log4j to 2.25.4 to address CVE-2025-68161.

  • OSV-23526 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-23527 — Bumped up OpenTelemetry to 1.62.0 to address CVE-2026-45292.

  • OSV-23513 — Bumped up Netty to 4.1.133.Final to address CVE-2026-42578.

Phoenix

  • OSV-22782 — Bumped up Log4j to 2.25.4 to address CVE-2026-34478.

  • OSV-22792 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

Pinot

  • OSV-22158 — Bumped up Netty to 4.1.135.Final to address CVE-2026-41417/CVE-2026-42578/CVE-2026-42579/CVE-2026-42580/CVE-2026-42581/CVE-2026-42583/CVE-2026-42584/CVE-2026-42585/CVE-2026-42586/CVE-2026-42587/CVE-2026-44248.

Ranger

  • OSV-22482 — Bumped up Jackson to 2.18.6 to address PRISMA-2023-0067.

  • OSV-22495 — Bumped up opentelemetry to 1.62.0 to address CVE-2026-45292.

  • OSV-22504 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-22523 — Bumped up poi to 5.4.0 to address CVE-2025-31672.

  • OSV-22548 — Bumped up Tomcat to 9.0.120 to address CVE-2026-24880/CVE-2026-25854/CVE-2026-29129/CVE-2026-29145/CVE-2026-29146/CVE-2026-32990 and others [source list truncated with "..."].

  • OSV-22565 — Bumped up logback to 1.3.16 to address CVE-2024-12798/CVE-2024-12801/CVE-2025-11226.

  • OSV-22568 — Increasing Netty version to 4.1.135.Final.

  • OSV-22577 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-22646 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

Registry

  • OSV-22868 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

  • OSV-22874 — Bumped up logback to 1.3.16 to address CVE-2024-12798/CVE-2024-12801/CVE-2025-11226.

  • OSV-22879 — Bumped up Jackson to 2.18.6 to address PRISMA-2023-0067.

  • OSV-22882 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-22894 — Bumped up plexus-utils to 3.6.1 to address CVE-2025-67030.

  • OSV-22896 — Bumped up PostgreSQL to 42.7.11 to address CVE-2026-42198.

Spark3

  • OSV-23559 — Bumped up Jackson to 2.18.6 to address PRISMA-2023-0067.

  • OSV-23562 — Bumped up Netty to 4.1.135.Final to address CVE-2026-42583.

  • OSV-23580 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479.

  • ODP-7165 — Bump log4j2 to 2.25.4 for vulnerability fix.

Spark4

Note: No CVE-tagged entries were identifiable for Spark4 — see the reconstruction note in improvements.md and bug-fixes.md. The "CVE Fixes" header appeared in the source with no distinguishable CVE content beneath it.

Sqoop

  • OSV-23399 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-23405 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • ODP-7170 — Bump log4j2 to 2.25.4 for vulnerability fix.

Tez

  • OSV-23224 — Bumped up async-http-client to 2.15.0, okio to 3.4.0, commons-configuration2 to 2.15.0, to address ODP 3.3.6.4 CVEs.

  • ODP-7165 — Bump log4j2 to 2.25.4 for vulnerability fix.

  • OSV-23633 — Bumped up Jackson to 2.21.1 to address GHSA-72hv-8253-57qq (#196).

  • OSV-23646 — Bumped up Log4j to 2.25.4 to address CVE-2026-34479 (#200).

  • OSV-23629 — Bumped up Netty to 4.2.13.Final to address CVE-2026-42579 (#204).

  • OSV-23624 — Bumped up lz4-java to 1.8.1, vertx to 4.5.24, to address Spark4 CVEs (#212).

  • OSV-23227 — Increasing Netty version to 4.1.135.Final.

  • OSV-23253 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

Trino

  • OSV-23411 — Increasing Netty version to 4.1.135.Final.

  • OSV-23419 — Bumped up Jackson to 2.21.1 to address GHSA-72hv-8253-57qq.

  • OSV-23420 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-23421 — Bumped up Jetty to 12.0.34 to address CVE-2025-11143/CVE-2026-1605/CVE-2026-2332/CVE-2026-5795.

  • OSV-23425 — Bumped up reactor-netty to 1.2.8 [source text cut off after "to address CVE-202…"].

  • OSV-23442 — Bumped up snowflake-jdbc to 3.23.1 to address CVE-2025-27496/CVE-2026-3293.

  • OSV-23444 — Bumped up grpc-netty-shaded to 1.75.0 to address CVE-2025-55163.

  • OSV-23454 — Bumped up bcprov-jdk18on to 1.84 to address CVE-2026-0636/CVE-2026-5598.

  • OSV-23456 — Bumped up OpenTelemetry to 1.62.0 [source text cut off after "to address CVE-20…"].

  • OSV-23462 — Bumped up logback to 1.5.25 to address CVE-2025-11226/CVE-2026-1225.

  • OSV-23465 — Bumped up lz4-java to 1.10.1 to address CVE-2025-66566.

Trino-gateway

  • OSV-24090 — Bumped up Jetty to 12.0.34 to address CVE-2025-11143/CVE-2025-1948/CVE-2025-5115/CVE-2026-1605/CVE-2026-2332/CVE-2026-5795.

  • OSV-24093 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

  • OSV-24103 — Bumped up Jackson to 2.18.6 to address GHSA-72hv-8253-57qq.

  • OSV-24109 — Bumped up aircompressor-v3 to 3.4 to address CVE-2025-67721.

  • OSV-24110 — Bumped up logback to 1.5.25 to address CVE-2025-11226/CVE-2026-1225.

  • OSV-24112 — Bumped up jakarta.mail to 2.0.2 to address CVE-2025-7962.

  • OSV-24113 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

Zeppelin

  • OSV-23748 — Bumped up Netty to 4.1.133.Final to address CVE-2025-55163/CVE-2025-58056/CVE-2025-59419/CVE-2025-67735/CVE-2026-33870/CVE-2026-33871/CVE-2026-41417/CVE-2026-42578/CVE-2026-42579/CVE-2026-42580/CVE-2026-42581/CVE-2026-42583/CVE-2026-42584/CVE-2026-42585/CVE-2026-42586/CVE-2026-42587/CVE-2026-44248.

  • OSV-23761 — Bumped up commons-net to 3.9.0 [source text cut off after "to address CVE-2021-…"].

  • OSV-23762 — Bumped up OpenTelemetry to 1.62.0 to address CVE-2026-45292.

  • OSV-23764 — Bumped up okio to 3.4.0 to address CVE-2023-3635.

  • OSV-23765 — Bumped up Jackson to 2.18.6 to address CVE-2020-9548.

  • OSV-23818 — Bumped up Jetty to 11.0.28 to address CVE-2025-11143/CVE-2026-2332/CVE-2026-5795.

  • OSV-23822 — Bumped up plexus-utils to 3.6.1 to address CVE-2025-67030.

  • OSV-23825 — Bumped up commons-configuration2 to 2.15.0 to address CVE-2026-45205.

  • OSV-23826 — Bumped up nimbus-jose-jwt to 10.0.2 to address CVE-2025-53864.

  • OSV-23827 — Bumped up okhttp to 4.9.2 [source text cut off after "to address CVE-2021-0341/…"].

  • OSV-23829 — Bumped up BouncyCastle to 1.84 to address CVE-2024-29857/CVE-2024-30171/CVE-2024-34447/CVE-2025-8916/CVE-2026-5588.

  • OSV-23841 — Bumped up jsoup to 1.15.3 to address CVE-2022-36033.

  • OSV-23846 — Bumped up commons-vfs2 to 2.10.0 to address CVE-2025-27553/CVE-2025-30474.

  • OSV-23867 — Bumped up jinjava to 2.8.3 to address CVE-2025-59340/CVE-2026-25526.

  • OSV-23870 — Bumped up commons-lang3 to 3.18.0 to address CVE-2025-48924.

  • OSV-23872 — Bumped up mina-core to 2.0.28 to address CVE-2026-41409/CVE-2026-41635.

Zookeeper

  • OSV-23899 — Bumping up netty-codec to 4.1.135.Final to fix CVE-2026-42583.

  • OSV-23906 | ZOOKEEPER-4986 — Disable reverse DNS lookup in the TLS client and server (branch-3.8).

  • OSV-23907 — Add log redactor method when logging ZK config properties.



  Last updated