Fixed CVEs
This release resolves 895 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.3.6.3-1 to 3.3.6.4-1.
Detailed List of CVE Fixes
For detailed information about CVEs addressed in this release, see ODP 3.3.6.4-1 Acceldata Open-Source Data Platform CVE Fixes.
Summary of CVEs by component and severity level
You can see the summary of CVEs addressed by components and severity level.
CVE Fix Descriptions
Airflow
- OSV-16499, OSV-16505, OSV-16506, OSV-16507, OSV-16509, OSV-16511, OSV-16512, OSV-16514, OSV-16515, OSV-16516, OSV-16517, OSV-16519, OSV-16531 Addressing multiple CVE fixes in WTForms, xmlsec, yarl, zipp, zope - Addressing multiple CVE fixes in WTForms, xmlsec, yarl, zipp, zope
Ambari
- ODP-6645: Upgraded
.commons-io - OCR-2427: Upgraded
for CVE-2022-48285 fixes.jszip - OCR-2427: Upgraded
for CVE-2026-27601 fixes.underscore.js - OSV-15824: Applied CVE fixes for
.spring-security-crypto - OSV-15832: Applied CVE fixes for
.snappy-java - OSV-15756: Applied Spring related CVE fixes.
- OSV-15854: Applied PostgreSQL related CVE fixes.
- OSV-15754: Applied Jetty related CVE fixes.
- OSV-15755: Applied
related CVE fixes.jetty.http2 - OSV-15879: Applied
related CVE fixes.jettison - OSV-15765: Applied
related CVE fixes.mina-core - OSV-15841: Applied
related CVE fixes.commons-compress - OSV-15888: Applied Avro related CVE fixes.
- OSV-15705: Applied
related CVE fixes.json-smart - OSV-15694: Applied Log4j related CVE fixes.
- OSV-15867: Applied Netty and
related CVE fixes.netty-codec - OSV-15857 | OSV-15901 | OSV-15758: Applied BeanUtils, Derby, and HSQLDB related CVE fixes.
- OSV-15701: Applied
related CVE fixes.nimbus-jose-jwt - OSV-15852: Applied
related CVE fixes.mchange-commons-java - OSV-15779: Applied
related CVE fixes.com.mchange_c3p0 - OSV-15837: Applied
related CVE fixes.com.h2database_h2 - OSV-15826: Applied
related CVE fixes.protobuf-java - OSV-15682: Applied Guava and related CVE fixes.
- OSV-15710: Applied Jackson Databind and related CVE fixes.
- OSV-15685: Applied Jackson and related CVE fixes.
- OSV-15902: Upgraded
to version 1.17.com.esotericsoftware.yamlbeans_yamlbeans
Cruise Control
- OSV-13090: Bumped Jetty version to
.9.4.58.v20250814
Cruise Control 3
- OSV-13097: Bumped Netty to
.4.1.130.Final - OSV-13096: Bumped Jetty version to
.9.4.58.v20250814 - ODP-6108: Bumped Log4j2 to
for vulnerability fixes.2.25.3
Druid
- Migrated JAXB bind dependency to Jakarta (
).apache#17370 - OSV-12602 | CVE-2024-29131: Bumped
tocommons-configuration2.2.10.1 - OSV-12603 | CVE-2025-55163: Upgraded
.grpc_grpc-netty-shaded - OSV-12606 | CVE-2025-55163: Upgraded
tonetty-codec-http2in4.1.124.Final.druid-azure-extensions - Updated
and corresponding license files (jose4j).apache#16078 - Bumped Jackson to
and Fabric8 to2.18.4(7.2.0).apache#18013 - Upgraded Jackson and Google GSON to address CVEs (
).apache#15461 - OSV-12617: Patched Jackson upgrades to address
andCVE-2022-42004.CVE-2022-42003
Flink
- ODP-6342: Bumped Netty version to
.4.1.132.Final - FLINK-38193 | CVE-2025-48924: Bumped
to versioncommons-lang3.3.18.0 - OSV-13324 | CVE-2025-68161: Bumped
tolog4jVersion.2.25.3
Hadoop
- Matched
version inbcprov-jdk18on.hadoop-hdfs-client.pom - Updated
version tobcprov-jdk18on.1.78 - Upgraded Bouncy Castle libraries to version
.1.78 - Bumped
inorg.bouncycastle:bcprov-jdk18on.hadoop-project - HADOOP-19024: Updated Bouncy Castle JDK18 to version
.1.77 - HADOOP-18540: Upgraded Bouncy Castle to
.1.70 - OSV-13528 | CVE-2025-48924: Upgraded
tocommons-lang3.3.18.0 - HADOOP-18496: Upgraded
and related dependencies to address Kotlin CVEs.okhttp3 - HADOOP-19632: Upgraded
tonimbus-jose-jwt.10.4 - OSV-12789 | HADOOP-19788 | CVE-2025-59419: Upgraded Netty4 version to
.4.1.130 - OSV-12791 | HADOOP-18991 | CVE-2025-48734: Removed
dependency from Hadoop3.commons-beanutils
HBase
- ODP-6109: Bumped Log4j2 to
for vulnerability fixes.2.25.3 - OSV-12618 | OSV-13399: Increased Tomcat version to address CVEs.
- HBASE-29928: Bumped
fromio.airlift:aircompressorto0.27.2.0.3 - HBASE-29740: Upgraded
tolz4-java.1.8.1+
Hive
- OSV-13183 | HIVE-28417: Bumped Log4j2 to address CVEs.
- OSV-13852: Bumped Jetty version to address CVEs.
- OSV-13188: Bumped
to address CVEs.nimbus-jose - OSV-13379: Increased
andcommons-compressversions to address CVEs.avatica - OSV-12390 | HIVE-28224: Bumped
to address CVEs.orc-core - OSV-13181: Bumped
to address CVEs.velocity-core - OSV-13173: Bumped
to address CVEs.commons-lang3 - OSV-13168: Bumped
to address CVEs.avatica - OSV-12468: Bumped Netty version to address CVEs.
- HIVE-28856: Removed
dependency.jetty-runner - ODP-6114: Bumped Log4j2 to
for vulnerability fixes.2.25.3
Hue
- OSV-12381 | OSV-12380 | OSV-12379 | OSV-12378 | OSV-12377: Fixed CVEs and rebuilt the old protobuf files.
Impala
- OSV-11051: Updated
to versioncommons-configuration2.2.10.1 - OSV-11056: Excluded and added
dependency.protobuf-java - OSV-11063: Added Netty dependencies to dependency management for
.kudu-client
JupyterHub
- ODP-6226: Updated
to patched versionfonttoolsto address4.45.1.CVE-2025-66034 - OSV-12016: Upgraded Jinja2 version to address CVEs.
Kafka 2
- OSV-16240 | CVE-2025-67030: Upgraded
toplexus-utils.4.0.3
Kafka 3
- OSV-13097: Bumped Netty to
.4.1.132.Final - OSV-12824: Bumped Checkstyle to
.12.3.1 - OSV-12825: Bumped
toorg.bitbucket.b_c_jose4j.0.9.6
Knox
- OSV-9834 | KNOX-3178: Upgraded dependencies to address CVEs.
- ODP-6110: Bumped Log4j2 to
for vulnerability fixes.2.25.3 - OSV-4624: Upgraded
tocom.nimbusds_nimbus-jose-jwtto address CVEs.9.37.3
Kudu
- OSV-12533: Matched Ranger lib Guava version with Kudu Java dependencies.
- OSV-12523: Matched Kudu Ranger lib
version with ODP Ranger tocommons-configuration2.2.10.1 - OSV-12525 | OSV-12527: Upgraded Netty to
to address CVEs.4.1.130.Final - OSV-12523: Updated Guava version to
in Kudu Ranger lib.32.0.1-jre - ODP-6112: Bumped Log4j2 to
for vulnerability fixes.2.25.3
Livy
- OSV-13357: Increased
version tocommons-lang3to address3.18.0.CVE-2025-48924 - OSV-13357: Increased Netty version to
to address4.1.130.Final.CVE-2025-67735
NiFi / NiFi Registry
- OSV-12598: Bumped
fromio.netty_netty-codec-http2to4.1.118.Final.4.1.124.Final - OSV-12597: Bumped shaded
gRPC toio.grpc_grpc-netty-shaded.1.75.0 - OSV-12594: Bumped
fromcommons-beanutils_commons-beanutilsto1.9.4.1.11.0 - OSV-12593 | OSV-12592: Bumped
fromcom.mchange_c3p0to0.9.5.4and0.12.0frommchange-commons-javato0.2.15.0.4.0 - OSV-12590: Bumped Jetty from
to9.4.56.v20240826.9.4.58.v20250814 - OSV-12589: Bumped
toprotobuf-java.3.25.5 - OSV-12581: Bumped Jersey from
to2.45.2.46
Oozie
- OSV-13380: Increased Jetty version to
to address CVEs.9.4.57.v20241219
Ozone
- OSV-11049: Bumped
to address CVEs.commons-beanutils - OSV-11016: Bumped
to address CVEs.commons-lang3 - OSV-11048: Bumped
to address CVEs.commons-io - OSV-11020: Bumped
to address CVEscommons-compress
Phoenix
- OSV-12933: Bumped Jetty version to address CVEs.
- ODP-6115: Bumped Log4j2 to
for vulnerability fixes.2.25.3
Pinot
- OSV-10752: Excluded Jackson libraries from
module that pulled older Jackson versions.pinot-orc - OSV-10752: Excluded Protobuf libraries from
module that pulled older Protobuf versions.pinot-parquet - OSV-10752: Increased Helix version to address
.CVE-2023-38647 - OSV-13469 | OSV-10752: Increased Log4j version to address
.OSV-10702 - OSV-12756 | OSV-10752: Increased
version to address CVEs.aircompressor - OSV-13467: Increased
version toclassgraphto address4.8.165.CVE-2021-47621
Ranger
- OSV-12863: Upgraded Tomcat to
to address CVEs.9.0.115 - OSV-12847: Upgraded Netty to
to address CVEs.4.1.130.Final - OSV-12840: Upgraded
tocommons-configuration2to address2.10.1.CVE-2024-29131 - OSV-12841: Dropped unused Elasticsearch JARs from Yarn plugin packaging to address CVEs.
- OSV-12830: Dropped unused Jetty HTTP component JARs to address CVEs.
Schema Registry
- OSV-11646: Bumped Nimbus version to
.10.0.1 - OSV-11653: Bumped
toorg.bitbucket.b_c_jose4j.0.9.6 - OSV-11749: Removed
from dependency tree.org.elasticsearch_elasticsearch - OSV-11756: Bumped
todnsjava.3.6.0 - OSV-11730: Bumped Jetty version.
- OSV-11664: Removed unused Zookeeper dependencies.
- OSV-11658: Bumped
version.jdom2 - OSV-11642: Bumped
tojackson-databind.2.15.0 - OSV-11742: Removed Jackson 1 dependencies.
- OSV-11632: Bumped
.commons_text - OSV-11757: Bumped
tosnakeyaml.2.0 - OSV-7607: Bumped Logback to
to address CVEs.1.2.13 - OSV-7681: Bumped Avro to
to address CVEs.1.11.4 - OSV-5583: Bumped Jackson to
to address CVEs.2.16.1
Spark 3
- OCR-2334: Increased
version toaws.java.sdkto address1.12.791.CVE-2025-58057 - OSV-13646: Increased Vert.x version to
.4.5.24 - ODP-6111: Bumped Log4j2 to
for vulnerability fixes.2.25.3 - OSV-13653: Increased Log4j version to
.2.24.3 - OSV-12917 | SPARK-52434: Upgraded
togcs-connector.2.2.28 - OSV-13653: Increased Netty version to
to address4.1.130.Final.CVE-2025-58057 - OSV-11402: Increased
version tocommons-lang3.3.18.0 - OSV-12929: Updated
version tolz4-java.1.10.4 - OSV-12929 | SPARK-55803: Bumped
tolz4-javato restore performance improvements.1.10.4 - OSV-12912 | OSV-12333: Increased Hudi version to address
.CVE-2020-36183
Sqoop
- OSV-13375: Increased
version tosnakeyamlto address1.33.CVE-2022-38750 - OSV-13431: Increased
version toaws-java-sdkto address1.12.797.CVE-2025-58057 - OSV-12763: Upgraded
toio.airlift:aircompressorto address2.0.3.CVE-2025-67721 - OSV-12761: Added
injetty-serverwith a non-vulnerable version to addressresolutionStrategy.CVE-2024-13009 - OSV-12760: Upgraded
fromjackson-coreto2.14.3and Jetty from2.15.0to9.4.45to address9.4.57.CVE-2025-52999
Trino
- ODP-6128: Updated
version totcnative.2.0.75.Final - ODP-6128: Bumped
version tocommons-text.1.13.1 - ODP-6128: Bumped
tocommons-lang3and Elasticsearch to3.18.0.7.17.29 - ODP-6128: Bumped
tocommons-textin1.13.1trino-ranger
Zookeeper
- OSV-13144: Bumped
tologback-coreto address CVEs.1.3.16 - ODP-6200 | GHSA-72hv-8253-57qq: Upgraded Jackson to
.2.18.6 - ODP-6583 | ZOOKEEPER-5017: Bumped Netty to
.4.1.132.Final

Have a suggestion?