Fixed CVEs
This release resolves 895 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.2.3.6-2 to 3.2.3.7-2.
Detailed List of CVEs Addressed
For detailed information about CVEs addressed in this release, see ODP 3.2.3.7-2 Acceldata Open-Source Data Platform CVE Fixes.
Summary of CVEs by component and severity level
You can see the summary of CVEs addressed by components and severity level.
CVE Fix Descriptions
Ambari
OSV-17061: Upgraded hadoop-shaded-guava.
OSV-16794 | 16780: Prevented old versions of Guava from being pulled in.
OSV-16922: Upgraded the PostgreSQL driver to 42.7.11.
OSV-17066 | 17019 | 17017 | 17076: Updated Spring to 5.3.34 and Spring Security to 5.8.16.
OSV-17024 | 17025: Pinned snappy-java to 1.1.10.4.
OSV-16928 | 12929 | 16931 | 16932: Updated mina-core.
OSV-16786 | 16787: Bumped jackson-databind to 2.16.1 in Ambari Infra Solr.
OSV-16812: Updated Derby to 10.14.3.0.
OSV-17055 | 17053 | 16933 | 16924: Updated Netty to 4.1.42.Final.
OSV-16924: Updated Netty and rebuilt
fast-hdfs-resource.jar.OSV-16837: Bumped Netty to 4.1.133.Final for Ambari Infra.
OSV-16803: Upgraded aws-java-sdk-core to 1.12.797.
OSV-16973 | 16974 | 16975 | 16976 | 16977 | 16978: Fixed Log4j CVEs.
OSV-16058: Bumped Netty to 4.1.132.Final.
Hadoop
ODP-7103: Bumped moment.js to 2.29.4 in Hadoop to fix CVE-2022-24785 and CVE-2022-31129.
OSV-19087 | ODP-2625 | HADOOP-19237 | HADOOP-17317: Upgraded to dnsjava 3.6.0 to resolve CVE-2024-25638.
OSV-19068: Bumped okio to 1.17.6 to fix CVE-2023-3635.
OSV-19046: Bumped Netty 4 to 4.1.135.Final to fix CVE-2026-44248.
OSV-19052: Bumped Bouncy Castle to 1.84 to fix CVE-2026-558.
OSV-19052: Bumped Netty 4 to 4.1.133.Final to fix CVE-2026-42587.
OSV-19052: Bumped Jackson 2 to 2.18.6 to fix GHSA-72hv-8253-57qq.
OSV-19052: Bumped commons-configuration2 to 2.15.0 to fix CVE-2026-45205.
Airflow
OSV-20101 | 20102: Bumped gunicorn from 21.2.0 to 23.0.0 (CVE-2024-1135, CVE-2024-6827).
OSV-20018 | 20019 | 20020: Bumped Jinja2 from 3.1.3 to 3.1.6 (CVE-2024-56326, CVE-2024-56201, CVE-2025-27516).
OSV-20028 | 20029 | 20030: Bumped GitPython from 3.1.41 to 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w).
OSV-19986 | 19989: Bumped aiohttp from 3.9.1 to 3.10.11 (CVE-2024-23334, CVE-2024-30251).
OSV-19968 | 19969: Bumped cryptography from 41.0.7 to 43.0.3 (CVE-2023-50782, CVE-2024-26130).
OSV-20094 | 20033: Bumped eventlet from 0.34.3 to 0.38.2 and dnspython from 2.4.2 to 2.6.1 (CVE-2023-29483).
OSV-20080: Bumped protobuf from 4.25.2 to 4.25.8 (CVE-2025-4565).
OSV-20015: Bumped certifi from 2023.11.17 to 2024.7.4 (CVE-2024-39689).
OSV-20083: Bumped Mako from 1.3.0 to 1.3.12 (CVE-2026-44307).
OSV-20046: Bumped sqlparse from 0.4.4 to 0.5.0 (CVE-2024-4340).
OSV-20027: Bumped virtualenv from 20.25.0 to 20.26.6 (CVE-2024-53899).
OSV-20037: Bumped Authlib from 1.3.0 to 1.3.2 (CVE-2024-37568).
OSV-20071: Bumped snowflake-connector-python from 3.6.0 to 3.13.1 (CVE-2025-24793).
OSV-20044: Bumped redshift-connector from 2.0.918 to 2.1.7 (CVE-2025-5279).
OSV-20119: Bumped Flask-AppBuilder from 4.3.10 to 4.3.11 (CVE-2024-25128).
OSV-19968 | 19969 | 20022: Fixed the resolver conflict introduced by cryptography 43.0.3 and bumped the Google stack along with httpx, httpcore, and h11 (CVE-2025-43859).
OSV-20062: Backported
example_xcomhardening from apache/airflow#63200 (CVE-2025-54550).OSV-20051: Disabled Jinja rendering of DAG
doc_md(CVE-2024-39877).OSV-20056: Loaded
airflow_local_settingsbefore adding the DAGs folder tosys.path(CVE-2024-45034).OSV-20055: Masked sensitive config values in logs (CVE-2024-45784).
OSV-20058: Added a distinct MENU permission check in the auth manager (CVE-2024-28746).
Fixed missing web UI assets in the from-source tarball build.
OSV-20028-2 | 20029-2 | 20030-2: Bumped the GitPython build dependency from 3.1.42 to 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w).
OSV-19972: Rejected semicolons in
CopyFromExternalStageToSnowflakeOperatortable and stage names (CVE-2025-50213).OSV-20009: Replaced pickle with JSON serialization for HTTP trigger responses (CVE-2025-69219).
Bumped beautifulsoup4 from 4.12.2 to 4.13.5 to satisfy redshift-connector 2.1.14.
Cruise Control
OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.
Cruise Control3
OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.
Druid
OSV-18025: Increased aircompressor to 2.0.3 to fix the Druid aircompressor CVEs.
OSV-18043: Increased the PostgreSQL version to fix the Druid PostgreSQL CVEs.
OSV-17943: Pinned woodstox-core to 6.5.1 to fix the Druid woodstox-core CVEs.
OSV-17940: Increased azure-sdk-bom to 1.2.25 (azure-identity 1.13.0) to fix the Druid azure-identity CVEs.
OSV-18047: Increased plexus-utils to 3.6.1 to fix the Druid plexus-utils CVEs.
OSV-17957: Increased jose4j to 0.9.6 to fix the Druid jose4j CVEs.
OSV-18024: Increased the json-path version to fix the Druid json-path CVEs.
OSV-18042: Increased the Netty version to fix the Druid Netty CVEs.
OSV-18048: Increased the Log4j 2 version to fix the Druid Log4j CVEs.
OSV-17937: Pinned jackson-databind to 2.12.7.1 to fix the Druid jackson-databind CVEs.
Flink
OSV-18068: Increased the Log4j 2 version to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.
HBase
CVE-2023-2976: Bumped Curator to 5.7.1 to fix the shaded Guava vulnerability.
OSV-18177: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
OSV-18087: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34480.
OSV-18166: Updated dnsjava to 3.6.0 in the supplemental XML to reflect the version pulled from Hadoop.
OSV-18095 | HBASE-30028: Bumped
io.opentelemetry.javaagent:opentelemetry-javaagent.OSV-19098: Upgraded to hbase-thirdparty 4.1.13.
OSV-19098: Bumped OpenTelemetry to 1.62.0 to fix CVE-2026-45292.
Hive
OSV-17463: Upgraded Bouncy Castle and commons-compress to match Hadoop.
OSV-17526: Upgraded the PostgreSQL driver to 42.7.11 to fix CVE-2026-42198.
OSV-17489: Upgraded json-path to 2.10.0 to fix CVE-2024-57699.
OSV-17489: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
OSV-17489: Upgraded Log4j 2 to 2.25.4 to fix CVE-2026-34479.
OSV-17378: Upgraded Netty to 4.1.135.Final.
Hue
OSV-17161: Upgraded Pygments from 2.0.2 to 2.5.2 (CVE-2015-8557).
OSV-17209: Removed the duplicate urllib3 1.26.12 (CVE-2023-43804).
OSV-17175: Upgraded python-rsa from 4.0 to 4.5 (CVE-2020-13757).
OSV-17218: Updated the certifi bundle to 2023.07.22 (CVE-2023-37920).
Impala
OSV-19104: Pinned opentelemetry-api to 1.62.0 to fix the Impala OpenTelemetry CVEs.
OSV-19233: Pinned commons-io to 2.14.0 to fix the Impala commons-io CVEs.
OSV-19206: Pinned okio to 1.17.6 to fix the Impala okio CVEs.
OSV-19139: Increased commons-configuration2 to 2.15.0 to fix the Impala commons-configuration2 CVEs.
OSV-19188: Increased the PostgreSQL JDBC version to 42.7.11 to fix the Impala PostgreSQL CVEs.
OSV-19228: Increased Log4j 2 to 2.25.4 to fix the Impala Log4j 2 CVEs.
OSV-19138: Increased Jackson to 2.18.6 to fix the Impala Jackson CVEs.
OSV-19108: Increased Netty to 4.1.133.Final (netty-bom) to fix the Impala Netty CVEs.
JupyterHub
OSV-20622: Bumped h11 to 0.16.0 and httpcore to 1.0.9 (CVE-2025-43859).
OSV-20579: Bumped Mako to 1.3.12 (CVE-2026-44307).
OSV-20613: Bumped mistune to 3.2.1 (CVE-2026-33079).
OSV-20626: Bumped jupyter_core to 5.8.1 (CVE-2025-30167).
Bumped Tornado to 6.4.2 (CVE-2024-52804).
Kafka
OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
KAFKA-19336: Upgraded Jackson to 2.19.0.
Kafka3
OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
KAFKA-19336: Upgraded Jackson to 2.19.0.
Knox
OSV-17552: Removed the duplicate Jackson version property and upgraded Jackson to 2.18.6 to resolve GHSA-72hv-8253-57qq.
OSV-17549: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
OSV-17544: Upgraded nimbus-jose-jwt to 9.37.4 to fix CVE-2025-53864.
OSV-17548: Upgraded commons-io to 2.14.0 and forbiddenapis to 3.6 to fix CVE-2024-47554.
OSV-17545: Bumped jakarta.mail from 1.6.5 to 1.6.8 to address CVE-2025-7962.
OSV-17542 | 17541 | 17540 | 17539 | 17538: Bumped Apache Log4j to 2.25.4 to fix CVE-2026-34479, CVE-2026-34477, CVE-2026-34480, CVE-2026-34481, and CVE-2025-68161.
OSV-17543: Upgraded PostgreSQL to 42.7.11 to fix CVE-2026-42198.
OSV-17640: Upgraded
spring.versionto 5.3.39 to resolve CVE-2024-38808.OSV-17559: Upgraded spring-vault-core to 2.3.3 to fix CVE-2023-20859.
OSV-17633 | 17632 | 17631 | 17566: Bumped Apache Shiro to 1.13.0 to address CVE-2023-46749, CVE-2023-46750, and CVE-2026-23903.
OSV-17570: Upgraded mina-core to 2.0.28 to fix CVE-2026-41409.
OSV-17573: Bumped
org.apache.santuario:xmlsecfrom 2.1.8 to 2.2.6 to fix CVE-2023-44483.KNOX-3307: Upgraded jackson-core to 2.18.6.
Bumped
org.apache.commons:commons-configuration2from 2.10.1 to 2.15.0.KNOX-3059: Upgraded commons-configuration2 to 2.10.1.
OSV-17565: Bumped
org.apache.commons:commons-lang3from 3.11.0 to 3.18.0 to fix CVE-2025-48924.OSV-17634 | 17635: Upgraded commons-compress from 1.21 to 1.26.0 to fix CVE-2024-26308 and CVE-2024-25710.
OSV-17638 | 17637 | 17564 | 17563 | 17562 | 17561 | 17560: Upgraded Bouncy Castle to jdk18on 1.84 to address multiple CVEs.
OSV-17559: Pinned amqp-client to 5.18.0 to fix CVE-2023-46120.
Kudu
OSV-17691: Upgraded Log4j to 2.25.4.
OSV-17512: Upgraded Netty to 4.1.135.Final to fix CVE-2026-42583.
NiFi / NiFi Registry
OSV-17883: Excluded commons-beanutils to resolve the reported CVEs.
ODP-6966: Used
${odp.release.version}for nifi-standard-shared-bom parent references.OSV-17902 | 17890 | 17888 | 17884: Bumped io.netty to 4.1.135.Final.
Oozie
OSV-18618: Backported OOZIE-3655 to upgrade jdom to jdom2 2.0.6.1 and fix CVE-2021-33813.
OSV-18467: Removed the pig module from the Oozie sharelib to exclude Pig package CVEs.
OSV-18465 | 18464 | 18463 | 18462 | 18461: Excluded the unwanted Jetty runner to address critical mina-core CVEs.
OSV-18622: Fixed CVE-2026-27727 from the transitive dependency mchange-commons-java.
OSV-18611: Fixed CVE-2026-27830 from the transitive dependency c3p0.
OSV-18679: Fixed CVE-2020-10683 from the transitive dependency dom4j 1.6.1.
Ozone
ODP-7371: Upgraded commons-configuration2 to 2.15.0 to match the version in the stack.
OSV-18758: Bumped
grpc.protobuf-compile.versionto 3.25.5.OSV-18712: Bumped Log4j 2 to 2.25.4.
Phoenix
Upgraded commons-beanutils to 1.11.0 to fix CVE-2025-48734.
Matched the Jackson version with HBase to fix CVE-2025-52999.
OSV-20133: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.
Pinot
OSV-18866: Increased the Netty version to fix CVE-2026-42579.
OSV-18862: Increased the Log4j 2 version to fix CVE-2026-34479.
OSV-18787: Increased the commons-lang3 version to fix CVE-2025-48924.
OSV-18772: Increased the commons-configuration2 version to fix CVE-2026-45205.
OSV-18793: Increased the nimbus-jose-jwt version to fix CVE-2025-53864.
OSV-18858: Increased the aircompressor version to fix CVE-2025-67721.
OSV-18860: Increased the async-http-client version to fix CVE-2026-45300.
OSV-18776: Stripped the Jackson 2.4.0 copy embedded in htrace-core4 from the pinot-orc and pinot-parquet shaded jars.
OSV-18796: Bumped Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
Ranger
OSV-19463: Upgraded netty-all to 4.1.133.Final to address CVE-2026-42587 and other CVEs.
OSV-19365: Upgraded Tomcat to 9.0.118 to mitigate CVE-2026-43515 and multiple other CVEs.
OSV-19554: Bumped hbase-thirdparty to 4.1.13 to mitigate multiple Netty CVEs.
Applied the OSV fixes on Ranger that address the HBase CVEs from 3.2.3.6-2.
OSV-19531: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
Schema Registry
OSV-20187 | OSV-20206: Bumped the PostgreSQL driver and plexus-utils.
Spark3
ODP-7140: Bumped the wildfly-openssl version in Spark 3.5.5 to fix CVE-2019-14887.
OSV-12356: Fixed CVEs from gson, okhttp, and jdom2.
OSV-19685: Increased the Jackson version (CVE unspecified).
OSV-19714: Increased the Netty version to fix CVE-2026-42587.
OSV-19741: Increased the Log4j 2 version to fix CVE-2026-34479.
OSV-19721: Increased the lz4-java version to fix CVE-2025-12183.
OSV-19743: Increased the aircompressor version to fix CVE-2025-67721.
Tez
OSV-17368: Pinned okio to 1.17.6 to fix the Tez okio CVEs.
OSV-17311: Pinned jdom2 to 2.0.6.1 to fix the Tez jdom2 CVEs.
OSV-17283: Pinned commons-configuration2 to 2.15.0 to fix the Tez commons-configuration2 CVEs.
OSV-17305: Increased async-http-client to 2.15.0 to fix the Tez async-http-client CVEs.
OSV-17290: Increased commons-io to 2.14.0 to fix the Tez commons-io CVEs.
OSV-17281: Increased Jackson to 2.18.6 to fix the Tez Jackson CVEs.
OSV-17377: Increased Netty to 4.1.133.Final (netty-bom) to fix the Tez Netty CVEs.
Trino
OSV-18944: Bumped
io.netty:netty-bomto 4.1.135.Final to fix the netty-codec, netty-codec-http, and netty-codec-http2 CVEs.OSV-18949: Bumped
io.airlift:aircompressorto 2.0.3 to fix CVE-2025-67721.OSV-18909: Bumped
org.eclipse.jettyto 12.0.33 to fix CVE-2026-2332, CVE-2026-1605, CVE-2025-11143, and CVE-2025-5115.
Zeppelin
OSV-20277: Forced bcprov-jdk18on 1.84 to fix CVE-2026-5598.
OSV-20282: Pinned plexus-utils to 3.6.1 to fix CVE-2025-67030.
OSV-20296 | OSV-20297: Bumped mina-core from 2.0.27 to 2.0.31 to fix CVE-2026-41409 and CVE-2026-41635.
OSV-20337: Bumped jsoup from 1.11.3 to 1.14.2 to fix CVE-2021-37714.
OSV-20348: Bumped Jersey from 2.30 to 2.34 to fix CVE-2021-28168.
ZooKeeper
ODP-6883: Upgraded the commons-io version in ZooKeeper to fix CVE-2024-47554.
OSV-20483 | ODP-6200: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
OSV-19624: Upgraded Bouncy Castle to 1.84 to fix CVE-2026-5588.
OSV-20478: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
OSV-19624 | ZOOKEEPER-4827: Bumped the Bouncy Castle version from 1.75 to 1.78.
OSV-19624 | ZOOKEEPER-4719: Upgraded Bouncy Castle from jdk15on to jdk18on.