This maintenance release addresses security vulnerabilities across multiple dependencies, including Apache Shiro, Eclipse Jetty, Jackson, Micrometer, HttpCore5, Bouncy Castle, Reactor Core, and Log4j.
Highlights
-
Apache Shiro Major Upgrade: Remediated CVE-2026-49268 by upgrading Shiro from 2.1.0 to 3.0.0 across all modules (GEODE-10607 #8033, GEODE-10591 #8017)
-
Jetty Security Patches: Remediated CVE-2026-10050 by upgrading Jetty from 12.0.33 to 12.0.37 (GEODE-10605 #8031)
-
Jackson Security Patches: Remediated GHSA-2m67-wjpj-xhg9 and CVE-2026-19032 by upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10589 #8015, GEODE-10621 #8048)
-
Micrometer Security Patches: Remediated CVE-2026-40984 and CVE-2026-59296 by upgrading Micrometer from 1.14.0 to 1.16.7 (GEODE-10592 #8018, GEODE-10619 #8044)
-
HttpCore5 Remediation: Remediated CVE-2026-54428 by upgrading HttpCore5 and HttpCore5-H2 from 5.3.6 to 5.4.3 (GEODE-10590 #8016)
-
Bouncy Castle Remediation: Remediated CVE-2026-8763 in the bcprov-jdk18on transitive dependency, 1.84 to 1.85 (GEODE-10606 #8032)
-
Reactor Core Remediation: Remediated CVE-2026-47857 by pinning Reactor Core, a transitive dependency of spring-shell-core, from 3.6.10 to 3.8.7 (GEODE-10622 #8049)
-
Log4j Upgrade: Upgraded Log4j from 2.25.4 to 2.25.5 to address a reported advisory (GEODE-10604 #8030)
sha256 for apache-geode-2.0.3.tgz is 23dd1cbf5c6ed49909a596f0b49c0ec73f6f3c7e6fec20c07d32af3543684825
See full release notes at https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-2.0.3