Skip to content

[fix][sec] Upgrade Jetty to address CVE-2026-5795#25532

Merged
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-jetty-12.1.8
Apr 15, 2026
Merged

[fix][sec] Upgrade Jetty to address CVE-2026-5795#25532
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-jetty-12.1.8

Conversation

@lhotari
Copy link
Copy Markdown
Member

@lhotari lhotari commented Apr 15, 2026

Motivation

There's yet another recent CVE in Jetty, CVE-2026-5795.

Modifications

Upgrade Jetty to 12.1.8

Additional details

Jetty project doesn't support 9.4.x any more. The fixed version 9.4.61 is released only for paying customers. The same applies for the fix for CVE-2026-2332.

@lhotari lhotari added this to the 4.3.0 milestone Apr 15, 2026
@lhotari lhotari requested a review from merlimat April 15, 2026 16:34
@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Apr 15, 2026

Fix for 9.4.x is only available for paying customers. More details at #25527 (comment) . @merlimat We'll have some trouble with Pulsar 4.0.x. Perhaps we should migrate to Jetty 12 also on 4.0 LTS?

@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Apr 15, 2026

Fix for 9.4.x is only available for paying customers. More details at #25527 (comment) . @merlimat We'll have some trouble with Pulsar 4.0.x. Perhaps we should migrate to Jetty 12 also on 4.0 LTS?

@merlimat I'll give this a try with Claude Code.

@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Apr 15, 2026

The Jetty 12 backport for branch-4.0 is #25534

@lhotari lhotari merged commit e05c212 into apache:master Apr 15, 2026
43 checks passed
lhotari added a commit that referenced this pull request Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants