Skip to content

OKAPI-1244: Vertx 4.5.27, log4j 2.26.0 fixing vulns (Sunflower)#1444

Merged
julianladisch merged 2 commits into
b6.2from
OKAPI-1244
May 21, 2026
Merged

OKAPI-1244: Vertx 4.5.27, log4j 2.26.0 fixing vulns (Sunflower)#1444
julianladisch merged 2 commits into
b6.2from
OKAPI-1244

Conversation

@julianladisch
Copy link
Copy Markdown
Contributor

https://folio-org.atlassian.net/browse/OKAPI-1244

For Sunflower branch b6.2:

Bump Vert.x from 4.5.23 to 4.5.27 fixing multiple vulnerabilities:

Bump log4j from 2.24.3 to 2.26.0 fixing a vulnerability in Okapi’s JSON logging:

https://folio-org.atlassian.net/browse/OKAPI-1244

For Sunflower branch b6.2:

Bump Vert.x from 4.5.23 to 4.5.27 fixing multiple vulnerabilities:

* CVE-2026-33871 GHSA-w9fj-cfpg-grvv  – Netty HTTP/2 CONTINUATION Frame Flood DoS
* CVE-2026-42583 GHSA-mj4r-2hfc-f8p6  – Netty Lz4FrameDecoder
* CVE-2026-42587 GHSA-f6hv-jmp6-3vwv  – Netty decompression bomb (br, zstd, or snappy)

Bump log4j from 2.24.3 to 2.26.0 fixing a vulnerability in Okapi’s JSON logging:

* CVE-2026-34481 GHSA-w35j-pv5h-q9q9 – MapMessage/JsonTemplateLayout
@julianladisch julianladisch requested a review from a team May 19, 2026 19:05
@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
2 Security Hotspots
B Reliability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@julianladisch julianladisch merged commit 7b12394 into b6.2 May 21, 2026
5 of 6 checks passed
@julianladisch julianladisch deleted the OKAPI-1244 branch May 21, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants