We need to update Vert.x to version 5.0.4 in order to upgrade the following transitive dependencies and address known CVEs affecting them:
| Dependency |
CVE ID |
Description |
| netty-codec-http2 |
CVE-2025-55163 |
Vulnerability in HTTP/2 codec leading to potential denial of service / crash |
| Thymeleaf |
CVE-2023-38286 |
Sandbox bypass via crafted HTML templates allowing malicious code execution |