Skip to content

Override Netty version to address 2026 CVEs#186

Merged
murillio4 merged 2 commits into
mainfrom
fix/netty-cves-2026
May 9, 2026
Merged

Override Netty version to address 2026 CVEs#186
murillio4 merged 2 commits into
mainfrom
fix/netty-cves-2026

Conversation

@murillio4

Copy link
Copy Markdown
Contributor

Overrides Netty with the io.netty:netty-bom at 4.1.133.Final to address current 2026 Netty CVEs affecting transitive dependencies pulled in by Fabric8 and Java Operator SDK.

The latest available io.fabric8 and io.javaoperatorsdk versions in this repo still resolve vulnerable transitive Netty modules, including io.netty:netty-codec-http2:4.1.130.Final.

This override updates the resolved Netty version to 4.1.133.Final, which covers the currently relevant disclosed issues, including:

  • CVE-2026-33870
  • CVE-2026-33871
  • CVE-2026-42579
  • CVE-2026-42583
  • CVE-2026-42584
  • CVE-2026-42587

@murillio4 murillio4 merged commit af0d482 into main May 9, 2026
9 checks passed
@murillio4 murillio4 deleted the fix/netty-cves-2026 branch May 9, 2026 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant