Skip to content

OKAPI-1256: Sunflower: Vertx 4.5.32, Netty 4.1.137 fixing vulns - #1464

Open
julianladisch wants to merge 1 commit into
b6.2from
OKAPI-1256
Open

OKAPI-1256: Sunflower: Vertx 4.5.32, Netty 4.1.137 fixing vulns#1464
julianladisch wants to merge 1 commit into
b6.2from
OKAPI-1256

Conversation

@julianladisch

Copy link
Copy Markdown
Contributor

https://folio-org.atlassian.net/browse/OKAPI-1256

Bump Vert.x from 4.5.30 to 4.5.32:

The Vert.x bump transitively bumps Netty from 4.1.136.Final to 4.1.137.Final fixing multiple security vulnerabilities:

https://netty.io/news/2026/08/06/4-1-137-Final.html:

https://folio-org.atlassian.net/browse/OKAPI-1256

Bump Vert.x from 4.5.30 to 4.5.32:

* https://github.com/vert-x3/wiki/wiki/4.5.31-Release-Notes
* https://github.com/vert-x3/wiki/wiki/4.5.32-Release-Notes

The Vert.x bump transitively bumps Netty from 4.1.136.Final to 4.1.137.Final fixing multiple security vulnerabilities:

https://netty.io/news/2026/08/06/4-1-137-Final.html:

* [CVE-2026-XXXXX](GHSA-fccg-mwvh-qqg4) : algorithm inefficiency in io.netty:netty-handler
* [CVE-2026-XXXXX](GHSA-cc6x-ffm5-83wf) : improper NUL byte neutrolization in io.netty:netty-codec-socks
* [CVE-2026-XXXXX](GHSA-c4c3-7fpv-j4q5) : SNI bypass in io.netty:netty-handler
* [CVE-2026-59902](GHSA-2qj4-mmr9-4v2f) : memory exhaustion in io.netty:netty-transport-sctp
* [CVE-2026-59903](GHSA-8c42-7qj2-3j46) : cache poisoning & info disclosure in io.netty:netty-codec-http
* [CVE-2026-XXXXX](GHSA-43fm-7cxg-hf3j) : validation bypass in io.netty:netty-codec-mqtt
* [CVE-2026-XXXXX](GHSA-p85m-gvr3-788c) : improper hostname verification in io.netty:netty-handler
@julianladisch
julianladisch requested a review from a team August 18, 2026 10:18
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants