Browse Source
Bump netty from 4.1.135.Final to 4.1.136.Final to fix CVE-2026-44891, CVE-2026-55831, and 11 others
pull/16039/head
Viacheslav Klimov
2 weeks ago
Failed to extract signature
1 changed files with
1 additions and
1 deletions
-
pom.xml
|
|
|
@ -70,7 +70,7 @@ |
|
|
|
entries below once TB migrates its tests off the deprecated @SpyBean/@MockBean to @MockitoSpyBean/@MockitoBean. --> |
|
|
|
<spring-boot-test.version>3.5.13</spring-boot-test.version> |
|
|
|
<commons-lang3.version>3.18.0</commons-lang3.version> <!-- to fix CVE-2025-48924. TODO: remove when fixed in spring-boot-dependencies --> |
|
|
|
<netty.version>4.1.135.Final</netty.version> <!-- to fix CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-45416, CVE-2026-45674, CVE-2026-46340, CVE-2026-47691, CVE-2026-48006, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011 (supersedes earlier netty CVE pins; also retains the 4.1.134 MQTT decoder regression fix). TODO: remove when fixed in spring-boot-dependencies --> |
|
|
|
<netty.version>4.1.136.Final</netty.version> <!-- to fix CVE-2026-44891, CVE-2026-55831, CVE-2026-55833, CVE-2026-55851, CVE-2026-56745, CVE-2026-56817, CVE-2026-56819, CVE-2026-56820, CVE-2026-56821, CVE-2026-56822, CVE-2026-59901, CVE-2026-59920, CVE-2026-73507 (supersedes earlier netty CVE pins; also retains the 4.1.134 MQTT decoder regression fix). TODO: remove when fixed in spring-boot-dependencies --> |
|
|
|
<javax.xml.bind-api.version>2.4.0-b180830.0359</javax.xml.bind-api.version> |
|
|
|
<jjwt.version>0.12.5</jjwt.version> |
|
|
|
<rat.version>0.10</rat.version> <!-- unused --> |
|
|
|
|