From 047c15fd0f552b29f4416c9c8b528d572fb6d040 Mon Sep 17 00:00:00 2001 From: Viacheslav Klimov Date: Mon, 23 Feb 2026 11:12:21 +0200 Subject: [PATCH 1/2] Fix CVE-2026-24734 and CVE-2025-66614 --- pom.xml | 25 ++++++++++++++++++------- 1 file changed, 18 insertions(+), 7 deletions(-) diff --git a/pom.xml b/pom.xml index b69540231e..6011d37c31 100755 --- a/pom.xml +++ b/pom.xml @@ -38,7 +38,8 @@ ${project.name} /var/log/${pkg.name} /usr/share/${pkg.name} - 3.4.10 + 3.4.13 + 10.1.52 2.4.0-b180830.0359 5.1.5 0.12.5 @@ -147,7 +148,6 @@ 9.2.0 1.1.10.5 9.10.0 - 4.1.128.Final @@ -899,13 +899,24 @@ + - io.netty - netty-bom - ${netty.version} - pom - import + org.apache.tomcat.embed + tomcat-embed-core + ${tomcat.version} + + + org.apache.tomcat.embed + tomcat-embed-el + ${tomcat.version} + + + org.apache.tomcat.embed + tomcat-embed-websocket + ${tomcat.version} + + org.springframework.boot spring-boot-dependencies From 154b2d564ca07297248ec25fd8db5ea62d2f3aa0 Mon Sep 17 00:00:00 2001 From: Viacheslav Klimov Date: Mon, 23 Feb 2026 11:13:52 +0200 Subject: [PATCH 2/2] Add Security category to release changelog Co-Authored-By: Claude Opus 4.6 --- .github/release.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/release.yml b/.github/release.yml index 70852dcbb2..fe88fab0ef 100644 --- a/.github/release.yml +++ b/.github/release.yml @@ -19,6 +19,10 @@ changelog: labels: - Ignore for release categories: + - title: 'Security' + labels: + - 'Security' + - title: 'Major Core & Rule Engine' labels: - 'Major Core'