Commit 70da797
Upgrade Netty to 4.1.132.Final to fix CVE-2026-33870 and CVE-2026-33871
Add Netty BOM to dependencyManagement to override the vulnerable transitive
Netty version (~4.1.115.Final) pulled in by Vert.x 4.5.21.
- CVE-2026-33870: HTTP request smuggling via chunked extension parsing (CVSS 7.5)
- CVE-2026-33871: HTTP/2 DoS via CONTINUATION frame flood (CVSS 8.7)
See: UID2-6837
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 2d812a9 commit 70da797
1 file changed
Lines changed: 8 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| |||
36 | 37 | | |
37 | 38 | | |
38 | 39 | | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
39 | 47 | | |
40 | 48 | | |
41 | 49 | | |
| |||
0 commit comments