Security Update: Address high/critical CVEs in dependencies
- Dominant language
- Java
- Stars
- 9.5k
- Forks
- 2.3k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 5
Description
Hi team,
In addition to the open [PR](https://github.com/apache/jmeter/pull/6701), our vulnerability reports the following CVEs in the dependency tree
| CVE | Package | Component Type | Severity | Version |
|---|---|---|---|---|
| CVE-2025-24970 | io.netty:netty-handler | Java Code Library | High | 4.1.118.Final |
| CVE-2026-44249 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-45416 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-50010 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-42583 | io.netty:netty-codec | Java Code Library | High | 4.1.133.Final |
Could we look into updating these to the patched versions?
@vlsi please consider updating these dependencies in your open PR.
Contributor guide
Research direction
Start by reviewing the dependency changes in open PR #6701 and the project's dependency tree. Confirm that io.netty:netty-handler and io.netty:netty-codec resolve to versions containing fixes for all listed CVEs; done means the vulnerability reports no longer flag these dependencies.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100