apache / apache/jmeter

Security Update: Address high/critical CVEs in dependencies

Open
#6,714 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
9.5k
Forks
2.3k
Avg merge
1d 22h
Merged PRs (30d)
5

Description

Hi team,

In addition to the open [PR](https://github.com/apache/jmeter/pull/6701), our vulnerability reports the following CVEs in the dependency tree

| CVE | Package | Component Type | Severity | Version |
|---|---|---|---|---|
| CVE-2025-24970 | io.netty:netty-handler | Java Code Library | High | 4.1.118.Final |
| CVE-2026-44249 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-45416 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-50010 | io.netty:netty-handler | Java Code Library | High | 4.1.135.Final |
| CVE-2026-42583 | io.netty:netty-codec | Java Code Library | High | 4.1.133.Final |

Could we look into updating these to the patched versions?

@vlsi please consider updating these dependencies in your open PR.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the dependency changes in open PR #6701 and the project's dependency tree. Confirm that io.netty:netty-handler and io.netty:netty-codec resolve to versions containing fixes for all listed CVEs; done means the vulnerability reports no longer flag these dependencies.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.