Skip to content

HADOOP-19761 Upgrade http2-common to 9.4.58.v20250814 due to CVE-2025-5115#8146

Merged
steveloughran merged 1 commit intoapache:trunkfrom
fuchaohong:HADOOP-19761
Dec 29, 2025
Merged

HADOOP-19761 Upgrade http2-common to 9.4.58.v20250814 due to CVE-2025-5115#8146
steveloughran merged 1 commit intoapache:trunkfrom
fuchaohong:HADOOP-19761

Conversation

@fuchaohong
Copy link
Contributor

Upgrade http2-common to 9.4.58.v20250814 due to CVE-2025-5115

Copy link
Contributor

@steveloughran steveloughran left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

build failures were HDFS test flakiness.

I see the http2 components are not in LICENSE-binary; audited a recent (local) release build off trunk and don't see them.

approving.

@steveloughran steveloughran merged commit 48448e5 into apache:trunk Dec 29, 2025
1 of 2 checks passed
steveloughran pushed a commit that referenced this pull request Dec 31, 2025
…endencies (#8150)

Fixes regression caused by  #8146 

Contributed by Chris Nauroth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants