surajmall opened a new pull request, #3141:
URL: https://github.com/apache/jackrabbit-oak/pull/3141

   ## What
   
   Bump `<netty.version>` in `oak-parent/pom.xml` from `4.1.136.Final` to 
`4.1.137.Final`.
   
   ## Why
   
   Netty `<= 4.1.136.Final` is affected by **CVE-2026-75595** 
(GHSA-c4c3-7fpv-j4q5, CVSS 9.1). `SslClientHelloHandler#decode` reads the wrong 
offset before parsing the TLS handshake header, so a `ClientHello` that spans 
multiple TLS records can cause the default `SslContext` to be selected instead 
of the SNI-specific one — bypassing per-SNI mutual TLS. Fixed upstream in netty 
**4.1.137.Final** / 4.2.17.Final.
   
   Netty is embedded in `oak-segment-tar` (TarMK cold-standby uses the Netty 
transport), so the property bump propagates into the shipped OSGi bundle.
   
   ## Scope
   
   Single-line property change; no source/behavior change. Follows the 
established netty-bump convention (trunk PR + a `1.22` backport PR).
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to