surajmall opened a new pull request, #3141: URL: https://github.com/apache/jackrabbit-oak/pull/3141
## What Bump `<netty.version>` in `oak-parent/pom.xml` from `4.1.136.Final` to `4.1.137.Final`. ## Why Netty `<= 4.1.136.Final` is affected by **CVE-2026-75595** (GHSA-c4c3-7fpv-j4q5, CVSS 9.1). `SslClientHelloHandler#decode` reads the wrong offset before parsing the TLS handshake header, so a `ClientHello` that spans multiple TLS records can cause the default `SslContext` to be selected instead of the SNI-specific one — bypassing per-SNI mutual TLS. Fixed upstream in netty **4.1.137.Final** / 4.2.17.Final. Netty is embedded in `oak-segment-tar` (TarMK cold-standby uses the Netty transport), so the property bump propagates into the shipped OSGi bundle. ## Scope Single-line property change; no source/behavior change. Follows the established netty-bump convention (trunk PR + a `1.22` backport PR). 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
