The GitHub Actions job "Build" on 
jackrabbit-oak.git/oak-netty-4.1.137-trunk-cve-2026-75595-granite-74049 has 
failed.
Run started by GitHub user surajmall (triggered by rishabhdaim).

Head commit for run:
71f67b2f3f018be8edb8a06af3e887f0c450ee66 / Suraj Kumar Mall 
<[email protected]>
OAK: bump netty to 4.1.137.Final (CVE-2026-75595) [GRANITE-74049]

Netty <= 4.1.136.Final is affected by CVE-2026-75595 (GHSA-c4c3-7fpv-j4q5):
SslClientHelloHandler#decode reads the wrong offset before reading the
TLS handshake header, so a ClientHello spanning records can select the
default SslContext instead of the SNI-specific one, bypassing per-SNI
mutual TLS. Fixed in netty 4.1.137.Final. trunk was on 4.1.136.Final.
netty is embedded in oak-segment-tar (used for cold-standby).

Report URL: https://github.com/apache/jackrabbit-oak/actions/runs/35850194505

With regards,
GitHub Actions via GitBox

Reply via email to