The GitHub Actions job "Build" on jackrabbit-oak.git/oak-netty-4.1.137-trunk-cve-2026-75595-granite-74049 has failed. Run started by GitHub user surajmall (triggered by rishabhdaim).
Head commit for run: 71f67b2f3f018be8edb8a06af3e887f0c450ee66 / Suraj Kumar Mall <[email protected]> OAK: bump netty to 4.1.137.Final (CVE-2026-75595) [GRANITE-74049] Netty <= 4.1.136.Final is affected by CVE-2026-75595 (GHSA-c4c3-7fpv-j4q5): SslClientHelloHandler#decode reads the wrong offset before reading the TLS handshake header, so a ClientHello spanning records can select the default SslContext instead of the SNI-specific one, bypassing per-SNI mutual TLS. Fixed in netty 4.1.137.Final. trunk was on 4.1.136.Final. netty is embedded in oak-segment-tar (used for cold-standby). Report URL: https://github.com/apache/jackrabbit-oak/actions/runs/35850194505 With regards, GitHub Actions via GitBox
