The GitHub Actions job "Build" on 
jackrabbit-oak.git/oak-netty-4.1.137-1.22-cve-2026-75595-granite-74049 has 
failed.
Run started by GitHub user surajmall (triggered by surajmall).

Head commit for run:
5ea8158389955d9d468fb2fceefed5e6dc20d4ad / Suraj Kumar Mall 
<[email protected]>
OAK: bump netty to 4.1.137.Final (CVE-2026-75595) [GRANITE-74049]

Backport to 1.22. Netty <= 4.1.136.Final is affected by CVE-2026-75595
(GHSA-c4c3-7fpv-j4q5): SslClientHelloHandler#decode reads the wrong
offset and can select the default SslContext instead of the SNI-specific
one, bypassing per-SNI mutual TLS. Fixed in netty 4.1.137.Final.
netty is embedded in oak-segment-tar, shipped by AEM 6.5 in
launchpad/felix as netty-handler-4.1.13x.Final.jar.

Report URL: https://github.com/apache/jackrabbit-oak/actions/runs/35850203050

With regards,
GitHub Actions via GitBox

Reply via email to