The GitHub Actions job "Build" on jackrabbit-oak.git/oak-netty-4.1.137-1.22-cve-2026-75595-granite-74049 has failed. Run started by GitHub user surajmall (triggered by surajmall).
Head commit for run: 5ea8158389955d9d468fb2fceefed5e6dc20d4ad / Suraj Kumar Mall <[email protected]> OAK: bump netty to 4.1.137.Final (CVE-2026-75595) [GRANITE-74049] Backport to 1.22. Netty <= 4.1.136.Final is affected by CVE-2026-75595 (GHSA-c4c3-7fpv-j4q5): SslClientHelloHandler#decode reads the wrong offset and can select the default SslContext instead of the SNI-specific one, bypassing per-SNI mutual TLS. Fixed in netty 4.1.137.Final. netty is embedded in oak-segment-tar, shipped by AEM 6.5 in launchpad/felix as netty-handler-4.1.13x.Final.jar. Report URL: https://github.com/apache/jackrabbit-oak/actions/runs/35850203050 With regards, GitHub Actions via GitBox
