Skip to content

USPR-13904: bump io.netty to 4.2.17.Final to resolve GHSA-8c42-7qj2-3j46 - #403

Draft
midnight-clue[bot] wants to merge 1 commit into
mainfrom
USPR-13904-bump-netty-4-2-17-clue
Draft

USPR-13904: bump io.netty to 4.2.17.Final to resolve GHSA-8c42-7qj2-3j46#403
midnight-clue[bot] wants to merge 1 commit into
mainfrom
USPR-13904-bump-netty-4-2-17-clue

Conversation

@midnight-clue

@midnight-clue midnight-clue Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Context & Problem

USPR-13904: GitHub Dependabot alert #134 on openapi-validation-java flags io.netty:netty-codec-http versions >= 4.2.0.Final and <= 4.2.16.Final as vulnerable to cache poisoning and information disclosure via CORS Vary header overwrite (GHSA-8c42-7qj2-3j46), fixed in 4.2.17.Final.

Solution

Updated the io.netty resolutionStrategy.eachDependency block in build.gradle to force io.netty group dependencies with version < '4.2.17.Final' to useVersion('4.2.17.Final'), and updated the because() comment to reference GHSA-8c42-7qj2-3j46 alongside existing CVE references.

Also updated the example subproject netty version overrides to 4.2.17.Final for consistency.

Verification

  • io.netty:netty-codec-http resolves to 4.2.17.Final (verified via ./gradlew :examples:example-spring-boot-starter-webflux:dependencyInsight --dependency netty-codec-http)
  • Checkstyle passes (./gradlew checkstyleMain checkstyleTest)
  • PMD passes (./gradlew pmdMain pmdTest)
  • Unit tests pass (./gradlew test)

🔍 Braintrust trace

Bump io.netty group dependency version constraint from 4.2.16.Final to 4.2.17.Final
in the resolutionStrategy to resolve the CORS Vary header overwrite vulnerability
(GHSA-8c42-7qj2-3j46) in io.netty:netty-codec-http, fixed in 4.2.17.Final.

Also update the accompanying  clause to document this new CVE alongside
existing Netty vulnerability references.

Updates both the root build.gradle resolutionStrategy and the example subproject
netty version overrides.

Co-Authored-By: Ronald van Duren <ronald.vanduren@getyourguide.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants