Skip to content

High severity CVEs in 1.17.1 #1714

Description

@alicejgibbons

Env: Spring boot 4.0.5
SDK: 1.17.1

✗ Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924] in com.fasterxml.jackson.core:[email protected]
introduced by io.dapr:[email protected] > com.fasterxml.jackson.core:[email protected] > com.fasterxml.jackson.core:[email protected] and 2 other path(s)
This issue was fixed in versions: 2.18.6, 2.21.1

✗ Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551] in com.fasterxml.jackson.core:[email protected]
introduced by io.dapr:[email protected] > com.fasterxml.jackson.core:[email protected] > com.fasterxml.jackson.core:[email protected] and 2 other path(s)
This issue was fixed in versions: 2.21.2

✗ HTTP Request Smuggling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-15789756] in io.netty:[email protected]
introduced by io.dapr:[email protected] > io.grpc:[email protected] > io.netty:[email protected] > io.netty:[email protected] and 3 other path(s)
This issue was fixed in versions: 4.1.132.Final, 4.2.12.Final

Activity

  1. changed the title [-]High vulnerability CVEs[/-] [+]High vulnerability CVEs in 1.17.4[/+] on Apr 7, 2026
  2. changed the title [-]High vulnerability CVEs in 1.17.4[/-] [+]High severity CVEs in 1.17.4[/+] on Apr 7, 2026
  3. changed the title [-]High severity CVEs in 1.17.4[/-] [+]High severity CVEs in 1.17.1[/+] on Apr 7, 2026
  4. self-assigned this
    on Apr 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

kind/bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions