← All tasks
javacamunda/camunda #62672Not a task: not reproduced

Bump Optimize jetty to 12.0.39 to resolve CVE-2026-19203

envgap__camunda__camunda-62672

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
34c3925ad54a8391c01d814a450a9b9da3ce81a8
Manifest
optimize/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

camunda/camunda #62672 · read the original issue
### <!-- Component -->

<!-- Optimize- -->

### <!-- Affected version -->

<!-- -8.7 -->

### CVE Number

- CVE-2026-19203
- CVE-2026-19204 (not affected)

### CVE Registry URL

- https://nvd.nist.gov/vuln/detail/CVE-2026-19203
- https://nvd.nist.gov/vuln/detail/CVE-2026-19204 (not affected)

### Description

Bumps Optimize Jetty to 12.0.39 to address:
- CVE-2026-19203: HTTP request smuggling in chunked request parsing
- CVE-2026-19204: Denial of Service via large WebSocket payload with unknown opcode
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]