Bump Optimize jetty to 12.0.39 to resolve CVE-2026-19203
envgap__camunda__camunda-62672
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
34c3925ad54a8391c01d814a450a9b9da3ce81a8- Manifest
optimize/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
camunda/camunda #62672 · read the original issue
### <!-- Component --> <!-- Optimize- --> ### <!-- Affected version --> <!-- -8.7 --> ### CVE Number - CVE-2026-19203 - CVE-2026-19204 (not affected) ### CVE Registry URL - https://nvd.nist.gov/vuln/detail/CVE-2026-19203 - https://nvd.nist.gov/vuln/detail/CVE-2026-19204 (not affected) ### Description Bumps Optimize Jetty to 12.0.39 to address: - CVE-2026-19203: HTTP request smuggling in chunked request parsing - CVE-2026-19204: Denial of Service via large WebSocket payload with unknown opcode
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]