Upgrade Netty to latest to address multiple CVEs
envgap__redis__lettuce-3888
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
ae9627f4287f5c2e01cc6eae8c23c3d96397a347- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
redis/lettuce #3888 · read the original issue
Please consider upgrading Netty to the latest version as part of your next release to address the following CVEs in the transitive Netty dependency: - CVE-2026-45674 (Fixed in 4.2.15.Final) - CVE-2026-44249 (Fixed in 4.2.15.Final) - CVE-2026-45416 (Fixed in 4.2.15.Final) - CVE-2026-47691 (Fixed in 4.2.15.Final) - CVE-2026-50010 (Fixed in 4.2.15.Final) - CVE-2026-73508 (Fixed in 4.2.16.Final) - CVE-2026-45536 (Fixed in 4.2.15.Final) - CVE-2026-45673 (Fixed in 4.2.15.Final)
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]