Upgrade reactor-core to latest (3.8.7)
envgap__redis__lettuce-3904
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
6da95df0603878a1986e861a6dcd18b291fd9ee7- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
redis/lettuce #3904 · read the original issue
There have recently been a few CVEs published for reactor, e.g.: https://spring.io/security/cve-2026-47863 https://spring.io/security/cve-2026-47857 Lettuce currently uses 3.6.6 (see https://github.com/redis/lettuce/blob/main/pom.xml#L73). Is it safe to use the latest release (3.8.7), which is not affected by any of these? And can we upgrade this for the next release?
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]