Repository navigation
project-reactor-bom 2025.0.7, reactor-core 3.8.7 - #2050
julianladisch wants to merge 3 commits into
Conversation
Bump project-reactor-bom from 2022.0.0 to 2025.0.7. This transitively bumps io.projectreactor:reactor-core from 3.5.0 to 3.8.7 fixing CVE-2026-47863
|
This fixes CVE-2026-47857 and the already mentioned CVE-2026-47863, both flagged as HIGH by common security scanners (which puts a lot of pressure on users of this library, due to short SLAs). @stIncMale Would you be so kind to look into this? Thanks a lot! |
|
We are weighing a local dependency constraint to pull Setup:
On both 8.0 and 7.0 the bump and baseline failure sets are identical, test for test. The
Two notes on the artifact itself: reactor-core 3.8.7 keeps the Java 8 baseline (class Feel free to ignore this if it is not useful. I can share logs or rerun with different |
|
hi @Donnerbart and @julianladisch we added this ticket to our queue for this sprint |
|
I scheduled the evergeen patch , meanwhile mongo-java-driver doesn't use the reactor API that is exposed to the CVE id, we are looking at the performance implication from upgrading the dependency, will share the update shortly |
Bump project-reactor-bom from 2022.0.0 to 2025.0.7. This transitively bumps io.projectreactor:reactor-core from 3.5.0 to 3.8.7 fixing CVE-2026-47863