Visitar URL original
project-reactor-bom 2025.0.7, reactor-core 3.8.7 by julianladisch · Pull Request #2050 · mongodb/mongo-java-driver · GitHub
Skip to content

project-reactor-bom 2025.0.7, reactor-core 3.8.7 - #2050

Open
julianladisch wants to merge 3 commits into
mongodb:mainfrom
julianladisch:project-reactor-bom-2025-0-7
Open

julianladisch wants to merge 3 commits into
mongodb:mainfrom
julianladisch:project-reactor-bom-2025-0-7

Conversation

@julianladisch

Copy link
Copy Markdown

Bump project-reactor-bom from 2022.0.0 to 2025.0.7. This transitively bumps io.projectreactor:reactor-core from 3.5.0 to 3.8.7 fixing CVE-2026-47863

Bump project-reactor-bom from 2022.0.0 to 2025.0.7.
This transitively bumps io.projectreactor:reactor-core from 3.5.0 to 3.8.7 fixing CVE-2026-47863
@julianladisch
julianladisch requested a review from a team as a code owner September 8, 2026 15:51
@Donnerbart

Copy link
Copy Markdown

This fixes CVE-2026-47857 and the already mentioned CVE-2026-47863, both flagged as HIGH by common security scanners (which puts a lot of pressure on users of this library, due to short SLAs).

@stIncMale Would you be so kind to look into this? Thanks a lot!

@Donnerbart

Copy link
Copy Markdown

We are weighing a local dependency constraint to pull reactor-core forward until this
PR lands, so we tested the bump against the driver's reactive test suites to see whether
the newer reactor changes driver behavior. The Evergreen patch on this PR has not been
scheduled yet, so these are local results.

Setup: main (5.13.0-SNAPSHOT) with this PR's single catalog change applied, so
io.projectreactor:reactor-core resolves to 3.8.7. Each server ran as a single node
replica set in Docker with enableTestCommands=1.

:driver-reactive-streams:test

server reactor-core tests failed skipped
8.0.32 3.5.0 (baseline) 3569 23 1278
8.0.32 3.8.7 3569 23 1278
7.0.43 3.5.0 (baseline) 3571 46 1415
7.0.43 3.8.7 3571 46 1415
6.0.28 3.8.7 3571 22 1461
5.0.33 3.8.7 3571 9 1510

On both 8.0 and 7.0 the bump and baseline failure sets are identical, test for test. The
6.0 and 5.0 sets are subsets of the 7.0 one. All failures are gaps in our local
environment rather than driver behavior: CSFLE and queryable encryption prose tests (no
mongocryptd or KMS), Atlas search index commands, multi-member replica set behavior, and
one DNS SRV test.

:driver-reactive-streams:tckTest, which is registered standalone and not wired into
check, so it needs an explicit invocation:

server tests failed skipped
8.0.32 494 0 177
7.0.43 494 0 177
6.0.28 494 0 177
5.0.33 494 0 177

Two notes on the artifact itself: reactor-core 3.8.7 keeps the Java 8 baseline (class
file major version 52, OSGi Require-Capability: osgi.ee=JavaSE version=1.8), and it
adds one transitive compile dependency, org.jspecify:jspecify:1.0.0.

Feel free to ignore this if it is not useful. I can share logs or rerun with different
settings if that would help.

@strogiyotec

Copy link
Copy Markdown
Collaborator

hi @Donnerbart and @julianladisch we added this ticket to our queue for this sprint

@strogiyotec

Copy link
Copy Markdown
Collaborator

I scheduled the evergeen patch , meanwhile mongo-java-driver doesn't use the reactor API that is exposed to the CVE id, we are looking at the performance implication from upgrading the dependency, will share the update shortly

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants