This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/jena-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 768903c1c Updated site from main
(a77a5233be603cc8a71931ecc15d8190f8ba213a)
768903c1c is described below
commit 768903c1c65281cb02ecada35058c82c38e7d9a9
Author: jenkins <[email protected]>
AuthorDate: Mon Aug 3 16:10:20 2026 +0000
Updated site from main (a77a5233be603cc8a71931ecc15d8190f8ba213a)
---
content/index.json | 2 +-
content/security/advisories.html | 7 +++++++
content/sitemap.xml | 4 ++--
3 files changed, 10 insertions(+), 3 deletions(-)
diff --git a/content/index.json b/content/index.json
index 569b7943b..3524b2c76 100644
--- a/content/index.json
+++ b/content/index.json
@@ -1 +1 @@
-[{"categories":null,"contents":"This page is historical \u0026ldquo;for
information only\u0026rdquo; - there is no Apache release of Eyeball and the
code has not been updated for Jena3.\nThe original source code is available. So
you\u0026rsquo;ve got Eyeball installed and you\u0026rsquo;ve run it on one of
your files, and Eyeball doesn\u0026rsquo;t like it. You\u0026rsquo;re not sure
why, or what to do about it. Here\u0026rsquo;s what\u0026rsquo;s going
on.\nEyeball inspects your model a [...]
\ No newline at end of file
+[{"categories":null,"contents":"This page is historical \u0026ldquo;for
information only\u0026rdquo; - there is no Apache release of Eyeball and the
code has not been updated for Jena3.\nThe original source code is available. So
you\u0026rsquo;ve got Eyeball installed and you\u0026rsquo;ve run it on one of
your files, and Eyeball doesn\u0026rsquo;t like it. You\u0026rsquo;re not sure
why, or what to do about it. Here\u0026rsquo;s what\u0026rsquo;s going
on.\nEyeball inspects your model a [...]
\ No newline at end of file
diff --git a/content/security/advisories.html b/content/security/advisories.html
index 5f5220c59..77b786a18 100644
--- a/content/security/advisories.html
+++ b/content/security/advisories.html
@@ -191,6 +191,13 @@ and relevant <a
href="#cves-in-jena-dependencies">Dependency CVEs</a>.</p>
addressed by the project. Per our policy above we advise users to always
utilise
the latest Jena release available.</p>
<p>Please refer to the individual CVE links for further details and
mitigations.</p>
+<p><strong>CVE-2026-61372 Web requests using SPARQL Update can escape file
restrictions</strong></p>
+<p><a href="https://www.cve.org/CVERecord?id=CVE-20-613372">CVE-2026-61372</a>
affects Jena
+up to version 6.1.0.</p>
+<p>URL references to local resources in SPARQL Update requests were not being
+correctly restricted, and could include access to data on the local
machine.</p>
+<p>Users are recommended to upgrade to version 6.2.0 where such URLs are
restricted
+to be HTTP or FTP URLs.</p>
<p><strong>CVE-2025-50151 - Configuration files uploaded by administrative
users are not checked properly</strong></p>
<p><a
href="https://www.cve.org/CVERecord?id=CVE-2025-50151">CVE-2025-50151</a>
affects Jena
Fuseki in versions up to 5.4.0.</p>
diff --git a/content/sitemap.xml b/content/sitemap.xml
index d32a0370e..09f4da09d 100644
--- a/content/sitemap.xml
+++ b/content/sitemap.xml
@@ -60,7 +60,7 @@
<lastmod>2024-10-18T14:24:57+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/security/advisories.html</loc>
- <lastmod>2026-07-24T11:22:34+01:00</lastmod>
+ <lastmod>2026-07-28T19:01:56+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/documentation/shacl/</loc>
<lastmod>2023-04-09T15:11:22+02:00</lastmod>
@@ -533,7 +533,7 @@
<lastmod>2023-02-12T15:23:22+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/security.html</loc>
- <lastmod>2026-07-24T11:22:34+01:00</lastmod>
+ <lastmod>2026-07-28T19:01:56+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/documentation/fuseki2/fuseki-security.html</loc>
<lastmod>2025-07-15T11:51:08+01:00</lastmod>