This is an automated email from the ASF dual-hosted git repository.

github-bot pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/storm-site.git


The following commit(s) were added to refs/heads/asf-site by this push:
     new da085770fa publishing 2026-04-12T18:21:31+00:00
da085770fa is described below

commit da085770fa5d3c0d78d9c1ec8b018286a40ea86a
Author: GitHub Actions Bot <>
AuthorDate: Sun Apr 12 18:21:31 2026 +0000

    publishing 2026-04-12T18:21:31+00:00
---
 2026/04/12/storm286-released.html | 4 +++-
 feed.xml                          | 8 +++++---
 news.html                         | 4 +++-
 3 files changed, 11 insertions(+), 5 deletions(-)

diff --git a/2026/04/12/storm286-released.html 
b/2026/04/12/storm286-released.html
index bade127bcc..f7971e914d 100644
--- a/2026/04/12/storm286-released.html
+++ b/2026/04/12/storm286-released.html
@@ -323,7 +323,7 @@ users on the mailing lists. Your efforts are much 
appreciated.</p>
 
 <p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
 
-<p>Users who cannot upgrade immediately should monkey-patch an 
<code>ObjectInputFilter</code> allow-list to 
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting 
deserialized classes to 
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known 
dependencies.</p>
+<p>Users who cannot upgrade immediately should monkey-patch an 
<code>ObjectInputFilter</code> allow-list to 
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting 
deserialized classes to 
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known 
dependencies; see <a 
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html";>for
 details.</a></p>
 
 <p><strong>Credit:</strong> This issue was discovered by K.</p>
 
@@ -335,6 +335,8 @@ users on the mailing lists. Your efforts are much 
appreciated.</p>
 
 <p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
 
+<p>Users wh ocannot upgrade immediately should monkey-patch the related 
escaping; see <a 
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html";>for
 details.</a></p>
+
 <p><strong>Credit:</strong> This issue was discovered while investigating 
another report by K.</p>
 
 <h2>Enhancements</h2>
diff --git a/feed.xml b/feed.xml
index 19c242cc3d..656541c1e3 100644
--- a/feed.xml
+++ b/feed.xml
@@ -5,8 +5,8 @@
     <description></description>
     <link>https://storm.apache.org/</link>
     <atom:link href="https://storm.apache.org/feed.xml"; rel="self" 
type="application/rss+xml"/>
-    <pubDate>Sun, 12 Apr 2026 18:13:55 +0000</pubDate>
-    <lastBuildDate>Sun, 12 Apr 2026 18:13:55 +0000</lastBuildDate>
+    <pubDate>Sun, 12 Apr 2026 18:20:05 +0000</pubDate>
+    <lastBuildDate>Sun, 12 Apr 2026 18:20:05 +0000</lastBuildDate>
     <generator>Jekyll v3.10.0</generator>
     
       <item>
@@ -37,7 +37,7 @@ users on the mailing lists. Your efforts are much 
appreciated.&lt;/p&gt;
 
 &lt;p&gt;&lt;strong&gt;Mitigation:&lt;/strong&gt; 2.x users should upgrade to 
2.8.6.&lt;/p&gt;
 
-&lt;p&gt;Users who cannot upgrade immediately should monkey-patch an 
&lt;code&gt;ObjectInputFilter&lt;/code&gt; allow-list to 
&lt;code&gt;ClientAuthUtils.deserializeKerberosTicket()&lt;/code&gt; 
restricting deserialized classes to 
&lt;code&gt;javax.security.auth.kerberos.KerberosTicket&lt;/code&gt; and its 
known dependencies.&lt;/p&gt;
+&lt;p&gt;Users who cannot upgrade immediately should monkey-patch an 
&lt;code&gt;ObjectInputFilter&lt;/code&gt; allow-list to 
&lt;code&gt;ClientAuthUtils.deserializeKerberosTicket()&lt;/code&gt; 
restricting deserialized classes to 
&lt;code&gt;javax.security.auth.kerberos.KerberosTicket&lt;/code&gt; and its 
known dependencies; see &lt;a 
href=&quot;https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html&quot;&gt;for
 details.&lt;/a&gt;&lt;/p&gt;
 
 &lt;p&gt;&lt;strong&gt;Credit:&lt;/strong&gt; This issue was discovered by 
K.&lt;/p&gt;
 
@@ -49,6 +49,8 @@ users on the mailing lists. Your efforts are much 
appreciated.&lt;/p&gt;
 
 &lt;p&gt;&lt;strong&gt;Mitigation:&lt;/strong&gt; 2.x users should upgrade to 
2.8.6.&lt;/p&gt;
 
+&lt;p&gt;Users wh ocannot upgrade immediately should monkey-patch the related 
escaping; see &lt;a 
href=&quot;https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html&quot;&gt;for
 details.&lt;/a&gt;&lt;/p&gt;
+
 &lt;p&gt;&lt;strong&gt;Credit:&lt;/strong&gt; This issue was discovered while 
investigating another report by K.&lt;/p&gt;
 
 &lt;h2&gt;Enhancements&lt;/h2&gt;
diff --git a/news.html b/news.html
index 3a4e4bc0d3..43dc7f28bd 100644
--- a/news.html
+++ b/news.html
@@ -320,7 +320,7 @@ users on the mailing lists. Your efforts are much 
appreciated.</p>
 
 <p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
 
-<p>Users who cannot upgrade immediately should monkey-patch an 
<code>ObjectInputFilter</code> allow-list to 
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting 
deserialized classes to 
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known 
dependencies.</p>
+<p>Users who cannot upgrade immediately should monkey-patch an 
<code>ObjectInputFilter</code> allow-list to 
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting 
deserialized classes to 
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known 
dependencies; see <a 
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html";>for
 details.</a></p>
 
 <p><strong>Credit:</strong> This issue was discovered by K.</p>
 
@@ -332,6 +332,8 @@ users on the mailing lists. Your efforts are much 
appreciated.</p>
 
 <p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
 
+<p>Users wh ocannot upgrade immediately should monkey-patch the related 
escaping; see <a 
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html";>for
 details.</a></p>
+
 <p><strong>Credit:</strong> This issue was discovered while investigating 
another report by K.</p>
 
 <h2>Enhancements</h2>

Reply via email to