This is an automated email from the ASF dual-hosted git repository.
github-bot pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/storm-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new da085770fa publishing 2026-04-12T18:21:31+00:00
da085770fa is described below
commit da085770fa5d3c0d78d9c1ec8b018286a40ea86a
Author: GitHub Actions Bot <>
AuthorDate: Sun Apr 12 18:21:31 2026 +0000
publishing 2026-04-12T18:21:31+00:00
---
2026/04/12/storm286-released.html | 4 +++-
feed.xml | 8 +++++---
news.html | 4 +++-
3 files changed, 11 insertions(+), 5 deletions(-)
diff --git a/2026/04/12/storm286-released.html
b/2026/04/12/storm286-released.html
index bade127bcc..f7971e914d 100644
--- a/2026/04/12/storm286-released.html
+++ b/2026/04/12/storm286-released.html
@@ -323,7 +323,7 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
-<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting
deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known
dependencies.</p>
+<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting
deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known
dependencies; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
<p><strong>Credit:</strong> This issue was discovered by K.</p>
@@ -335,6 +335,8 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
+<p>Users wh ocannot upgrade immediately should monkey-patch the related
escaping; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
+
<p><strong>Credit:</strong> This issue was discovered while investigating
another report by K.</p>
<h2>Enhancements</h2>
diff --git a/feed.xml b/feed.xml
index 19c242cc3d..656541c1e3 100644
--- a/feed.xml
+++ b/feed.xml
@@ -5,8 +5,8 @@
<description></description>
<link>https://storm.apache.org/</link>
<atom:link href="https://storm.apache.org/feed.xml" rel="self"
type="application/rss+xml"/>
- <pubDate>Sun, 12 Apr 2026 18:13:55 +0000</pubDate>
- <lastBuildDate>Sun, 12 Apr 2026 18:13:55 +0000</lastBuildDate>
+ <pubDate>Sun, 12 Apr 2026 18:20:05 +0000</pubDate>
+ <lastBuildDate>Sun, 12 Apr 2026 18:20:05 +0000</lastBuildDate>
<generator>Jekyll v3.10.0</generator>
<item>
@@ -37,7 +37,7 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to
2.8.6.</p>
-<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code>
restricting deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its
known dependencies.</p>
+<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code>
restricting deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its
known dependencies; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
<p><strong>Credit:</strong> This issue was discovered by
K.</p>
@@ -49,6 +49,8 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to
2.8.6.</p>
+<p>Users wh ocannot upgrade immediately should monkey-patch the related
escaping; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
+
<p><strong>Credit:</strong> This issue was discovered while
investigating another report by K.</p>
<h2>Enhancements</h2>
diff --git a/news.html b/news.html
index 3a4e4bc0d3..43dc7f28bd 100644
--- a/news.html
+++ b/news.html
@@ -320,7 +320,7 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
-<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting
deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known
dependencies.</p>
+<p>Users who cannot upgrade immediately should monkey-patch an
<code>ObjectInputFilter</code> allow-list to
<code>ClientAuthUtils.deserializeKerberosTicket()</code> restricting
deserialized classes to
<code>javax.security.auth.kerberos.KerberosTicket</code> and its known
dependencies; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
<p><strong>Credit:</strong> This issue was discovered by K.</p>
@@ -332,6 +332,8 @@ users on the mailing lists. Your efforts are much
appreciated.</p>
<p><strong>Mitigation:</strong> 2.x users should upgrade to 2.8.6.</p>
+<p>Users wh ocannot upgrade immediately should monkey-patch the related
escaping; see <a
href="https://dist.apache.org/repos/dist/release/storm/apache-storm-2.8.6/RELEASE_NOTES.html">for
details.</a></p>
+
<p><strong>Credit:</strong> This issue was discovered while investigating
another report by K.</p>
<h2>Enhancements</h2>