Hello Apache Geode Developer Community,

The 1.15.5 maintenance release is nearing completion, we're reaching out to 
invite the community's input before the release notes are locked in.

This release reflects our continued, collective effort to remediate security 
vulnerabilities and preserve the stability of the 1.15.x line - work made 
possible by contributors across the project. We want the notes to be both 
accurate and representative of that shared progress.

If there's a ticket or pull request you believe deserves mention, please reply 
to this thread with the details. Your input will help ensure the release notes 
fully and fairly reflect what the community has accomplished.

Thank you for your continued support and contributions.

================ BEGIN OF RELEASE NOTE ==============

1.15.5

This maintenance release focuses on security remediation

Highlights

-Vulnerability Remediation: Addressed CVE-2026-59296 by upgrading Micrometer 
from 1.9.1 to 1.16.7 (GEODE-10628 #8057)
-Vulnerability Remediation: Addressed CVE-2026-54513 and CVE-2026-19032 by 
upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10600 #8026, GEODE-10627 #8056)
-Vulnerability Remediation: Addressed CVE-2026-49844 by upgrading Log4j from 
2.25.4 to 2.25.5 (GEODE-10601 #8027)

================== END OF RELEASE NOTE ==============

Best regards,
Jinwoo Hwang (he/him/his)
Apache Geode / SASĀ® Research and Development
http://JinwooHwang.com<http://jinwoohwang.com/>

Reply via email to