Hello Apache Geode Developer Community, The 1.15.5 maintenance release is nearing completion, we're reaching out to invite the community's input before the release notes are locked in.
This release reflects our continued, collective effort to remediate security vulnerabilities and preserve the stability of the 1.15.x line - work made possible by contributors across the project. We want the notes to be both accurate and representative of that shared progress. If there's a ticket or pull request you believe deserves mention, please reply to this thread with the details. Your input will help ensure the release notes fully and fairly reflect what the community has accomplished. Thank you for your continued support and contributions. ================ BEGIN OF RELEASE NOTE ============== 1.15.5 This maintenance release focuses on security remediation Highlights -Vulnerability Remediation: Addressed CVE-2026-59296 by upgrading Micrometer from 1.9.1 to 1.16.7 (GEODE-10628 #8057) -Vulnerability Remediation: Addressed CVE-2026-54513 and CVE-2026-19032 by upgrading Jackson from 2.21.2 to 2.21.6 (GEODE-10600 #8026, GEODE-10627 #8056) -Vulnerability Remediation: Addressed CVE-2026-49844 by upgrading Log4j from 2.25.4 to 2.25.5 (GEODE-10601 #8027) ================== END OF RELEASE NOTE ============== Best regards, Jinwoo Hwang (he/him/his) Apache Geode / SASĀ® Research and Development http://JinwooHwang.com<http://jinwoohwang.com/>
