hernaldog opened a new issue, #6628:
URL: https://github.com/apache/jmeter/issues/6628

   Hello, on December 15, 2025, my company's Security department notified me 
that I must remove these libraries from JMeter 5.6.3. They are called 
"tika-core-1.28.3" and "tika-parsers-1.28.3" because they present a group of 
XXE vulnerabilities. Is it possible to update JMeter 5.6.3 to a version 5.6.4, 
for example, with the latest versions of these libraries? I've noticed that 
version 1.28.3 is quite old.
   
   https://nvd.nist.gov/vuln/detail/CVE-2025-66516


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to