Hi All,

SPARK-57672 upgraded the bundled Jetty to 12.1.10, which resolves 
CVE-2026-10050 (critical) and CVE-2026-10051 (high) in spark-core. It's marked 
fixed for 5.0.0, which hasn't been released yet.

Since the fix is currently only slated for the 5.0.0 major release, would it be 
possible to also backport the Jetty bump to a 4.2.x maintenance release (e.g. 
4.2.1)? These are high/critical CVEs, and it's a patch-level bump within the 
12.1.x line, so it may be a low-risk backport that would let users on the 
current 4.2.x line remediate without waiting for a major upgrade.

Thanks for considering it.

Best regards,
Ejas Ali

________________________________

This message is for the designated recipient only and may contain privileged, 
proprietary, or otherwise confidential information. If you have received it in 
error, please notify the sender immediately and delete the original. Any other 
use of the e-mail by you is prohibited. Where allowed by local law, electronic 
communications with Accenture and its affiliates, including e-mail and instant 
messaging (including content), may be scanned by our systems for the purposes 
of information security, AI-powered support capabilities, and assessment of 
internal compliance with Accenture policy. Your privacy is important to us. 
Accenture uses your personal data only in compliance with data protection laws. 
For further information on how Accenture processes your personal data, please 
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

www.accenture.com

Reply via email to