rmoff opened a new issue, #14983:
URL: https://github.com/apache/iceberg/issues/14983
### Apache Iceberg version
1.10.1 (latest release)
### Query engine
Kafka Connect
### Please describe the bug π
When building the Kafka Connect connector as part of hopefully getting it
onto [Confluent Marketplace](hub.confluent.io) (neΓ© Confluent Hub), the vuln
scanner reports CVE-2025-55163
```
$ trivy rootfs --severity HIGH,CRITICAL
kafka-connect/kafka-connect-runtime/build/distributions/
[β¦]
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬βββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Library β Vulnerability
β Severity β Status β Installed Version β Fixed Version β
Title β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββΌβββββββββββΌβββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β io.grpc:grpc-netty-shaded (grpc-netty-shaded-1.71.0.jar) β CVE-2025-55163
β HIGH β fixed β 1.71.0 β 1.75.0 β netty:
netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS β
β β
β β β β β Vulnerability
β
β β
β β β β β
https://avd.aquasec.com/nvd/cve-2025-55163 β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄βββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
### Willingness to contribute
- [ ] I can contribute a fix for this bug independently
- [x] I would be willing to contribute a fix for this bug with guidance from
the Iceberg community
- [ ] I cannot contribute a fix for this bug at this time
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]