cruwe opened a new issue, #1274:
URL: https://github.com/apache/maven-site-plugin/issues/1274

   ### New feature, improvement proposal
   
   First, thank you very much for developing the maven-site-plugin and 
releasing it to the general public.
   
   
https://github.com/apache/maven-site-plugin/blob/55ebd9fb33a76b2f3aaf81dfdf4e8475bb3e4b4b/pom.xml#L200
   
   As per https://nvd.nist.gov/vuln/detail/CVE-2026-2332, the Eclipse Jetty 
Suite is vulnerable to "request smuggling" and the NIST marks the severity of 
this vulnerability as critical.
   
   Would it be possible to bump the jetty dependency to >=9.4.60 and release?
   
   Thanks again and cheers,
   --
   Christopher


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to