[ 
https://issues.apache.org/jira/browse/SPARK-58755?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated SPARK-58755:
-----------------------------------
    Labels: build pull-request-available security  (was: build security)

> [BUILD] Upgrade 6 third-party dependencies to fix 29 security vulnerabilities
> -----------------------------------------------------------------------------
>
>                 Key: SPARK-58755
>                 URL: https://issues.apache.org/jira/browse/SPARK-58755
>             Project: Spark
>          Issue Type: Improvement
>          Components: Build
>    Affects Versions: 5.0.0
>            Reporter: Anoopam Sharma
>            Priority: Major
>              Labels: build, pull-request-available, security
>
> This patch upgrades 6 third-party dependencies to address 29 known CVEs at 
> the runtime level.
>  
> h3. Upgrades
>  
> ||Library||From||To||CVEs Fixed||
> |libthrift|0.16.0|0.24.0|18|
> |Jackson (fasterxml)|2.22.0|2.22.1|4|
> |Log4j|2.26.0|2.26.1|1|
> |Janino|3.1.9|3.1.12|1|
> |Apache Ivy|2.5.3|2.6.0|1|
> |scalapb-runtime|0.11.17|0.11.20|4|
>  
> h3. Key CVEs addressed
>  
> * *libthrift 0.16.0* — CVE-2026-41604 (HIGH 8.2), CVE-2026-41602, 
> CVE-2026-41636, CVE-2025-48431, and 14 more
> * *Jackson 2.22.0* — CVE-2026-54512 (HIGH 8.1, PolymorphicTypeValidator 
> bypass allowing arbitrary class instantiation), CVE-2026-54513, 
> CVE-2026-54516, CVE-2026-54517
> * *Log4j 2.26.0* — CVE-2026-49844 (MEDIUM 5.9)
> * *Janino 3.1.9* — CVE-2023-33546 (MEDIUM 5.5)
> * *Ivy 2.5.3* — CVE-2026-26032 (MEDIUM 5.4)
> * *scalapb-runtime 0.11.17* — CVE-2024-7254 (HIGH 7.5), CVE-2026-0994, 
> CVE-2015-5237, CVE-2021-22570
>  
> h3. Compatibility
>  
> * All upgrades are minor/patch versions maintaining backward compatibility
> * libthrift 0.24.0 is a major version bump but maintains backward 
> compatibility for TBinaryProtocol/TCompactProtocol used by Hive metastore
> * Full distribution build passes with no compile errors
> * No user-facing API changes
>  
> h3. Testing
>  
> * \{{./dev/make-distribution.sh --name hadoop3 --tgz -Phadoop-3 -DskipTests}} 
> passes
> * \{{dev/deps/spark-deps-hadoop-3-hive-2.3}} updated to reflect new versions



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to