Skip to content

Commit 4eea791

Browse files
NO-SNOW bump to netty 4.1.132.Final (CVE-2026-33870 & CVE-2026-33871) (#2561)
1 parent 25f0727 commit 4eea791

File tree

4 files changed

+18
-5
lines changed

4 files changed

+18
-5
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
- Added warning about using plain HTTP OAuth endpoints (snowflakedb/snowflake-jdbc#2556).
66
- Fix initializing ObjectMapper when DATE_OUTPUT_FORMAT is specified (snowflakedb/snowflake-jdbc#2545).
77
- Fix Netty native library conflict in thin JAR (snowflakedb/snowflake-jdbc#2559)
8+
- Bumped netty to 4.1.132.Final to address CVE-2026-33870 (High) and CVE-2026-33871 (High) (snowflakedb/snowflake-jdbc#2561)
89

910
- v4.0.2
1011
- Fix expired session token renewal when polling results (snowflakedb/snowflake-jdbc#2489)

TestOnly/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
<junit.version>5.11.1</junit.version>
2222
<surefire.version>3.5.1</surefire.version>
2323
<mockito.version>3.5.6</mockito.version>
24-
<netty.version>4.1.130.Final</netty.version>
24+
<netty.version>4.1.132.Final</netty.version>
2525
<apache.httpclient.version>4.5.14</apache.httpclient.version>
2626
<bouncycastle.version>1.82</bouncycastle.version>
2727
<shadeBase>net.snowflake.client.jdbc.internal</shadeBase>

parent-pom.xml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
</modules>
1515

1616
<properties>
17+
<animal.sniffer.annotations.version>1.26</animal.sniffer.annotations.version>
1718
<apache.commons.compress.version>1.28.0</apache.commons.compress.version>
1819
<apache.commons.lang3.version>3.18.0</apache.commons.lang3.version>
1920
<apache.commons.text.version>1.10.0</apache.commons.text.version>
@@ -55,7 +56,7 @@
5556
<google.j2objc-annotations.version>3.0.0</google.j2objc-annotations.version>
5657
<google.jsr305.version>3.0.2</google.jsr305.version>
5758
<google.protobuf.java.version>4.28.2</google.protobuf.java.version>
58-
<grpc.version>1.77.0</grpc.version>
59+
<grpc.version>1.80.0</grpc.version>
5960
<hamcrest.version>2.2</hamcrest.version>
6061
<hikaricp.version>2.4.3</hikaricp.version>
6162
<jackson.version>2.18.4.1</jackson.version>
@@ -70,7 +71,7 @@
7071
<logback.version>1.3.6</logback.version>
7172
<mockito.version>4.11.0</mockito.version>
7273
<nimbusds.oauth2.version>11.30.1</nimbusds.oauth2.version>
73-
<netty.version>4.1.130.Final</netty.version>
74+
<netty.version>4.1.132.Final</netty.version>
7475
<nimbusds.version>10.6</nimbusds.version>
7576
<opencensus.version>0.31.1</opencensus.version>
7677
<plexus.container.version>1.0-alpha-9-stable-1</plexus.container.version>
@@ -151,6 +152,11 @@
151152
<type>pom</type>
152153
<scope>import</scope>
153154
</dependency>
155+
<dependency>
156+
<groupId>org.codehaus.mojo</groupId>
157+
<artifactId>animal-sniffer-annotations</artifactId>
158+
<version>${animal.sniffer.annotations.version}</version>
159+
</dependency>
154160
<dependency>
155161
<groupId>classworlds</groupId>
156162
<artifactId>classworlds</artifactId>

thin_public_pom.xml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@
3333
</scm>
3434

3535
<properties>
36+
<animal.sniffer.annotations.version>1.26</animal.sniffer.annotations.version>
3637
<apache.httpclient.version>4.5.14</apache.httpclient.version>
3738
<apache.httpcore.version>4.4.16</apache.httpcore.version>
3839
<awssdk.version>2.37.5</awssdk.version>
@@ -53,14 +54,14 @@
5354
<google.http.client.version>1.45.0</google.http.client.version>
5455
<google.jsr305.version>3.0.2</google.jsr305.version>
5556
<google.protobuf.java.version>4.28.2</google.protobuf.java.version>
56-
<grpc.version>1.77.0</grpc.version>
57+
<grpc.version>1.80.0</grpc.version>
5758
<jackson.version>2.18.4.1</jackson.version>
5859
<javax.servlet.version>3.1.0</javax.servlet.version>
5960
<jna.version>5.13.0</jna.version>
6061
<json.smart.version>2.5.2</json.smart.version>
6162
<jsoup.version>1.15.3</jsoup.version>
6263
<metrics.version>2.2.0</metrics.version>
63-
<netty.version>4.1.130.Final</netty.version>
64+
<netty.version>4.1.132.Final</netty.version>
6465
<nimbusds.version>10.6</nimbusds.version>
6566
<nimbusds.oauth2.version>11.30.1</nimbusds.oauth2.version>
6667
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
@@ -106,6 +107,11 @@
106107
<type>pom</type>
107108
<scope>import</scope>
108109
</dependency>
110+
<dependency>
111+
<groupId>org.codehaus.mojo</groupId>
112+
<artifactId>animal-sniffer-annotations</artifactId>
113+
<version>${animal.sniffer.annotations.version}</version>
114+
</dependency>
109115
</dependencies>
110116
</dependencyManagement>
111117

0 commit comments

Comments
 (0)