Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@jamie-albert
Copy link
Member

Summary

Adds pending-upstream-fix advisories to spark-4.1 for 6 CVEs, copying analysis from spark-4.0 which has the same underlying dependencies and blockers.

CVEs Addressed

Hive Upgrade Required

Jackson Upgrades Blocked by Avro

Both require Hadoop release with Avro 1.11.4+ due to dependency conflicts. Spark PR #40933 documents the blocker.

Commons-lang Migration

Jetty Migration

Shaded JAR Conflicts

Verification

All advisories based on spark-4.0 analysis where same components/versions exist:

  • spark-4.0: hive-exec 2.3.10, jetty-http 11.0.24, commons-lang 2.6
  • spark-4.1: hive-exec 2.3.10, jetty-http 11.0.26, commons-lang 2.6

Added pending-upstream-fix advisories from spark-4.0 analysis:

- GHSA-c476-j253-5rgq (CVE-2024-29869): Hive 2.3.10 → 4.0.1+ upgrade required
- GHSA-h46c-h94j-95f3 (CVE-2025-52999): Jackson 2.15.0+ requires Hadoop release with Avro 1.11.4+
- GHSA-j288-q9x7-2f5v (CVE-2025-48924): commons-lang 2.6 → commons-lang3 3.18.0+ upgrade needed
- GHSA-qh8g-58pp-2wxh (CVE-2024-6763): Jetty 11 → 12 migration pending
- GHSA-wf8f-6423-gfxg (CVE-2025-49128): Jackson 2.13.0+ requires Hadoop release with Avro 1.11.4+
- GHSA-xwmg-2g98-w7v9 (CVE-2025-53864): nimbus-jose-jwt shaded JAR conflicts

All advisories reference upstream PRs/JIRAs documenting blocker reasons.
@jamie-albert jamie-albert requested a review from a team January 7, 2026 01:38
@dnegreira dnegreira added this pull request to the merge queue Jan 7, 2026
Merged via the queue into wolfi-dev:main with commit f894f58 Jan 7, 2026
4 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants