11 hours ago
Activiti
13 hours ago
netty

netty-4.1.139.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

New Contributors

Full Changelog: https://github.com/netty/netty/compare/netty-4.1.138.Final...netty-4.1.139.Final

13 hours ago
netty

netty-4.2.19.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

New Contributors

Full Changelog: https://github.com/netty/netty/compare/netty-4.2.18.Final...netty-4.2.19.Final

23 hours ago
Activiti
1 days ago
selenium

Nightly

Commits

  • 8ba36d4: [build] Automated Dependency Update (#18124) (Selenium CI Bot) #18124
  • 77e3a5f: [build] Automated Selenium Manager Update (Selenium CI Bot)
  • 9fc36cc: [dotnet] [build] Escape macOS Edge browser path (#18126) (Nikolay Borisenko) #18126
1 days ago
Activiti

7.21.0-rc.658

What's Changed

⬆️ Dependencies

🔨 Other Changes

Full Changelog: https://github.com/Activiti/Activiti/compare/7.21.0-rc.657...7.21.0-rc.658