Skip to content

Consider Upgrading Netty to 4.1.118.Final Due to CVE-2025-24970 #2710

@CPogX

Description

@CPogX

CVE-2025-24970 is coming high in my security scans.

Please consider upgrading Netty version to 4.1.118.Final. Not a big deal as I can just specify the netty version in my java project, but I wanted to try the karate-npm and the -all jar it tries to pull is quarantined on my end.

https://nvd.nist.gov/vuln/detail/CVE-2025-24970
GHSA-4g8c-wm8x-jfhw

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions