Skip to content

[Bug] Upgrade Netty to remediate CVEs #10089

@shub-est

Description

@shub-est

Before Creating the Bug Report

  • I found a bug, not just asking a question, which should be created in GitHub Discussions.

  • I have searched the GitHub Issues and GitHub Discussions of this repository and believe that this is not a duplicate.

  • I have confirmed that this bug belongs to the current repository, not other repositories of RocketMQ.

Runtime platform environment

All

RocketMQ version

develop

JDK Version

8

Describe the Bug

Upgraded Netty to 4.1.130.Final to remediate CVE-2025-55163, CVE-2025-59419, CVE-2025-58057, CVE-2025-67735 and CVE-2025-58056

Steps to Reproduce

N/A

What Did You Expect to See?

N/A

What Did You See Instead?

N/A

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions