Skip to content

Provide the list of vulnerable classes of grpc-netty-shaded 1.62.2 #12606

@Archana-toran

Description

@Archana-toran

Following up on issue #4180, requesting clarification regarding CVE-2025-55163 and its impact on the spring-cloud-gcp-dependencies.

As mentioned in #4180, there are concerns about CVE-2025-55163 affecting certain components in the Spring Cloud GCP ecosystem. However, there seems to be some uncertainty about the actual impact and scope. Hence, we are requesting to provide the necessary information below.

Vulnerable Library we used:
Library name: grpc-netty-shaded
Version: 1.62.2

Questions/Requests:

  1. Vulnerable Classes Identification:
     Could you please provide a detailed list of the exact classes that are vulnerable to [CVE-2025-55163(https://github.com/advisories/GHSA-prj3-ccx8-p6x4)?
     Which of these vulnerable classes are used by gRPC components in spring-cloud-gcp?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions