[BUG] CVE-2025-24970 Apache Netty < 4.1.118.Final #17461
Labels
bug
Something isn't working
_No response_
v2.19.1
Issues and PRs related to version 2.19.1
v3.0.0
Issues and PRs related to version 3.0.0
Describe the bug
As per my question and received advice on the Opensearch forum: https://forum.opensearch.org/t/cve-2025-24970-apache-netty-4-118-final/23580
Please update Apache Netty libs to 4.1.118.Final to address recent high severity CVE-2025-24970 https://nvd.nist.gov/vuln/detail/CVE-2025-24970 and to ensure a clean vulnerability scan against a full tarball deployment of Opensearch 2.x
Looking at current opensearch release 2.19 ( in unpacked tarball) can see affected libs in several places (here searching for just the handler):
Related component
No response
To Reproduce
Install Opensearch 2.19.0
Expected behavior
Apache Netty libs upgraded to 4.1.118.Final throughout product
Additional Details
Plugins
Please list all plugins currently enabled.
Screenshots
If applicable, add screenshots to help explain your problem.
Host/Environment (please complete the following information):
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: