Skip to content

Bump undertow to v2.2.40 - #91

Merged
patrikk0123 merged 1 commit into
Commonjava:1.xfrom
patrikk0123:fix-cve
Sep 17, 2026
Merged

patrikk0123 merged 1 commit into
Commonjava:1.xfrom
patrikk0123:fix-cve

Conversation

@patrikk0123

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown
Contributor

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 21 dependencies

Detected 7 vulnerabilities (0 Critical, 6 High, 1 Medium, 0 Low)

+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| SEVERITY |              LIBRARY              |       ID       |                                             TOP FIX                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.40.Final.jar    | CVE-2024-4027  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.3.21.Final,                 |
|          |                                   |                | io.undertow:undertow-core:2.3.21.Final,io.undertow:undertow-core:2.2.39.Final,                  |
|          |                                   |                | https://github.com/undertow-io/undertow.git - 2.4.0.Beta1,io.undertow:undertow-core:2.4.0.Beta1 |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.40.Final.jar    | CVE-2026-15554 | N/A                                                                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.40.Final.jar    | CVE-2026-15561 | N/A                                                                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.40.Final.jar    | CVE-2026-5680  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.4.3.Final,                  |
|          |                                   |                | io.undertow:undertow-core:2.4.3.Final                                                           |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.40.Final.jar    | CVE-2026-81624 | N/A                                                                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| HIGH     | undertow-servlet-2.2.40.Final.jar | CVE-2026-81624 | N/A                                                                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+
| MEDIUM   | undertow-core-2.2.40.Final.jar    | CVE-2026-19879 | N/A                                                                                             |
+----------+-----------------------------------+----------------+-------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

undertow-core-2.2.40.Final.jar [5 HIGH, 1 MEDIUM]
undertow-servlet-2.2.40.Final.jar [1 HIGH]
|-- undertow-core-2.2.40.Final.jar [5 HIGH, 1 MEDIUM]


No Policy violations were detected

Project 'http-testserver' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=3e4a4791-bd78-42c2-810a-0fe36f078b23
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=377f5a0ae9fd4922a9e55480620df3a0685d6038dc7f41849565798974f4e93d

Mend AI scan succeeded.

Support Token: 003c05ca68a1f4c75b31710fd125160931789655567458

Full logs and artifacts

@patrikk0123
patrikk0123 merged commit 7b3eb01 into Commonjava:1.x Sep 17, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants