Acceldata
ODP

Fixed CVEs

This release resolves 895 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.2.3.6-2 to 3.2.3.7-2.


Detailed List of CVEs Addressed

For detailed information about CVEs addressed in this release, see ODP 3.2.3.7-2 Acceldata Open-Source Data Platform CVE Fixes.


Summary of CVEs by component and severity level

You can see the summary of CVEs addressed by components and severity level.


CVE Fix Descriptions

Ambari

  • OSV-17061: Upgraded hadoop-shaded-guava.
  • OSV-16794 | 16780: Prevented old versions of Guava from being pulled in.
  • OSV-16922: Upgraded the PostgreSQL driver to 42.7.11.
  • OSV-17066 | 17019 | 17017 | 17076: Updated Spring to 5.3.34 and Spring Security to 5.8.16.
  • OSV-17024 | 17025: Pinned snappy-java to 1.1.10.4.
  • OSV-16928 | 12929 | 16931 | 16932: Updated mina-core.
  • OSV-16786 | 16787: Bumped jackson-databind to 2.16.1 in Ambari Infra Solr.
  • OSV-16812: Updated Derby to 10.14.3.0.
  • OSV-17055 | 17053 | 16933 | 16924: Updated Netty to 4.1.42.Final.
  • OSV-16924: Updated Netty and rebuilt fast-hdfs-resource.jar.
  • OSV-16837: Bumped Netty to 4.1.133.Final for Ambari Infra.
  • OSV-16803: Upgraded aws-java-sdk-core to 1.12.797.
  • OSV-16973 | 16974 | 16975 | 16976 | 16977 | 16978: Fixed Log4j CVEs.
  • OSV-16058: Bumped Netty to 4.1.132.Final.

Hadoop

  • ODP-7103: Bumped moment.js to 2.29.4 in Hadoop to fix CVE-2022-24785 and CVE-2022-31129.
  • OSV-19087 | ODP-2625 | HADOOP-19237 | HADOOP-17317: Upgraded to dnsjava 3.6.0 to resolve CVE-2024-25638.
  • OSV-19068: Bumped okio to 1.17.6 to fix CVE-2023-3635.
  • OSV-19046: Bumped Netty 4 to 4.1.135.Final to fix CVE-2026-44248.
  • OSV-19052: Bumped Bouncy Castle to 1.84 to fix CVE-2026-558.
  • OSV-19052: Bumped Netty 4 to 4.1.133.Final to fix CVE-2026-42587.
  • OSV-19052: Bumped Jackson 2 to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-19052: Bumped commons-configuration2 to 2.15.0 to fix CVE-2026-45205.

Airflow

  • OSV-20101 | 20102: Bumped gunicorn from 21.2.0 to 23.0.0 (CVE-2024-1135, CVE-2024-6827).
  • OSV-20018 | 20019 | 20020: Bumped Jinja2 from 3.1.3 to 3.1.6 (CVE-2024-56326, CVE-2024-56201, CVE-2025-27516).
  • OSV-20028 | 20029 | 20030: Bumped GitPython from 3.1.41 to 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w).
  • OSV-19986 | 19989: Bumped aiohttp from 3.9.1 to 3.10.11 (CVE-2024-23334, CVE-2024-30251).
  • OSV-19968 | 19969: Bumped cryptography from 41.0.7 to 43.0.3 (CVE-2023-50782, CVE-2024-26130).
  • OSV-20094 | 20033: Bumped eventlet from 0.34.3 to 0.38.2 and dnspython from 2.4.2 to 2.6.1 (CVE-2023-29483).
  • OSV-20080: Bumped protobuf from 4.25.2 to 4.25.8 (CVE-2025-4565).
  • OSV-20015: Bumped certifi from 2023.11.17 to 2024.7.4 (CVE-2024-39689).
  • OSV-20083: Bumped Mako from 1.3.0 to 1.3.12 (CVE-2026-44307).
  • OSV-20046: Bumped sqlparse from 0.4.4 to 0.5.0 (CVE-2024-4340).
  • OSV-20027: Bumped virtualenv from 20.25.0 to 20.26.6 (CVE-2024-53899).
  • OSV-20037: Bumped Authlib from 1.3.0 to 1.3.2 (CVE-2024-37568).
  • OSV-20071: Bumped snowflake-connector-python from 3.6.0 to 3.13.1 (CVE-2025-24793).
  • OSV-20044: Bumped redshift-connector from 2.0.918 to 2.1.7 (CVE-2025-5279).
  • OSV-20119: Bumped Flask-AppBuilder from 4.3.10 to 4.3.11 (CVE-2024-25128).
  • OSV-19968 | 19969 | 20022: Fixed the resolver conflict introduced by cryptography 43.0.3 and bumped the Google stack along with httpx, httpcore, and h11 (CVE-2025-43859).
  • OSV-20062: Backported example_xcom hardening from apache/airflow#63200 (CVE-2025-54550).
  • OSV-20051: Disabled Jinja rendering of DAG doc_md (CVE-2024-39877).
  • OSV-20056: Loaded airflow_local_settings before adding the DAGs folder to sys.path (CVE-2024-45034).
  • OSV-20055: Masked sensitive config values in logs (CVE-2024-45784).
  • OSV-20058: Added a distinct MENU permission check in the auth manager (CVE-2024-28746).
  • Fixed missing web UI assets in the from-source tarball build.
  • OSV-20028-2 | 20029-2 | 20030-2: Bumped the GitPython build dependency from 3.1.42 to 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w).
  • OSV-19972: Rejected semicolons in CopyFromExternalStageToSnowflakeOperator table and stage names (CVE-2025-50213).
  • OSV-20009: Replaced pickle with JSON serialization for HTTP trigger responses (CVE-2025-69219).
  • Bumped beautifulsoup4 from 4.12.2 to 4.13.5 to satisfy redshift-connector 2.1.14.

Cruise Control

  • OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.

Cruise Control3

  • OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.

Druid

  • OSV-18025: Increased aircompressor to 2.0.3 to fix the Druid aircompressor CVEs.
  • OSV-18043: Increased the PostgreSQL version to fix the Druid PostgreSQL CVEs.
  • OSV-17943: Pinned woodstox-core to 6.5.1 to fix the Druid woodstox-core CVEs.
  • OSV-17940: Increased azure-sdk-bom to 1.2.25 (azure-identity 1.13.0) to fix the Druid azure-identity CVEs.
  • OSV-18047: Increased plexus-utils to 3.6.1 to fix the Druid plexus-utils CVEs.
  • OSV-17957: Increased jose4j to 0.9.6 to fix the Druid jose4j CVEs.
  • OSV-18024: Increased the json-path version to fix the Druid json-path CVEs.
  • OSV-18042: Increased the Netty version to fix the Druid Netty CVEs.
  • OSV-18048: Increased the Log4j 2 version to fix the Druid Log4j CVEs.
  • OSV-17937: Pinned jackson-databind to 2.12.7.1 to fix the Druid jackson-databind CVEs.

Flink

  • OSV-18068: Increased the Log4j 2 version to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.

HBase

  • CVE-2023-2976: Bumped Curator to 5.7.1 to fix the shaded Guava vulnerability.
  • OSV-18177: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
  • OSV-18087: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34480.
  • OSV-18166: Updated dnsjava to 3.6.0 in the supplemental XML to reflect the version pulled from Hadoop.
  • OSV-18095 | HBASE-30028: Bumped io.opentelemetry.javaagent:opentelemetry-javaagent.
  • OSV-19098: Upgraded to hbase-thirdparty 4.1.13.
  • OSV-19098: Bumped OpenTelemetry to 1.62.0 to fix CVE-2026-45292.

Hive

  • OSV-17463: Upgraded Bouncy Castle and commons-compress to match Hadoop.
  • OSV-17526: Upgraded the PostgreSQL driver to 42.7.11 to fix CVE-2026-42198.
  • OSV-17489: Upgraded json-path to 2.10.0 to fix CVE-2024-57699.
  • OSV-17489: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-17489: Upgraded Log4j 2 to 2.25.4 to fix CVE-2026-34479.
  • OSV-17378: Upgraded Netty to 4.1.135.Final.

Hue

  • OSV-17161: Upgraded Pygments from 2.0.2 to 2.5.2 (CVE-2015-8557).
  • OSV-17209: Removed the duplicate urllib3 1.26.12 (CVE-2023-43804).
  • OSV-17175: Upgraded python-rsa from 4.0 to 4.5 (CVE-2020-13757).
  • OSV-17218: Updated the certifi bundle to 2023.07.22 (CVE-2023-37920).

Impala

  • OSV-19104: Pinned opentelemetry-api to 1.62.0 to fix the Impala OpenTelemetry CVEs.
  • OSV-19233: Pinned commons-io to 2.14.0 to fix the Impala commons-io CVEs.
  • OSV-19206: Pinned okio to 1.17.6 to fix the Impala okio CVEs.
  • OSV-19139: Increased commons-configuration2 to 2.15.0 to fix the Impala commons-configuration2 CVEs.
  • OSV-19188: Increased the PostgreSQL JDBC version to 42.7.11 to fix the Impala PostgreSQL CVEs.
  • OSV-19228: Increased Log4j 2 to 2.25.4 to fix the Impala Log4j 2 CVEs.
  • OSV-19138: Increased Jackson to 2.18.6 to fix the Impala Jackson CVEs.
  • OSV-19108: Increased Netty to 4.1.133.Final (netty-bom) to fix the Impala Netty CVEs.

JupyterHub

  • OSV-20622: Bumped h11 to 0.16.0 and httpcore to 1.0.9 (CVE-2025-43859).
  • OSV-20579: Bumped Mako to 1.3.12 (CVE-2026-44307).
  • OSV-20613: Bumped mistune to 3.2.1 (CVE-2026-33079).
  • OSV-20626: Bumped jupyter_core to 5.8.1 (CVE-2025-30167).
  • Bumped Tornado to 6.4.2 (CVE-2024-52804).

Kafka

  • OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
  • OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
  • KAFKA-19336: Upgraded Jackson to 2.19.0.

Kafka3

  • OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
  • OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
  • KAFKA-19336: Upgraded Jackson to 2.19.0.

Knox

  • OSV-17552: Removed the duplicate Jackson version property and upgraded Jackson to 2.18.6 to resolve GHSA-72hv-8253-57qq.
  • OSV-17549: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
  • OSV-17544: Upgraded nimbus-jose-jwt to 9.37.4 to fix CVE-2025-53864.
  • OSV-17548: Upgraded commons-io to 2.14.0 and forbiddenapis to 3.6 to fix CVE-2024-47554.
  • OSV-17545: Bumped jakarta.mail from 1.6.5 to 1.6.8 to address CVE-2025-7962.
  • OSV-17542 | 17541 | 17540 | 17539 | 17538: Bumped Apache Log4j to 2.25.4 to fix CVE-2026-34479, CVE-2026-34477, CVE-2026-34480, CVE-2026-34481, and CVE-2025-68161.
  • OSV-17543: Upgraded PostgreSQL to 42.7.11 to fix CVE-2026-42198.
  • OSV-17640: Upgraded spring.version to 5.3.39 to resolve CVE-2024-38808.
  • OSV-17559: Upgraded spring-vault-core to 2.3.3 to fix CVE-2023-20859.
  • OSV-17633 | 17632 | 17631 | 17566: Bumped Apache Shiro to 1.13.0 to address CVE-2023-46749, CVE-2023-46750, and CVE-2026-23903.
  • OSV-17570: Upgraded mina-core to 2.0.28 to fix CVE-2026-41409.
  • OSV-17573: Bumped org.apache.santuario:xmlsec from 2.1.8 to 2.2.6 to fix CVE-2023-44483.
  • KNOX-3307: Upgraded jackson-core to 2.18.6.
  • Bumped org.apache.commons:commons-configuration2 from 2.10.1 to 2.15.0.
  • KNOX-3059: Upgraded commons-configuration2 to 2.10.1.
  • OSV-17565: Bumped org.apache.commons:commons-lang3 from 3.11.0 to 3.18.0 to fix CVE-2025-48924.
  • OSV-17634 | 17635: Upgraded commons-compress from 1.21 to 1.26.0 to fix CVE-2024-26308 and CVE-2024-25710.
  • OSV-17638 | 17637 | 17564 | 17563 | 17562 | 17561 | 17560: Upgraded Bouncy Castle to jdk18on 1.84 to address multiple CVEs.
  • OSV-17559: Pinned amqp-client to 5.18.0 to fix CVE-2023-46120.

Kudu

  • OSV-17691: Upgraded Log4j to 2.25.4.
  • OSV-17512: Upgraded Netty to 4.1.135.Final to fix CVE-2026-42583.

NiFi / NiFi Registry

  • OSV-17883: Excluded commons-beanutils to resolve the reported CVEs.
  • ODP-6966: Used ${odp.release.version} for nifi-standard-shared-bom parent references.
  • OSV-17902 | 17890 | 17888 | 17884: Bumped io.netty to 4.1.135.Final.

Oozie

  • OSV-18618: Backported OOZIE-3655 to upgrade jdom to jdom2 2.0.6.1 and fix CVE-2021-33813.
  • OSV-18467: Removed the pig module from the Oozie sharelib to exclude Pig package CVEs.
  • OSV-18465 | 18464 | 18463 | 18462 | 18461: Excluded the unwanted Jetty runner to address critical mina-core CVEs.
  • OSV-18622: Fixed CVE-2026-27727 from the transitive dependency mchange-commons-java.
  • OSV-18611: Fixed CVE-2026-27830 from the transitive dependency c3p0.
  • OSV-18679: Fixed CVE-2020-10683 from the transitive dependency dom4j 1.6.1.

Ozone

  • ODP-7371: Upgraded commons-configuration2 to 2.15.0 to match the version in the stack.
  • OSV-18758: Bumped grpc.protobuf-compile.version to 3.25.5.
  • OSV-18712: Bumped Log4j 2 to 2.25.4.

Phoenix

  • Upgraded commons-beanutils to 1.11.0 to fix CVE-2025-48734.
  • Matched the Jackson version with HBase to fix CVE-2025-52999.
  • OSV-20133: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.

Pinot

  • OSV-18866: Increased the Netty version to fix CVE-2026-42579.
  • OSV-18862: Increased the Log4j 2 version to fix CVE-2026-34479.
  • OSV-18787: Increased the commons-lang3 version to fix CVE-2025-48924.
  • OSV-18772: Increased the commons-configuration2 version to fix CVE-2026-45205.
  • OSV-18793: Increased the nimbus-jose-jwt version to fix CVE-2025-53864.
  • OSV-18858: Increased the aircompressor version to fix CVE-2025-67721.
  • OSV-18860: Increased the async-http-client version to fix CVE-2026-45300.
  • OSV-18776: Stripped the Jackson 2.4.0 copy embedded in htrace-core4 from the pinot-orc and pinot-parquet shaded jars.
  • OSV-18796: Bumped Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.

Ranger

  • OSV-19463: Upgraded netty-all to 4.1.133.Final to address CVE-2026-42587 and other CVEs.
  • OSV-19365: Upgraded Tomcat to 9.0.118 to mitigate CVE-2026-43515 and multiple other CVEs.
  • OSV-19554: Bumped hbase-thirdparty to 4.1.13 to mitigate multiple Netty CVEs.
  • Applied the OSV fixes on Ranger that address the HBase CVEs from 3.2.3.6-2.
  • OSV-19531: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.

Schema Registry

  • OSV-20187 | OSV-20206: Bumped the PostgreSQL driver and plexus-utils.

Spark3

  • ODP-7140: Bumped the wildfly-openssl version in Spark 3.5.5 to fix CVE-2019-14887.
  • OSV-12356: Fixed CVEs from gson, okhttp, and jdom2.
  • OSV-19685: Increased the Jackson version (CVE unspecified).
  • OSV-19714: Increased the Netty version to fix CVE-2026-42587.
  • OSV-19741: Increased the Log4j 2 version to fix CVE-2026-34479.
  • OSV-19721: Increased the lz4-java version to fix CVE-2025-12183.
  • OSV-19743: Increased the aircompressor version to fix CVE-2025-67721.

Tez

  • OSV-17368: Pinned okio to 1.17.6 to fix the Tez okio CVEs.
  • OSV-17311: Pinned jdom2 to 2.0.6.1 to fix the Tez jdom2 CVEs.
  • OSV-17283: Pinned commons-configuration2 to 2.15.0 to fix the Tez commons-configuration2 CVEs.
  • OSV-17305: Increased async-http-client to 2.15.0 to fix the Tez async-http-client CVEs.
  • OSV-17290: Increased commons-io to 2.14.0 to fix the Tez commons-io CVEs.
  • OSV-17281: Increased Jackson to 2.18.6 to fix the Tez Jackson CVEs.
  • OSV-17377: Increased Netty to 4.1.133.Final (netty-bom) to fix the Tez Netty CVEs.

Trino

  • OSV-18944: Bumped io.netty:netty-bom to 4.1.135.Final to fix the netty-codec, netty-codec-http, and netty-codec-http2 CVEs.
  • OSV-18949: Bumped io.airlift:aircompressor to 2.0.3 to fix CVE-2025-67721.
  • OSV-18909: Bumped org.eclipse.jetty to 12.0.33 to fix CVE-2026-2332, CVE-2026-1605, CVE-2025-11143, and CVE-2025-5115.

Zeppelin

  • OSV-20277: Forced bcprov-jdk18on 1.84 to fix CVE-2026-5598.
  • OSV-20282: Pinned plexus-utils to 3.6.1 to fix CVE-2025-67030.
  • OSV-20296 | OSV-20297: Bumped mina-core from 2.0.27 to 2.0.31 to fix CVE-2026-41409 and CVE-2026-41635.
  • OSV-20337: Bumped jsoup from 1.11.3 to 1.14.2 to fix CVE-2021-37714.
  • OSV-20348: Bumped Jersey from 2.30 to 2.34 to fix CVE-2021-28168.

ZooKeeper

  • ODP-6883: Upgraded the commons-io version in ZooKeeper to fix CVE-2024-47554.
  • OSV-20483 | ODP-6200: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-19624: Upgraded Bouncy Castle to 1.84 to fix CVE-2026-5588.
  • OSV-20478: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
  • OSV-19624 | ZOOKEEPER-4827: Bumped the Bouncy Castle version from 1.75 to 1.78.
  • OSV-19624 | ZOOKEEPER-4719: Upgraded Bouncy Castle from jdk15on to jdk18on.