Acceldata
ODP

Fixed CVEs

This release resolves 895 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.2.3.6-3 to 3.2.3.7-3.


Detailed List of CVEs Addressed

For detailed information about CVEs addressed in this release, see ODP 3.2.3.7-3 Acceldata Open-Source Data Platform CVE Fixes.


Summary of CVEs by component and severity level

You can see the summary of CVEs addressed by components and severity level.

Preserved image


CVE Fix Descriptions

Ambari

  • OSV-17061: Upgraded hadoop-shaded-guava.
  • OSV-16794 | 16780: Prevented old versions of Guava from being pulled in.
  • OSV-16922: Upgraded the PostgreSQL driver to 42.7.11.
  • OSV-17066 | 17019 | 17017 | 17076: Updated Spring to 5.3.34 and Spring Security to 5.8.16.
  • OSV-17024 | 17025: Pinned snappy-java to 1.1.10.4.
  • OSV-16928 | 12929 | 16931 | 16932: Updated mina-core.
  • OSV-16786 | 16787: Bumped jackson-databind to 2.16.1 in Ambari Infra Solr.
  • OSV-16812: Updated Derby to 10.14.3.0.
  • OSV-17055 | 17053 | 16933 | 16924: Updated Netty to 4.1.42.Final.
  • OSV-16924: Updated Netty and rebuilt fast-hdfs-resource.jar.
  • OSV-16837: Bumped Netty to 4.1.133.Final for Ambari Infra.
  • OSV-16803: Upgraded aws-java-sdk-core to 1.12.797.
  • OSV-16973 | 16974 | 16975 | 16976 | 16977 | 16978: Fixed Log4j CVEs.
  • OSV-16058: Bumped Netty to 4.1.132.Final.

Hadoop

  • ODP-7103: Bumped moment.js to 2.29.4 in Hadoop to fix CVE-2022-24785 and CVE-2022-31129.
  • OSV-19087 | ODP-2625 | HADOOP-19237 | HADOOP-17317: Upgraded to dnsjava 3.6.0 to resolve CVE-2024-25638.
  • OSV-19068: Bumped okio to 1.17.6 to fix CVE-2023-3635.
  • OSV-19046: Bumped Netty 4 to 4.1.135.Final to fix CVE-2026-44248.
  • OSV-19052: Bumped Bouncy Castle to 1.84 to fix CVE-2026-558.
  • OSV-19052: Bumped Netty 4 to 4.1.133.Final to fix CVE-2026-42587.
  • OSV-19052: Bumped Jackson 2 to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-19052: Bumped commons-configuration2 to 2.15.0 to fix CVE-2026-45205.

Airflow

  • OSV-24782 | OSV-24783 | OSV-24784: Bumped GitPython 3.1.41 -> 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w)
  • OSV-24781 | OSV-25028: Bumped Mako 1.3.0 -> 1.3.12 (CVE-2026-44307, CVE-2026-41205)
  • OSV-24779 | OSV-24780: Bumped soupsieve 2.5 -> 2.8.4 (CVE-2026-49476, CVE-2026-49477)
  • OSV-24749 | OSV-24750 | OSV-25026: Bumped tornado 6.4 -> 6.5.6 (CVE-2026-49853, CVE-2026-49855, CVE-2026-31958)
  • OSV-24790 | OSV-25017 | OSV-25018 | OSV-25019 | OSV-25020 | OSV-25021: Bumped Authlib 1.3.0 -> 1.6.9 (CVE-2024-37568, CVE-2025-61920, CVE-2025-59420, CVE-2026-27962, CVE-2026-28490, CVE-2026-28498)
  • OSV-24795: Bumped eventlet 0.35.2 -> 0.40.3 (CVE-2025-58068)
  • OSV-24793: Bumped aiohttp 3.9.4 -> 3.13.3 (CVE-2025-69223)
  • OSV-25027: Bumped azure-core 1.29.6 -> 1.38.0 (CVE-2026-21226)
  • OSV-24764: Bumped snowflake-connector-python 3.6.0 -> 3.13.1 (CVE-2025-24793)
  • OSV-24789: Bumped h11 0.14.0 -> 0.16.0 (CVE-2025-43859) and bumped httpcore/httpx to enable it.
  • OSV-24797: Bumped redshift-connector 2.0.918 -> 2.1.7 (CVE-2025-5279)
  • OSV-24793: Fixed aiohttp 3.13.3 transitive pins.

Cruise Control

  • OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.

Cruise Control3

  • OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.

Druid

  • OSV-18025: Increased aircompressor to 2.0.3 to fix the Druid aircompressor CVEs.
  • OSV-18043: Increased the PostgreSQL version to fix the Druid PostgreSQL CVEs.
  • OSV-17943: Pinned woodstox-core to 6.5.1 to fix the Druid woodstox-core CVEs.
  • OSV-17940: Increased azure-sdk-bom to 1.2.25 (azure-identity 1.13.0) to fix the Druid azure-identity CVEs.
  • OSV-18047: Increased plexus-utils to 3.6.1 to fix the Druid plexus-utils CVEs.
  • OSV-17957: Increased jose4j to 0.9.6 to fix the Druid jose4j CVEs.
  • OSV-18024: Increased the json-path version to fix the Druid json-path CVEs.
  • OSV-18042: Increased the Netty version to fix the Druid Netty CVEs.
  • OSV-18048: Increased the Log4j 2 version to fix the Druid Log4j CVEs.
  • OSV-17937: Pinned jackson-databind to 2.12.7.1 to fix the Druid jackson-databind CVEs.

Flink

  • OSV-18068: Increased the Log4j 2 version to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.

HBase

  • CVE-2023-2976: Bumped Curator to 5.7.1 to fix the shaded Guava vulnerability.
  • OSV-18177: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
  • OSV-18087: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34480.
  • OSV-18166: Updated dnsjava to 3.6.0 in the supplemental XML to reflect the version pulled from Hadoop.
  • OSV-18095 | HBASE-30028: Bumped io.opentelemetry.javaagent:opentelemetry-javaagent.
  • OSV-19098: Upgraded to hbase-thirdparty 4.1.13.
  • OSV-19098: Bumped OpenTelemetry to 1.62.0 to fix CVE-2026-45292.

Hive

  • OSV-17463: Upgraded Bouncy Castle and commons-compress to match Hadoop.
  • OSV-17526: Upgraded the PostgreSQL driver to 42.7.11 to fix CVE-2026-42198.
  • OSV-17489: Upgraded json-path to 2.10.0 to fix CVE-2024-57699.
  • OSV-17489: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-17489: Upgraded Log4j 2 to 2.25.4 to fix CVE-2026-34479.
  • OSV-17378: Upgraded Netty to 4.1.135.Final.

Hue

  • OSV-24672 | OSV-24671: Pinned cryptography 48.0.1 and pyOpenSSL 26.0.0 (GHSA-537c-gmf6-5ccf, CVE-2026-27459)
  • OSV-24677: Pinned ujson 5.12.1 (CVE-2026-44660)
  • OSV-24675 | OSV-24676: Pinned tornado 6.5.6 (CVE-2026-49853, CVE-2026-49855)
  • OSV-24669: Pinned msgpack 1.2.1 (GHSA-6v7p-g79w-8964)
  • OSV-24659: Pinned Twisted 26.4.0 (CVE-2026-42304)
  • OSV-24658: Pinned urllib3 2.7.0 (CVE-2026-44432)
  • OSV-24667 | OSV-24668: Upgraded Mako 1.2.3 -> 1.3.12 (CVE-2026-44307, CVE-2026-41205)
  • OSV-24657: Upgraded Markdown 3.7 -> 3.8.1 (CVE-2025-69534)

Impala

  • OSV-19104: Pinned opentelemetry-api to 1.62.0 to fix the Impala OpenTelemetry CVEs.
  • OSV-19233: Pinned commons-io to 2.14.0 to fix the Impala commons-io CVEs.
  • OSV-19206: Pinned okio to 1.17.6 to fix the Impala okio CVEs.
  • OSV-19139: Increased commons-configuration2 to 2.15.0 to fix the Impala commons-configuration2 CVEs.
  • OSV-19188: Increased the PostgreSQL JDBC version to 42.7.11 to fix the Impala PostgreSQL CVEs.
  • OSV-19228: Increased Log4j 2 to 2.25.4 to fix the Impala Log4j 2 CVEs.
  • OSV-19138: Increased Jackson to 2.18.6 to fix the Impala Jackson CVEs.
  • OSV-19108: Increased Netty to 4.1.133.Final (netty-bom) to fix the Impala Netty CVEs.

JupyterHub

  • OSV-24809 | GHSA-537c-gmf6-5ccf: Bumped cryptography to 48.0.1.
  • OSV-24810 | CVE-2025-66034: Replaced the fonttools fork with upstream 4.60.2.
  • OSV-24806 | CVE-2025-43859: Bumped h11 to 0.16.0.
  • OSV-24804 | CVE-2025-30167: Bumped jupyter_core to 5.8.1.
  • OSV-24816 | OSV-25035 | CVE-2026-44307 | CVE-2026-41205: Bumped Mako to 1.3.12.
  • OSV-24802 | OSV-24803 | CVE-2026-33079 | CVE-2026-49851: Bumped mistune to 3.3.0.
  • OSV-24811 | OSV-24812 | OSV-24813 | OSV-24814 | OSV-24815 | OSV-25034 | CVE-2026-25990 | CVE-2026-40192 | CVE-2026-42311 | CVE-2026-59198 | CVE-2026-59204 | CVE-2026-54058: Bumped pillow to 12.3.0.
  • OSV-24799 | OSV-24800 | CVE-2026-49476 | CVE-2026-49477: Bumped soupsieve to 2.8.4.
  • OSV-25033 | OSV-24807 | OSV-24808 | CVE-2026-31958 | CVE-2026-49853 | CVE-2026-49855: Bumped tornado to 6.5.6.
  • OSV-24801 | CVE-2026-44432: Bumped urllib3 to 2.7.0.
  • OSV-25029 | OSV-25030 | OSV-25031 | OSV-25032 | CVE-2026-40171 | CVE-2026-42557: Bumped jupyterlab to 4.5.7 and notebook to 7.5.6.

Kafka

  • OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
  • OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
  • KAFKA-19336: Upgraded Jackson to 2.19.0.

Kafka3

  • OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
  • OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
  • KAFKA-19336: Upgraded Jackson to 2.19.0.

Knox

  • OSV-17552: Removed the duplicate Jackson version property and upgraded Jackson to 2.18.6 to resolve GHSA-72hv-8253-57qq.
  • OSV-17549: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
  • OSV-17544: Upgraded nimbus-jose-jwt to 9.37.4 to fix CVE-2025-53864.
  • OSV-17548: Upgraded commons-io to 2.14.0 and forbiddenapis to 3.6 to fix CVE-2024-47554.
  • OSV-17545: Bumped jakarta.mail from 1.6.5 to 1.6.8 to address CVE-2025-7962.
  • OSV-17542 | 17541 | 17540 | 17539 | 17538: Bumped Apache Log4j to 2.25.4 to fix CVE-2026-34479, CVE-2026-34477, CVE-2026-34480, CVE-2026-34481, and CVE-2025-68161.
  • OSV-17543: Upgraded PostgreSQL to 42.7.11 to fix CVE-2026-42198.
  • OSV-17640: Upgraded spring.version to 5.3.39 to resolve CVE-2024-38808.
  • OSV-17559: Upgraded spring-vault-core to 2.3.3 to fix CVE-2023-20859.
  • OSV-17633 | 17632 | 17631 | 17566: Bumped Apache Shiro to 1.13.0 to address CVE-2023-46749, CVE-2023-46750, and CVE-2026-23903.
  • OSV-17570: Upgraded mina-core to 2.0.28 to fix CVE-2026-41409.
  • OSV-17573: Bumped org.apache.santuario:xmlsec from 2.1.8 to 2.2.6 to fix CVE-2023-44483.
  • KNOX-3307: Upgraded jackson-core to 2.18.6.
  • Bumped org.apache.commons:commons-configuration2 from 2.10.1 to 2.15.0.
  • KNOX-3059: Upgraded commons-configuration2 to 2.10.1.
  • OSV-17565: Bumped org.apache.commons:commons-lang3 from 3.11.0 to 3.18.0 to fix CVE-2025-48924.
  • OSV-17634 | 17635: Upgraded commons-compress from 1.21 to 1.26.0 to fix CVE-2024-26308 and CVE-2024-25710.
  • OSV-17638 | 17637 | 17564 | 17563 | 17562 | 17561 | 17560: Upgraded Bouncy Castle to jdk18on 1.84 to address multiple CVEs.
  • OSV-17559: Pinned amqp-client to 5.18.0 to fix CVE-2023-46120.

Kudu

  • OSV-17691: Upgraded Log4j to 2.25.4.
  • OSV-17512: Upgraded Netty to 4.1.135.Final to fix CVE-2026-42583.

NiFi / NiFi Registry

  • OSV-17883: Excluded commons-beanutils to resolve the reported CVEs.
  • ODP-6966: Used ${odp.release.version} for nifi-standard-shared-bom parent references.
  • OSV-17902 | 17890 | 17888 | 17884: Bumped io.netty to 4.1.135.Final.

Oozie

  • OSV-18618: Backported OOZIE-3655 to upgrade jdom to jdom2 2.0.6.1 and fix CVE-2021-33813.
  • OSV-18467: Removed the pig module from the Oozie sharelib to exclude Pig package CVEs.
  • OSV-18465 | 18464 | 18463 | 18462 | 18461: Excluded the unwanted Jetty runner to address critical mina-core CVEs.
  • OSV-18622: Fixed CVE-2026-27727 from the transitive dependency mchange-commons-java.
  • OSV-18611: Fixed CVE-2026-27830 from the transitive dependency c3p0.
  • OSV-18679: Fixed CVE-2020-10683 from the transitive dependency dom4j 1.6.1.

Ozone

  • ODP-7371: Upgraded commons-configuration2 to 2.15.0 to match the version in the stack.
  • OSV-18758: Bumped grpc.protobuf-compile.version to 3.25.5.
  • OSV-18712: Bumped Log4j 2 to 2.25.4.

Phoenix

  • Upgraded commons-beanutils to 1.11.0 to fix CVE-2025-48734.
  • Matched the Jackson version with HBase to fix CVE-2025-52999.
  • OSV-20133: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.

Pinot

  • OSV-18866: Increased the Netty version to fix CVE-2026-42579.
  • OSV-18862: Increased the Log4j 2 version to fix CVE-2026-34479.
  • OSV-18787: Increased the commons-lang3 version to fix CVE-2025-48924.
  • OSV-18772: Increased the commons-configuration2 version to fix CVE-2026-45205.
  • OSV-18793: Increased the nimbus-jose-jwt version to fix CVE-2025-53864.
  • OSV-18858: Increased the aircompressor version to fix CVE-2025-67721.
  • OSV-18860: Increased the async-http-client version to fix CVE-2026-45300.
  • OSV-18776: Stripped the Jackson 2.4.0 copy embedded in htrace-core4 from the pinot-orc and pinot-parquet shaded jars.
  • OSV-18796: Bumped Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.

Ranger

  • OSV-19463: Upgraded netty-all to 4.1.133.Final to address CVE-2026-42587 and other CVEs.
  • OSV-19365: Upgraded Tomcat to 9.0.118 to mitigate CVE-2026-43515 and multiple other CVEs.
  • OSV-19554: Bumped hbase-thirdparty to 4.1.13 to mitigate multiple Netty CVEs.
  • Applied the OSV fixes on Ranger that address the HBase CVEs from 3.2.3.6-2.
  • OSV-19531: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.

Schema Registry

  • OSV-20187 | OSV-20206: Bumped the PostgreSQL driver and plexus-utils.

Spark3

  • ODP-7140: Bumped the wildfly-openssl version in Spark 3.5.5 to fix CVE-2019-14887.
  • OSV-12356: Fixed CVEs from gson, okhttp, and jdom2.
  • OSV-19685: Increased the Jackson version (CVE unspecified).
  • OSV-19714: Increased the Netty version to fix CVE-2026-42587.
  • OSV-19741: Increased the Log4j 2 version to fix CVE-2026-34479.
  • OSV-19721: Increased the lz4-java version to fix CVE-2025-12183.
  • OSV-19743: Increased the aircompressor version to fix CVE-2025-67721.

Tez

  • OSV-17368: Pinned okio to 1.17.6 to fix the Tez okio CVEs.
  • OSV-17311: Pinned jdom2 to 2.0.6.1 to fix the Tez jdom2 CVEs.
  • OSV-17283: Pinned commons-configuration2 to 2.15.0 to fix the Tez commons-configuration2 CVEs.
  • OSV-17305: Increased async-http-client to 2.15.0 to fix the Tez async-http-client CVEs.
  • OSV-17290: Increased commons-io to 2.14.0 to fix the Tez commons-io CVEs.
  • OSV-17281: Increased Jackson to 2.18.6 to fix the Tez Jackson CVEs.
  • OSV-17377: Increased Netty to 4.1.133.Final (netty-bom) to fix the Tez Netty CVEs.

Trino

  • OSV-18944: Bumped io.netty:netty-bom to 4.1.135.Final to fix the netty-codec, netty-codec-http, and netty-codec-http2 CVEs.
  • OSV-18949: Bumped io.airlift:aircompressor to 2.0.3 to fix CVE-2025-67721.
  • OSV-18909: Bumped org.eclipse.jetty to 12.0.33 to fix CVE-2026-2332, CVE-2026-1605, CVE-2025-11143, and CVE-2025-5115.

Zeppelin

  • OSV-20277: Forced bcprov-jdk18on 1.84 to fix CVE-2026-5598.
  • OSV-20282: Pinned plexus-utils to 3.6.1 to fix CVE-2025-67030.
  • OSV-20296 | OSV-20297: Bumped mina-core from 2.0.27 to 2.0.31 to fix CVE-2026-41409 and CVE-2026-41635.
  • OSV-20337: Bumped jsoup from 1.11.3 to 1.14.2 to fix CVE-2021-37714.
  • OSV-20348: Bumped Jersey from 2.30 to 2.34 to fix CVE-2021-28168.

ZooKeeper

  • ODP-6883: Upgraded the commons-io version in ZooKeeper to fix CVE-2024-47554.
  • OSV-20483 | ODP-6200: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
  • OSV-19624: Upgraded Bouncy Castle to 1.84 to fix CVE-2026-5588.
  • OSV-20478: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
  • OSV-19624 | ZOOKEEPER-4827: Bumped the Bouncy Castle version from 1.75 to 1.78.
  • OSV-19624 | ZOOKEEPER-4719: Upgraded Bouncy Castle from jdk15on to jdk18on.