Fixed CVEs
This release resolves 895 security vulnerabilities (CVEs) identified across ODP platform components, representing a comprehensive security hardening initiative implemented during the upgrade from version 3.2.3.6-3 to 3.2.3.7-3.
Detailed List of CVEs Addressed
For detailed information about CVEs addressed in this release, see ODP 3.2.3.7-3 Acceldata Open-Source Data Platform CVE Fixes.
Summary of CVEs by component and severity level
You can see the summary of CVEs addressed by components and severity level.

CVE Fix Descriptions
Ambari
- OSV-17061: Upgraded hadoop-shaded-guava.
- OSV-16794 | 16780: Prevented old versions of Guava from being pulled in.
- OSV-16922: Upgraded the PostgreSQL driver to 42.7.11.
- OSV-17066 | 17019 | 17017 | 17076: Updated Spring to 5.3.34 and Spring Security to 5.8.16.
- OSV-17024 | 17025: Pinned snappy-java to 1.1.10.4.
- OSV-16928 | 12929 | 16931 | 16932: Updated mina-core.
- OSV-16786 | 16787: Bumped jackson-databind to 2.16.1 in Ambari Infra Solr.
- OSV-16812: Updated Derby to 10.14.3.0.
- OSV-17055 | 17053 | 16933 | 16924: Updated Netty to 4.1.42.Final.
- OSV-16924: Updated Netty and rebuilt fast-hdfs-resource.jar.
- OSV-16837: Bumped Netty to 4.1.133.Final for Ambari Infra.
- OSV-16803: Upgraded aws-java-sdk-core to 1.12.797.
- OSV-16973 | 16974 | 16975 | 16976 | 16977 | 16978: Fixed Log4j CVEs.
- OSV-16058: Bumped Netty to 4.1.132.Final.
Hadoop
- ODP-7103: Bumped moment.js to 2.29.4 in Hadoop to fix CVE-2022-24785 and CVE-2022-31129.
- OSV-19087 | ODP-2625 | HADOOP-19237 | HADOOP-17317: Upgraded to dnsjava 3.6.0 to resolve CVE-2024-25638.
- OSV-19068: Bumped okio to 1.17.6 to fix CVE-2023-3635.
- OSV-19046: Bumped Netty 4 to 4.1.135.Final to fix CVE-2026-44248.
- OSV-19052: Bumped Bouncy Castle to 1.84 to fix CVE-2026-558.
- OSV-19052: Bumped Netty 4 to 4.1.133.Final to fix CVE-2026-42587.
- OSV-19052: Bumped Jackson 2 to 2.18.6 to fix GHSA-72hv-8253-57qq.
- OSV-19052: Bumped commons-configuration2 to 2.15.0 to fix CVE-2026-45205.
Airflow
- OSV-24782 | OSV-24783 | OSV-24784: Bumped GitPython 3.1.41 -> 3.1.50 (CVE-2026-42284, CVE-2026-44243, GHSA-mv93-w799-cj2w)
- OSV-24781 | OSV-25028: Bumped Mako 1.3.0 -> 1.3.12 (CVE-2026-44307, CVE-2026-41205)
- OSV-24779 | OSV-24780: Bumped soupsieve 2.5 -> 2.8.4 (CVE-2026-49476, CVE-2026-49477)
- OSV-24749 | OSV-24750 | OSV-25026: Bumped tornado 6.4 -> 6.5.6 (CVE-2026-49853, CVE-2026-49855, CVE-2026-31958)
- OSV-24790 | OSV-25017 | OSV-25018 | OSV-25019 | OSV-25020 | OSV-25021: Bumped Authlib 1.3.0 -> 1.6.9 (CVE-2024-37568, CVE-2025-61920, CVE-2025-59420, CVE-2026-27962, CVE-2026-28490, CVE-2026-28498)
- OSV-24795: Bumped eventlet 0.35.2 -> 0.40.3 (CVE-2025-58068)
- OSV-24793: Bumped aiohttp 3.9.4 -> 3.13.3 (CVE-2025-69223)
- OSV-25027: Bumped azure-core 1.29.6 -> 1.38.0 (CVE-2026-21226)
- OSV-24764: Bumped snowflake-connector-python 3.6.0 -> 3.13.1 (CVE-2025-24793)
- OSV-24789: Bumped h11 0.14.0 -> 0.16.0 (CVE-2025-43859) and bumped httpcore/httpx to enable it.
- OSV-24797: Bumped redshift-connector 2.0.918 -> 2.1.7 (CVE-2025-5279)
- OSV-24793: Fixed aiohttp 3.13.3 transitive pins.
Cruise Control
- OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.
Cruise Control3
- OSV-20918: Bumped Log4j 2 to 2.25.4 to fix the reported vulnerability.
Druid
- OSV-18025: Increased aircompressor to 2.0.3 to fix the Druid aircompressor CVEs.
- OSV-18043: Increased the PostgreSQL version to fix the Druid PostgreSQL CVEs.
- OSV-17943: Pinned woodstox-core to 6.5.1 to fix the Druid woodstox-core CVEs.
- OSV-17940: Increased azure-sdk-bom to 1.2.25 (azure-identity 1.13.0) to fix the Druid azure-identity CVEs.
- OSV-18047: Increased plexus-utils to 3.6.1 to fix the Druid plexus-utils CVEs.
- OSV-17957: Increased jose4j to 0.9.6 to fix the Druid jose4j CVEs.
- OSV-18024: Increased the json-path version to fix the Druid json-path CVEs.
- OSV-18042: Increased the Netty version to fix the Druid Netty CVEs.
- OSV-18048: Increased the Log4j 2 version to fix the Druid Log4j CVEs.
- OSV-17937: Pinned jackson-databind to 2.12.7.1 to fix the Druid jackson-databind CVEs.
Flink
- OSV-18068: Increased the Log4j 2 version to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.
HBase
- CVE-2023-2976: Bumped Curator to 5.7.1 to fix the shaded Guava vulnerability.
- OSV-18177: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
- OSV-18087: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34480.
- OSV-18166: Updated dnsjava to 3.6.0 in the supplemental XML to reflect the version pulled from Hadoop.
- OSV-18095 | HBASE-30028: Bumped io.opentelemetry.javaagent:opentelemetry-javaagent.
- OSV-19098: Upgraded to hbase-thirdparty 4.1.13.
- OSV-19098: Bumped OpenTelemetry to 1.62.0 to fix CVE-2026-45292.
Hive
- OSV-17463: Upgraded Bouncy Castle and commons-compress to match Hadoop.
- OSV-17526: Upgraded the PostgreSQL driver to 42.7.11 to fix CVE-2026-42198.
- OSV-17489: Upgraded json-path to 2.10.0 to fix CVE-2024-57699.
- OSV-17489: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
- OSV-17489: Upgraded Log4j 2 to 2.25.4 to fix CVE-2026-34479.
- OSV-17378: Upgraded Netty to 4.1.135.Final.
Hue
- OSV-24672 | OSV-24671: Pinned cryptography 48.0.1 and pyOpenSSL 26.0.0 (GHSA-537c-gmf6-5ccf, CVE-2026-27459)
- OSV-24677: Pinned ujson 5.12.1 (CVE-2026-44660)
- OSV-24675 | OSV-24676: Pinned tornado 6.5.6 (CVE-2026-49853, CVE-2026-49855)
- OSV-24669: Pinned msgpack 1.2.1 (GHSA-6v7p-g79w-8964)
- OSV-24659: Pinned Twisted 26.4.0 (CVE-2026-42304)
- OSV-24658: Pinned urllib3 2.7.0 (CVE-2026-44432)
- OSV-24667 | OSV-24668: Upgraded Mako 1.2.3 -> 1.3.12 (CVE-2026-44307, CVE-2026-41205)
- OSV-24657: Upgraded Markdown 3.7 -> 3.8.1 (CVE-2025-69534)
Impala
- OSV-19104: Pinned opentelemetry-api to 1.62.0 to fix the Impala OpenTelemetry CVEs.
- OSV-19233: Pinned commons-io to 2.14.0 to fix the Impala commons-io CVEs.
- OSV-19206: Pinned okio to 1.17.6 to fix the Impala okio CVEs.
- OSV-19139: Increased commons-configuration2 to 2.15.0 to fix the Impala commons-configuration2 CVEs.
- OSV-19188: Increased the PostgreSQL JDBC version to 42.7.11 to fix the Impala PostgreSQL CVEs.
- OSV-19228: Increased Log4j 2 to 2.25.4 to fix the Impala Log4j 2 CVEs.
- OSV-19138: Increased Jackson to 2.18.6 to fix the Impala Jackson CVEs.
- OSV-19108: Increased Netty to 4.1.133.Final (netty-bom) to fix the Impala Netty CVEs.
JupyterHub
- OSV-24809 | GHSA-537c-gmf6-5ccf: Bumped cryptography to 48.0.1.
- OSV-24810 | CVE-2025-66034: Replaced the fonttools fork with upstream 4.60.2.
- OSV-24806 | CVE-2025-43859: Bumped h11 to 0.16.0.
- OSV-24804 | CVE-2025-30167: Bumped jupyter_core to 5.8.1.
- OSV-24816 | OSV-25035 | CVE-2026-44307 | CVE-2026-41205: Bumped Mako to 1.3.12.
- OSV-24802 | OSV-24803 | CVE-2026-33079 | CVE-2026-49851: Bumped mistune to 3.3.0.
- OSV-24811 | OSV-24812 | OSV-24813 | OSV-24814 | OSV-24815 | OSV-25034 | CVE-2026-25990 | CVE-2026-40192 | CVE-2026-42311 | CVE-2026-59198 | CVE-2026-59204 | CVE-2026-54058: Bumped pillow to 12.3.0.
- OSV-24799 | OSV-24800 | CVE-2026-49476 | CVE-2026-49477: Bumped soupsieve to 2.8.4.
- OSV-25033 | OSV-24807 | OSV-24808 | CVE-2026-31958 | CVE-2026-49853 | CVE-2026-49855: Bumped tornado to 6.5.6.
- OSV-24801 | CVE-2026-44432: Bumped urllib3 to 2.7.0.
- OSV-25029 | OSV-25030 | OSV-25031 | OSV-25032 | CVE-2026-40171 | CVE-2026-42557: Bumped jupyterlab to 4.5.7 and notebook to 7.5.6.
Kafka
- OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
- OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
- KAFKA-19336: Upgraded Jackson to 2.19.0.
Kafka3
- OSV-18241: Upgraded plexus-utils to 1.6.1 to fix CVE-2025-67030.
- OSV-18214: Upgraded Netty to 4.1.133 to fix CVE-2026-42583.
- KAFKA-19336: Upgraded Jackson to 2.19.0.
Knox
- OSV-17552: Removed the duplicate Jackson version property and upgraded Jackson to 2.18.6 to resolve GHSA-72hv-8253-57qq.
- OSV-17549: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
- OSV-17544: Upgraded nimbus-jose-jwt to 9.37.4 to fix CVE-2025-53864.
- OSV-17548: Upgraded commons-io to 2.14.0 and forbiddenapis to 3.6 to fix CVE-2024-47554.
- OSV-17545: Bumped jakarta.mail from 1.6.5 to 1.6.8 to address CVE-2025-7962.
- OSV-17542 | 17541 | 17540 | 17539 | 17538: Bumped Apache Log4j to 2.25.4 to fix CVE-2026-34479, CVE-2026-34477, CVE-2026-34480, CVE-2026-34481, and CVE-2025-68161.
- OSV-17543: Upgraded PostgreSQL to 42.7.11 to fix CVE-2026-42198.
- OSV-17640: Upgraded spring.version to 5.3.39 to resolve CVE-2024-38808.
- OSV-17559: Upgraded spring-vault-core to 2.3.3 to fix CVE-2023-20859.
- OSV-17633 | 17632 | 17631 | 17566: Bumped Apache Shiro to 1.13.0 to address CVE-2023-46749, CVE-2023-46750, and CVE-2026-23903.
- OSV-17570: Upgraded mina-core to 2.0.28 to fix CVE-2026-41409.
- OSV-17573: Bumped org.apache.santuario:xmlsec from 2.1.8 to 2.2.6 to fix CVE-2023-44483.
- KNOX-3307: Upgraded jackson-core to 2.18.6.
- Bumped org.apache.commons:commons-configuration2 from 2.10.1 to 2.15.0.
- KNOX-3059: Upgraded commons-configuration2 to 2.10.1.
- OSV-17565: Bumped org.apache.commons:commons-lang3 from 3.11.0 to 3.18.0 to fix CVE-2025-48924.
- OSV-17634 | 17635: Upgraded commons-compress from 1.21 to 1.26.0 to fix CVE-2024-26308 and CVE-2024-25710.
- OSV-17638 | 17637 | 17564 | 17563 | 17562 | 17561 | 17560: Upgraded Bouncy Castle to jdk18on 1.84 to address multiple CVEs.
- OSV-17559: Pinned amqp-client to 5.18.0 to fix CVE-2023-46120.
Kudu
- OSV-17691: Upgraded Log4j to 2.25.4.
- OSV-17512: Upgraded Netty to 4.1.135.Final to fix CVE-2026-42583.
NiFi / NiFi Registry
- OSV-17883: Excluded commons-beanutils to resolve the reported CVEs.
- ODP-6966: Used ${odp.release.version} for nifi-standard-shared-bom parent references.
- OSV-17902 | 17890 | 17888 | 17884: Bumped io.netty to 4.1.135.Final.
Oozie
- OSV-18618: Backported OOZIE-3655 to upgrade jdom to jdom2 2.0.6.1 and fix CVE-2021-33813.
- OSV-18467: Removed the pig module from the Oozie sharelib to exclude Pig package CVEs.
- OSV-18465 | 18464 | 18463 | 18462 | 18461: Excluded the unwanted Jetty runner to address critical mina-core CVEs.
- OSV-18622: Fixed CVE-2026-27727 from the transitive dependency mchange-commons-java.
- OSV-18611: Fixed CVE-2026-27830 from the transitive dependency c3p0.
- OSV-18679: Fixed CVE-2020-10683 from the transitive dependency dom4j 1.6.1.
Ozone
- ODP-7371: Upgraded commons-configuration2 to 2.15.0 to match the version in the stack.
- OSV-18758: Bumped grpc.protobuf-compile.version to 3.25.5.
- OSV-18712: Bumped Log4j 2 to 2.25.4.
Phoenix
- Upgraded commons-beanutils to 1.11.0 to fix CVE-2025-48734.
- Matched the Jackson version with HBase to fix CVE-2025-52999.
- OSV-20133: Bumped Log4j 2 to 2.25.4 to fix CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.
Pinot
- OSV-18866: Increased the Netty version to fix CVE-2026-42579.
- OSV-18862: Increased the Log4j 2 version to fix CVE-2026-34479.
- OSV-18787: Increased the commons-lang3 version to fix CVE-2025-48924.
- OSV-18772: Increased the commons-configuration2 version to fix CVE-2026-45205.
- OSV-18793: Increased the nimbus-jose-jwt version to fix CVE-2025-53864.
- OSV-18858: Increased the aircompressor version to fix CVE-2025-67721.
- OSV-18860: Increased the async-http-client version to fix CVE-2026-45300.
- OSV-18776: Stripped the Jackson 2.4.0 copy embedded in htrace-core4 from the pinot-orc and pinot-parquet shaded jars.
- OSV-18796: Bumped Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
Ranger
- OSV-19463: Upgraded netty-all to 4.1.133.Final to address CVE-2026-42587 and other CVEs.
- OSV-19365: Upgraded Tomcat to 9.0.118 to mitigate CVE-2026-43515 and multiple other CVEs.
- OSV-19554: Bumped hbase-thirdparty to 4.1.13 to mitigate multiple Netty CVEs.
- Applied the OSV fixes on Ranger that address the HBase CVEs from 3.2.3.6-2.
- OSV-19531: Bumped aircompressor to 2.0.3 to fix CVE-2025-67721.
Schema Registry
- OSV-20187 | OSV-20206: Bumped the PostgreSQL driver and plexus-utils.
Spark3
- ODP-7140: Bumped the wildfly-openssl version in Spark 3.5.5 to fix CVE-2019-14887.
- OSV-12356: Fixed CVEs from gson, okhttp, and jdom2.
- OSV-19685: Increased the Jackson version (CVE unspecified).
- OSV-19714: Increased the Netty version to fix CVE-2026-42587.
- OSV-19741: Increased the Log4j 2 version to fix CVE-2026-34479.
- OSV-19721: Increased the lz4-java version to fix CVE-2025-12183.
- OSV-19743: Increased the aircompressor version to fix CVE-2025-67721.
Tez
- OSV-17368: Pinned okio to 1.17.6 to fix the Tez okio CVEs.
- OSV-17311: Pinned jdom2 to 2.0.6.1 to fix the Tez jdom2 CVEs.
- OSV-17283: Pinned commons-configuration2 to 2.15.0 to fix the Tez commons-configuration2 CVEs.
- OSV-17305: Increased async-http-client to 2.15.0 to fix the Tez async-http-client CVEs.
- OSV-17290: Increased commons-io to 2.14.0 to fix the Tez commons-io CVEs.
- OSV-17281: Increased Jackson to 2.18.6 to fix the Tez Jackson CVEs.
- OSV-17377: Increased Netty to 4.1.133.Final (netty-bom) to fix the Tez Netty CVEs.
Trino
- OSV-18944: Bumped io.netty:netty-bom to 4.1.135.Final to fix the netty-codec, netty-codec-http, and netty-codec-http2 CVEs.
- OSV-18949: Bumped io.airlift:aircompressor to 2.0.3 to fix CVE-2025-67721.
- OSV-18909: Bumped org.eclipse.jetty to 12.0.33 to fix CVE-2026-2332, CVE-2026-1605, CVE-2025-11143, and CVE-2025-5115.
Zeppelin
- OSV-20277: Forced bcprov-jdk18on 1.84 to fix CVE-2026-5598.
- OSV-20282: Pinned plexus-utils to 3.6.1 to fix CVE-2025-67030.
- OSV-20296 | OSV-20297: Bumped mina-core from 2.0.27 to 2.0.31 to fix CVE-2026-41409 and CVE-2026-41635.
- OSV-20337: Bumped jsoup from 1.11.3 to 1.14.2 to fix CVE-2021-37714.
- OSV-20348: Bumped Jersey from 2.30 to 2.34 to fix CVE-2021-28168.
ZooKeeper
- ODP-6883: Upgraded the commons-io version in ZooKeeper to fix CVE-2024-47554.
- OSV-20483 | ODP-6200: Upgraded Jackson to 2.18.6 to fix GHSA-72hv-8253-57qq.
- OSV-19624: Upgraded Bouncy Castle to 1.84 to fix CVE-2026-5588.
- OSV-20478: Upgraded Netty to 4.1.133.Final to fix CVE-2026-42583.
- OSV-19624 | ZOOKEEPER-4827: Bumped the Bouncy Castle version from 1.75 to 1.78.
- OSV-19624 | ZOOKEEPER-4719: Upgraded Bouncy Castle from jdk15on to jdk18on.
