Package
flyway
Component
netty-codec-http2
Latest update
Fixed version
13.0.0-r1
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
13.0.0-r1Status
Impact
CVE-2026-50560 is detected in netty-codec-http2 4.2.14.Final, shaded/relocated to com/couchbase/client/core/deps/io/netty inside couchbase core-io-3.12.0.jar, the latest upstream core-io release (no 3.12.1 exists). The fix requires netty 4.2.15.Final, but couchbase has not released a core-io build bundling it. As a pre-built fat jar the embedded dependency cannot be updated via a melange pin; requires a new upstream couchbase release.
Status
Status