Package
celeborn-0.6
Component
netty-codec-http
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is a copy shaded inside a prebuilt upstream assembly jar (ratis-thirdparty-misc / hadoop-client-runtime); the standalone dependency is updated, but the bundled copy cannot be replaced by a dependency pin. Pending an upstream release built against the fixed version.
Status