7.5
CVSS CVSS_V3
Status
Impact
The AKHQ package has a dependency on micronaut-core, which in turns depends on the netty-code-http2 library affected by the CVE. The micronaut-core project has patched their source to include a fixed version of netty-codec-http2, see https://github.com/micronaut-projects/micronaut-core/commit/692e76250d77494389c535af22f4b8e112dc3ead However, micronaut-core has not released a version containing this fix, and therefore AKHQ cannot be updated to use it just yet.
Status