7.5
CVSS CVSS_V3
Status
Impact
The identified vulnerability originates from the netty-codec-http2 dependency, which can be remediated by upgrading to version 4.1.124.Final. However, direct upgrades introduce cascading dependency resolution issues that cause build failures. Upstream must properly realign and update the dependency tree to ensure compatibility. Once this is addressed at the upstream level, we can safely apply the upgrade and remediate the vulnerability.
Status