You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2026-85721: offline checker for org.asynchttpclient:async-http-client against all 21 repository-level advisories. The GitHub Advisory Database (Dependabot / OSV) lists only 4 of the 17 published on 2026-08-09 - 3.0.12, the version Dependabot recommends, still has 5 (2 high). Fixed in 3.0.13 / 2.16.1.
CVE-2026-45674 / CVE-2026-47691 / CVE-2026-45673: offline checker for DNS cache poisoning in io.netty:netty-resolver-dns - and whether your app actually uses that resolver. Spring WebClient on Reactor Netty uses it by default, although it is not in your pom.xml.
CVE-2026-59903 / CVE-2026-33870: offline checker for io.netty:netty-codec-http - its 14 CVEs plus 9 advisories Netty published on 2026-09-10 that the GitHub Advisory Database (Dependabot) does not list. 4.1.137.Final / 4.2.17.Final is no longer enough; upgrade to 4.1.138.Final / 4.2.18.Final.