Conversation
|
Ring doesn't use Jetty's digest authentication. While it's useful to update Jetty's dependencies, it doesn't look like Ring is susceptible to CVE-2026-10050. |
|
Appreciate the response 🙏 It got flagged by my project's vuln scanner, I can just flag it as a false positive. Happy to close this if it's just noise. |
|
We ship a product that depends on Ring into audited environments, and it's hard to explain to a customer's security team why our tree still carries CVEs that upstream has already fixed. If you're open to merging dependency bumps and cutting patch releases, we'd be glad to keep sending the PRs. And if that's not something you want to take on - fair enough, it's open source - but we'd rather have an explicit no than silence, so we can plan around it. |
Why don't you include the updated Jetty packages in your deps? You don't need to wait on a Ring release, unless the Jetty changes are breaking and we need to update the adapter code. |
Mitigates CVE-2026-10050
Just a patch version change needed.