Skip to content

Bump jetty dependencies to mitigate CVE-2026-10050 - #554

Open
Kimbsy wants to merge 1 commit into
ring-clojure:masterfrom
Kimbsy:CVE-2026-10050
Open

Kimbsy wants to merge 1 commit into
ring-clojure:masterfrom
Kimbsy:CVE-2026-10050

Conversation

@Kimbsy

@Kimbsy Kimbsy commented Sep 2, 2026 •

Copy link
Copy Markdown

Mitigates CVE-2026-10050

Just a patch version change needed.

@weavejester

Copy link
Copy Markdown
Member

Ring doesn't use Jetty's digest authentication. While it's useful to update Jetty's dependencies, it doesn't look like Ring is susceptible to CVE-2026-10050.

@Kimbsy

Kimbsy commented Sep 2, 2026

Copy link
Copy Markdown
Author

Appreciate the response 🙏

It got flagged by my project's vuln scanner, I can just flag it as a false positive. Happy to close this if it's just noise.

@darkleaf

Copy link
Copy Markdown

We ship a product that depends on Ring into audited environments, and it's hard to explain to a customer's security team why our tree still carries CVEs that upstream has already fixed.

If you're open to merging dependency bumps and cutting patch releases, we'd be glad to keep sending the PRs.

And if that's not something you want to take on - fair enough, it's open source - but we'd rather have an explicit no than silence, so we can plan around it.

@weavejester

Copy link
Copy Markdown
Member

We ship a product that depends on Ring into audited environments, and it's hard to explain to a customer's security team why our tree still carries CVEs that upstream has already fixed.

Why don't you include the updated Jetty packages in your deps? You don't need to wait on a Ring release, unless the Jetty changes are breaking and we need to update the adapter code.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants