Skip to content

More SchemaFactory hardenings (CVE-2026-49875)#3236

Open
eballetbaz wants to merge 1 commit into
apache:3.6.x-fixesfrom
eballetbaz:3.6.x-fixes
Open

More SchemaFactory hardenings (CVE-2026-49875)#3236
eballetbaz wants to merge 1 commit into
apache:3.6.x-fixesfrom
eballetbaz:3.6.x-fixes

Conversation

@eballetbaz

Copy link
Copy Markdown

More SchemaFactory hardenings

This is a cherry picked from commit 7cfa2fb to fix critical CVE CVE-2026-49875

I know that 3.6 is EOL but since this CVE is rated 9.8 and since the fix is very easy please consider to include it

Migration from 3.6 to 4 is a huge step and cannot be quickly achieved by everyone.
Considering the criticity of the CVE is would be nice to protected all existing systems

* More SchemaFactory hardenings

* Address code review comments

(cherry picked from commit 7cfa2fb)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants