Skip to content

Revert "Update vertx top 4.5.24 to address CVE-2026-1002"#36

Merged
matthew1001 merged 1 commit into
kaleido-besu-release-25.8.0from
revert-25.8.0-CVE-2026-1002
Feb 3, 2026
Merged

Revert "Update vertx top 4.5.24 to address CVE-2026-1002"#36
matthew1001 merged 1 commit into
kaleido-besu-release-25.8.0from
revert-25.8.0-CVE-2026-1002

Conversation

@matthew1001

Copy link
Copy Markdown

PR description

This PR reverts #35 which was intended to upgrade vertx to version v4.5.24 to address CVE-2026-1002

There is a complication with the upgrade in that the new version of vertx pre-reqs an older version of netty than the one currently pulled in.

There is a draft OSS PR besu-eth#9645 which is currently being worked, which aims to upgrade vertx to a much newer version so that netty isn't downgraded, but that requires some additional Besu code changes.

This reverts commit c010b4a.

Signed-off-by: Matthew Whitehead <matthew.whitehead@kaleido.io>
@matthew1001 matthew1001 force-pushed the revert-25.8.0-CVE-2026-1002 branch from 777f7ad to eb76530 Compare February 3, 2026 10:10
@matthew1001 matthew1001 merged commit 4697275 into kaleido-besu-release-25.8.0 Feb 3, 2026
1 check passed
@matthew1001 matthew1001 deleted the revert-25.8.0-CVE-2026-1002 branch March 19, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants