GraphKnowledge

graph-lakehouse

Patched Vulnerabilities

This page provides information about the common security vulnerabilities that were patched in Graph Lakehouse.

Graph Lakehouse Releases

|

Graph Lakehouse 2026.1 DB 3.4.0

  • CVE-2025-48734: The Apache Commons BeanUtils dependency was updated to remediate a potential Improper Access Control vulnerability.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.
  • CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
  • CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.
  • CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
  • CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
  • GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2026-3805: curl has been updated to address an issue in which it accesses memory that has already been freed when handling a second server message block (SMB) request to the same host.
  • CVE-2025-53864: Upgraded com.nimbusds:nimbus-jose-jwt to address medium-severity vulnerabilities.
  • CVE-2026-33870, CVE-2026-33871: The Netty library dependency was updated to version 4.1.132.Final to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2026-33186: The golang /grpc package was updated to remediate this potential critical security vulnerability.

Graph Lakehouse 2026.0 DB 3.3.1

  • CVE-2025-68121, CVE-2025-61726, CVE-2025-681728, and CVE-2025-61730: The Go standard library was updated to mitigate critical security vulnerabilities including DoS attacks, memory exhaustion, and unauthorized session resumption.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
  • CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
  • CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
  • CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.

Graph Lakehouse 2026.0 DB 3.3.0

  • CVE-2025-46762: The org.apache.parquet dependency was updated to remediate this vulnerability.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-32989, CVE-2025-32990, CVE-2025-32988, CVE-2025-6395: The GnuTLS library was updated to remediate various potential vulnerabilities related to this dependency.

Graph Lakehouse 2025.0 DB 3.2.2

  • CVE-2025-22870 : The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-27553 : The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-22871 : The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872 : The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-1948 : The Eclipse Jetty dependency was updated to remediate this vulnerability in the Jetty HTTP/2 server.

Graph Lakehouse 2025.0 DB 3.2.1

Graph Lakehouse 2025.0 DB 3.2.0

Graph Lakehouse 3.1.9

  • GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
  • CVE-2026-25646: The libpng library was updated to remediate this potential out-of-bounds read vulnerability.
  • CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
  • CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
  • CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-54988: The Apache Tika package was updated to remediate this potential security vulnerability.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.

Graph Lakehouse 3.1.8

  • CVE-2024-45336: The golang net/http package dependency was updated to remediate this vulnerability.
  • CVE-2024-45341: The golang crypto/x509 package dependency was updated to remediate this vulnerability.
  • CVE-2025-22870: The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-27553: The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-48734: The Apache commons dependency was updated to remediate this potential Improper Access Control vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-47907: The golang database/sql package dependency was updated to remediate vulnerability.
  • CVE-2025-4674: The golang package was updated to remediate issues related to unexpected code execution.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-5115: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential HTTP/2 MadeYouReset DoS vulnerability.

Graph Lakehouse 3.1.7

Graph Lakehouse 3.1.6

  • GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XML external entity (XXE) vulnerability in the jetty XmlParser.
  • CVE-2024-43382: The Snowflake JDBC driver dependency was updated to remediate this incorrect security setting vulnerability.
  • GHSA-w32m-9786-jp63, CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

Graph Lakehouse 3.1.5

  • CVE-2024-47554: The Apache Commons IO dependency of the Neptune extension library of Graph Lakehouse DB was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-48910: The DOMPurify dependency was upgraded to version 2.4.2 to remediate this Prototype Pollution vulnerability.

Graph Lakehouse 3.1.4

  • CVE-2024-34156: The encoding/gob package dependency was updated to remediate this stack exhaustion vulnerability (Go upgraded to version 1.23.1).
  • CVE-2024-7254: The Protocol Buffers parser dependency was updated to remediate this improper input validation vulnerability.
  • CVE-2024-45801: The DOMPurify dependency was upgraded to remediate this XSS attack vulnerability.
  • CVE-2024-43591: The Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability was remediated.
  • CVE-2024-2398: The libcurl dependency was upgraded from version 8.1.2 to 8.10.1 to further remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-47554: The Apache Commons IO dependency was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-8184: The Eclipse jetty dependency was updated to version 12.0.12 to remediate a potential remote Denial of Service (DoS) attack vulnerability.

Graph Lakehouse 3.1.3

  • CVE-2024-2398: The libcurl dependency was updated to remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-6345: The pypa/setuptools dependency was upgraded to remediate this vulnerability.

Graph Lakehouse 3.1.2

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).
  • CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
  • CVE-2023-6597: The CPython dependency for the frontend user interface was updated to remediate this tempfile.TemporaryDirectory class vulnerability.
  • CVE-2023-52424: A dependency for the frontend user interface was updated to remediate the SSID Confusion Attack vulnerability.
  • CVE-2024-24788: A golang dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).

Graph Lakehouse 3.1.1

  • CVE-2024-30172: The BC Java Cryptography API dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-21634: The BC Java, BC-FJA, and BC C# .Net library dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-29857: The ion-java dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.

Graph Lakehouse 3.1.0

Graph Lakehouse 3.0.0

  • CVE-2023-32067: The c-ares dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.
  • CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.
  • CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.
  • CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.
  • CVE-2022-46175: The JSON5 dependency for the frontend user interface was updated to remediate this vulnerability.
  • CVE-2022-31129: The moment JavaScript library dependency for the frontend user interface was upgraded to remediate this vulnerability.
  • CVE-2021-0341: The com.squareup.okhttp dependency for the frontend user interface was updated to remediate this possible improper certificate validation vulnerability.
  • GHSA-v78c-4p63-2j6c: The moment-timezone dependency for the frontend user interface was updated to remediate this vulnerability.
  • SONATYPE-2022-4402: The Postgres JDBC driver was updated to remediate this possible SQL injection vulnerability.
  • SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.

AnzoGraph 2.5.23

  • CVE-2025-52999: The jackson-core dependency was updated to remediate a potential Denial-of-Service vulnerability.

  • CVE-2025-24970, CVE-2024-29025, CVE-2025-25193, CVE-2024-47535, CVE-2023-34462: The Netty library dependency for GDI and the front-end user interface was updated to remediate this vulnerability.

  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2020-13956: The org.apache.httpcomponents package dependency was updated to remediate this vulnerability.

  • SONATYPE-2012-0050: The Apache commons-codec package was updated to remediate this vulnerability.

  • CVE-2023-35116: The jackson-databind dependency was updated to remediate this vulnerability.

  • CVE-2024-43382: The Snowflake JDBC driver was updated to remediate this security setting vulnerability.

  • CVE-2024-48910, CVE-2024-45801: The DOMPurify JavaScript library was updated to remediate this vulnerability, preventing security bypasses and unauthorized modifications of application behavior.

  • CVE-2024-43591: The Azure CLI and Azure Service Connector was updated to remediate this Azure Command Line Integration (CLI) Elevation of Privilege vulnerability.

  • CVE-2024-47554: The Apache Commons IO dependency was updated to address this potential Denial of Service (DoS) vulnerability.

  • CVE-2024-8184: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2024-34156: The encoding/gob package of the Golang standard library was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2024-7254: The protobuf dependency for the frontend user interface was updated to address this potential Denial of Service (DoS) vulnerability.

  • CVE-2019-5827, CVE-2014-3566: The nss, nss-tools, sqlite, and nss-sysinit libraries were updated to remediate these vulnerabilities.

  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.

  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.

  • CVE-2025-27553: The Apache Commons VFS dependency was updated to remediate this Relative Path Traversal vulnerability.

  • CVE-2025-0665, CVE-2025-0725, CVE-2024-2398: The libcurl library dependency was upgraded to version 8.12.0 to remediate this vulnerability.

  • CVE-2023-2976, CVE-2020-8908: The Google Guava library dependency was updated to remediate these vulnerabilities.

AnzoGraph 2.5.22

  • CVE-2022-30187: Azure Storage client library dependencies were updated to remediate the Azure Storage Library Information Disclosure Vulnerability.
  • CVE-2023-2976: The Google Guava dependency was updated to remediate this vulnerability.
  • CVE-2024-29025: The io.netty:netty-codec-http dependency was updated to remediate this HttpPostRequestDecoder out-of-memory vulnerability.
  • CVE-2024-29131 and CVE-2024-29133: The Apache Commons Configuration dependency was updated to remediate this Out-of-bounds Write vulnerability.
  • CVE-2023-52428: The Connect2id Nimbus JOSE+JWT dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

AnzoGraph 2.5.21

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability.
  • CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
  • CVE-2023-45283: The golang path/filepath package dependency was updated to remediate this vulnerability.
  • CVE-2024-24791: The golang net/http HTTP/1.1 client dependency for Graph LakehouseDB and frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XmlParser XML external entity (XXE) vulnerability.
  • CVE-2022-36944: The Scala dependency for Graph LakehouseDB was upgraded to remediate this vulnerability.

AnzoGraph 2.5.20

AnzoGraph 2.5.19

The Jetty dependency for the frontend user interface was updated to remediate the following vulnerabilities:

GHSA-jjjh-jjxp-wpff, GHSA-rgv9-q543-rqg4, GHSA-wgh7-54f2-x98r, GHSA-58qw-p7qm-5rvh, CVE-2022-25647, CVE-2007-1652, CVE-2022-2048, CVE-2009-5045, CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2017-9735, CVE-2022-2048, CVE-2020-27216, CVE-2023-44487, CVE-2023-40167, CVE-2023-36478, CVE-2023-36479, and CVE-2023-41900.

AnzoGraph 2.5.17

  • CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.

AnzoGraph 2.5.15

  • CVE-2023-28154: The Webpack dependency for the frontend user interface was updated to remediate this vulnerability.
  • CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.

AnzoGraph 2.5.14

  • CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.

AnzoGraph 2.5.13

AnzoGraph 2.5.12

  • SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.
  • GHSA-h4h5-3hr4-j3g2: The com.google.protobuf and woodstox-core dependencies were updated to remediate this vulnerability.

AnzoGraph 2.5.11

  • CVE-2022-42889: The Apache Commons Text (commons-text) dependency was updated to remediate this vulnerability.
  • CVE-2022-42003 and CVE-2022-42004: The FasterXML jackson-databind dependencies were updated to remediate these vulnerabilities.
  • CVE-2022-41853: To mitigate this vulnerability, the HyperSQL DataBase driver was removed from the product.
  • CVE-2022-36944: The Scala library was updated to version 2.13.9 to remediate this vulnerability.
  • CVE-2020-15250: The JUnit dependency was updated to version 4.13.1 to remediate this vulnerability.

AnzoGraph 2.5.10

  • CVE-2015-6420: The Apache Commons Collections (ACC) library (commons-collections) dependency was updated to remediate this vulnerability.
  • CVE-2022-25168: The Apache Hadoop file utility (hadoop-common) dependency was updated to remediate this vulnerability.
  • CVE-2022-2309: The python2-lxml dependency was updated to remediate this vulnerability.

AnzoGraph 2.5.8

  • CVE-2022-31129: The moment JavaScript library dependency in the Graph Lakehouse user interface was upgraded to remediate this vulnerability.

AnzoGraph 2.5.7

  • CVE-2021-0341: The unused Java component OkHostnameVerifier.java was removed from the Graph Lakehouse user interface to remediate this vulnerability.

AnzoGraph 2.5.6

  • CVE-2020-8908: Updated the GDI Guava dependency to remediate a temp directory creation vulnerability.
  • CVE-2021-22573: Updated the GDI com.google.oauth-client:google-oauth-client dependency to version 1.33.3 to remediate a vulnerability where the IDToken verifier did not verify if a token was properly signed.
  • CVE-2022-24823: Updated the GDI Netty IO dependency to version 4.1.77.Final to remediate this vulnerability.

AnzoGraph 2.5.5

  • CVE-2020-36518: The jackson-databind dependency for Graph Lakehouse extensions and the frontend user interface was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.

AnzoGraph 2.5.4

  • CVE-2021-3807: The ansi-regex dependency in the frontend user interface was updated to remediate an Inefficient Regular Expression Complexity vulnerability.
  • CVE-2022-0778: The MySQL driver was updated to remediate a Denial of Service (DoS) vulnerability related to certificate parsing.
  • CVE-2022-29078: The Embedded JavaScript templates package for Node.js, which is used in the frontend user interface, was updated to remediate a vulnerability that could allow server-side template injection.

AnzoGraph 2.5.3

  • CVE-2022-24785: The Moment.js JavaScript date library frontend user interface dependency was updated to remediate a path traversal vulnerability.
  • CVE-2020-15366, CVE-2021-3757, CVE-2021-3918, CVE-2021-23807: The Another JSON Schema Validator (AJV), json-schema, jsonpointer, and immer frontend user interface dependencies were updated to remediate "prototype pollution" vulnerabilities.
  • CVE-2021-23364, CVE-2021-27290, and CVE-2021-23382: The package browserslist, ssri, and postcss frontend user interface dependencies were updated to remediate a Regular Expression Denial of Service (ReDoS) vulnerability.
  • CVE-2021-3803: The nth-check frontend user interface dependency was updated to remediate an Inefficient Regular Expression Complexity vulnerability.

AnzoGraph 2.5.2

  • CVE-2020-36518: The jackson-databind dependency in the GDI and Neptune and Geospatial extensions was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.
  • CVE-2021-3807 and CVE-2021-44906: The ansi-regex and Minimist dependencies in the Graph Lakehouse frontend container were updated to remediate vulnerabilities.
  • CVE-2022-25315: The Expat library for Red Hat Enterprise Linux and CentOS 7 was updated to remediate the integer overflow flaw in libexpat.

AnzoGraph 2.5.1

Updated 2.5.1 Docker Images

The following Docker images were re-released to resolve the vulnerabilities listed below:

docker.io/cambridgesemantics/anzograph-frontend:latest docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912-b202202242300 docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 docker.io/cambridgesemantics/anzograph-frontend:2.5.1 docker.io/cambridgesemantics/anzograph-db:latest docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-db:2.5.1 docker.io/cambridgesemantics/anzograph:latest docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph:2.5.1 docker.io/cambridgesemantics/anzograph-devel:latest docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-devel:2.5.1

  • CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
  • CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.

Released 2.5.1 Red Hat Marketplace Images

The following release of Red Hat Marketplace images resolve the vulnerabilities listed below:

cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202282115 cambridgesemantics/anzograph:2.5.1-r202202161817-b202202282115

  • CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
  • CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.

Initial 2.5.1 Release of all Deployment Methods Except Red Hat Marketplace

Source: https://docs.sw.siemens.com/documentation/external/PL20260518131381558/en-US/html/relnotes/security-patches.htm · retrieved 2026-08-23