GraphKnowledge

graph-studio

Graph Studio Patched Vulnerabilities

This page provides information about the common security vulnerabilities that were patched in Graph Studio and Graph Lakehouse releases.

Graph Studio Releases

|

Graph Studio 2026.1 Engine v6.3

This release addresses the following security vulnerabilities in third-party dependencies:

  • Updated multiple-dependency JARs to resolve CVE issues.

  • Updated the Kotlin bundle to the latest version to resolve various CVEs.

  • Jetty 12 Security Update: Updated Jetty 12 to the latest patch release to resolve CVEs.

  • Go Standard Library Updates (Multiple CVEs): Updated Go stdlib to address 13 vulnerabilities including CVE-2026-25679 and CVE-2025-47907.

  • CVE-2025-7365: Updated keycloak-services to address a phishing attack vulnerability in the email verification flow.

  • CVE-2025-55163: Updated grpc-netty-shaded to address a Netty vulnerability.

  • CVE-2025-59419: Updated netty-codec-smtp in Graph Studio DU.

  • CVE-2025-53066: Updated OpenJDK in Graph Studio DU 6.3 builds to address an Oracle Java SE vulnerability.

  • CVE-2025-48976: Updated OpenJDK in Graph Studio to address a high-severity vulnerability.

  • CVE-2025-37727: Updated Elasticsearch to address an insertion vulnerability.

  • CVE-2023-39017: Updated org.quartz-scheduler to address a detected vulnerability.

  • CVE-2026-21945, CVE-2026-21932: Updated the Eclipse Angus Mail library to address two vulnerabilities.

  • CVE-2026-21945: Updated OpenJDK in Graph Studio DU to address a vulnerability.

  • CVE-2023-24998: Updated commons-fileupload in Graph Studio DU.

  • CVE-2026-32280, CVE-2026-32289: Updated Go stdlib in Graph Studio and Graph Studio DU.

  • CVE-2026-39304: Updated activemq-client in Graph Studio DU.

  • CVE-2026-1486, CVE-2026-1529: Updated keycloak-services to address two vulnerabilities.

  • CVE-2026-1605: Updated jetty-server in Graph Studio and Graph Studio DU.

  • GHSA-72hv-8253-57qq: Updated jackson-core in Graph Studio and Graph Studio DU.

  • CVE-2026-33871: Updated netty-codec-http2 in Graph Studio and Graph Studio DU.

  • CVE-2026-33870: Updated netty-codec-http in Graph Studio and Graph Studio DU.

  • CVE-2026-2092: Updated keycloak-saml-core in Graph Studio.

  • CVE-2026-40477, CVE-2026-40478: Updated Thymeleaf in Graph Studio to address critical severity vulnerabilities (CVSS 9.0).

Graph Studio 2026.0.1 Engine v6.2.1

  • CVE-2025-30749, CVE-2025-50106, CVE-2025-50059: Updated Java Runtime to version 17.0.16 to address multiple high-severity vulnerabilities related to the Java SE 2D and Java SE Networking components.
  • CVE-2024-6763: Updated Jetty to version 12.0.12 to address a URI parsing vulnerability.
  • Updated the mina-core, netty, tika-core, grpc-netty-shaded, activemq, and janino libraries.
  • CVE-2025-53066: Updated OpenJDK to version 21.0.9 to address a JAXP vulnerability,

Graph Studio 2026.0 Engine v6.2

  • CVE-2024-47535: Fixed Netty DoS vulnerability affecting HTTP/2 communication in Graph Studio dependencies.
  • CVE-2024-6763: Resolved Eclipse Jetty URI parsing vulnerability that could affect invalid authority handling.
  • CVE-2025-48734: Fixed Apache Commons BeanUtils remote code execution vulnerability by upgrading to version 1.11.0.
  • CVE-2025-52999: Resolved Jackson Core vulnerabilities in both main Graph Studio and DU pipeline dependencies by upgrading to version 2.15.0.
  • CVE-2025-50059, CVE-2025-30749, CVE-2025-50106: Fixed multiple security vulnerabilities in OpenJDK components affecting 2D graphics and networking.
  • CVE-2025-55163: Resolved Netty HTTP/2 DDoS vulnerability (MadeYouReset attack) affecting codec-http2 components.

Graph Studio 2025.1 Engine v6.1

  • Fixes for Grapstudio Distributed Unstructured CVE-2025-48734: This addresses the need for a fix related to CVE-2025-48734 for Graph Studio Distributed Unstructured Users.
  • DOMPurify js library updated due to CVE: This updates DOMPurify JavaScript library due to a CVE.
  • Journal query performance regression: This fix addresses a regression in journal query performance.

Graph Studio 2025.0.1 Engine v6.0.1

  • CVE-2024-21235 (Medium Severity): Addresses multiple CVEs in openjdk and jetty components, enhancing core Java security.
  • Multiple High Severity CVEs in Unstructured Components: Resolves multiple high-severity CVEs in okio and openjdk, preventing unauthenticated network compromise and data manipulation.
  • CVE-2025-25193 (Medium Severity) in Netty: Fixes CVE-2025-25193 in netty-common, improving network communication integrity.
  • CVE-2025-1391 in Keycloak Services: Resolves CVE-2025-1391 in keycloak-services, strengthening SSO security.
  • CVE-2025-27553 (High Severity) in Commons VFS2: Patches high-severity CVE-2025-27553 in commons-vfs2, critical for secure pipeline data flows.
  • CVE-2024-13009 (High Severity) in Jetty Server: Fixes high-severity CVE-2024-13009 in jetty-server, preventing data corruption and sharing issues.
  • Keycloak CVE-2025-3501: Resolves Keycloak CVE-2025-3501, which allowed bypassing trust store verification. CVE-2019-9628 was a false positive.
  • Update to Latest Keycloak Libraries: Updates Keycloak libraries to version 26.1.5 to mitigate various CVEs and enhance authentication security.
  • Elasticsearch Update: Updates Elasticsearch to address CVE-2024-52981, securing search and indexing functions.
  • XSS Security Fix for Object Titles: Patches an XSS vulnerability that allowed malicious scripts in object titles, improving UI security.

Graph Studio 5.4.17

This release addresses the following security vulnerabilities in third-party dependencies:

  • CVE-2024-43709: Updated ElasticSearch dependencies to address CVE-2024-43709.
  • ElasticSearch Security Updates: Resolved additional CVEs detected in ElasticSearch components.
  • Apache ActiveMQ and pac4j Critical CVEs: Updated Apache ActiveMQ and pac4j dependencies to fix critical security vulnerabilities.
  • CVE-2026-33871, CVE-2026-42587: Updated netty-codec-http2 to address denial-of-service vulnerabilities.
  • CVE-2026-42587, CVE-2026-42584, CVE-2026-33870: Updated netty-codec-http to address request smuggling and denial-of-service vulnerabilities.
  • CVE-2026-42579 - Updated netty-codec-dns to address a denial-of-service vulnerability.

Graph Studio 5.4.16

Graph Studio 5.4.16 addresses multiple security vulnerabilities to ensure the safety and integrity of your deployments. All security fixes have been verified through container image scanning.

Severity: High

Fixed a high-severity vulnerability in the io.netty:netty-codec-smtp package by upgrading from version 4.1.118.Final to version 4.1.128.Final.

Severity: High

Resolved a high-severity vulnerability in Oracle Java SE (component: JAXP) by upgrading OpenJDK from version 1.8.0_462 to version 1.8.0_472. This vulnerability allowed unauthenticated attackers with network access to compromise the system and gain unauthorized access to critical data.

CVSS 3.1 Base Score: 7.5 (Confidentiality impacts)

CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Severity: High

Mitigated a high-severity Apache Tika XXE (XML External Entity) vulnerability via crafted XFA files inside PDFs. The fix involved removing the Apache Tika dependency where possible and upgrading tika-parsers from version 1.28.4/1.28.5 to version 2.0.0-ALPHA where required.

Severity: Critical

Addressed a critical Apache Tika XXE vulnerability by upgrading to tika-core version 2.9.5-SNAPSHOT, which contains the security fixes from the released version 3.2.2. This custom build was created from the Apache Tika GitHub repository branch 2x, which includes the commit that fixes the CVE.

Note: The tika-core 2.9.5-SNAPSHOT version is not a released version but contains the fix that was released in version 3.2.2.

Severity: High

Fixed a high-severity vulnerability in libxml2's xmlBuildQName function where integer overflows in buffer size calculations could lead to stack-based buffer overflow, resulting in memory corruption or denial of service. This was resolved by upgrading OpenJDK from version 1.8.0_472 to version 1.8.0_482.

Multiple OpenJDK Vulnerabilities

Severity: Critical

Addressed multiple high-severity OpenJDK vulnerabilities by upgrading to version 1.8.0_482:

All vulnerabilities have been verified as fixed in the latest container image scans.

Graph Studio 5.4.15

Upgraded the DOMPurify library from version 2.5.8 to 3.2.7 to address security scan findings and maintain compliance with current security standards. The updated library is used in toast messages and navigation display components.

Graph Studio 5.4.14

  • CVE-2025-48976: Upgraded commons-fileupload from version 1.5 to 1.6.0 to address high-severity security vulnerability in pipeline service.
  • CVE-2025-53864, CVE-2025-4879: Upgraded com.nimbusds:nimbus-jose-jwt from version 9.37.2 to 10.0.2 and org.apache.cxf:cxf-core from version 3.5.10 to 3.5.11+ to address medium-severity vulnerabilities.
  • CVE-2024-13009: Upgraded org.eclipse.jetty:jetty-server from version 9.4.56.v20240826 to 9.4.57.v20241219 to address high-severity security vulnerability.
  • Additional security vulnerability fixes: Resolved multiple security vulnerabilities in various dependencies to improve overall system security.

Graph Studio 5.4.9

  • CVE-2024-7254: The Protocol Buffers parser dependency was updated to remediate this improper input validation vulnerability.
  • CVE-2024-47561: The Apache Avro Java SDK dependency was upgraded to remediate this vulnerability.
  • CVE-2024-47554: The Apache Commons IO dependency was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2020-2801, CVE-2023-41993:The Oracle JDK dependency was replaced with OpenJDK version 1.8 to remediate these vulnerabilities.

Graph Studio 5.4.8

  • GHSA-xpw8-rcwv-8f8p: The io.netty:netty-codec-http2 package dependency was upgraded to remediate a potential DDoS attack vulnerability.
  • CVE-2020-11971: The Apache Camel's JMX dependency was upgraded to remediate this Rebind Flaw vulnerability.
  • CVE-2024-21634: The ion-java dependency for Graph Lakehouse DB was updated to remediate this Oracle JDK vulnerability.

Graph Studio 5.4.7

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability.
  • CVE-2024-2961: The glibc library dependency was updated to remediate this vulnerability.

Graph Studio 5.4.6

  • CVE-2018-1320: The Apache Thrift Java client library dependency was updated to remediate this vulnerability.
  • CVE-2023-6378: The logback receiver component of the logback dependency was updated to remediate a possible Denial of Service (DoS) vulnerability.
  • CVE-2023-34054 and CVE-2023-34062: The Reactor Netty HTTP Server dependency was updated to remediate these vulnerabilities.
  • CVE-2023-33202: The Bouncy Castle for Java dependency was updated to remediate a possible Denial of Service (DoS) vulnerability.
  • CVE-2023-46673: The Elasticsearch dependency was updated as it was identified that malformed scripts used in the script processor of a pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
  • GHSA-xpw8-rcwv-8f8p: The io.netty:netty-codec-http2 dependency for Graph Studio Distributed Unstructured was updated to remediate this possible HTTP/2 Rapid Reset Attack vulnerability.

Graph Studio 5.4.5

  • CVE-2023-46604: The Apache ActiveMQ dependency was updated to remediate this possible remote code execution vulnerability.
  • CVE-2023-39410: The Apache Avro dependency for Graph Studio Unstructured was updated to remediate this possible out of memory vulnerability.
  • CVE-2023-41900, CVE-2023-36479, and CVE-2023-40167: The Eclipse Jetty dependency was updated to remediate these vulnerabilities.
  • CVE-2022-44729 and CVE-2022-44730: The Apache XML Graphics Batik dependency was updated to remediate these possible Server-Side Request Forgery (SSRF) vulnerabilities.
  • CVE-2023-2976: The Google Guava dependency was updated to remediate this vulnerability.

Graph Studio 5.4.2

  • CVE-2023-24998: The Apache Commons FileUpload dependency for Graph Studio Unstructured was updated to remediate a possible Denial of Service (DoS) vulnerability. ​- CVE-2022-1471: Modified the SnakeYaml dependency for Graph Studio Unstructured to use the SafeConstructor when parsing content.
  • CVE-2023-1370: The json-smart dependency was updated to remediate a possible stack overflow vulnerability.
  • CVE-2023-1436: The Jettison dependency was updated to remediate this possible StackOverflowError vulnerability.
  • CVE-2023-26048, CVE-2023-26049: The Jetty dependency was updated to remediate these vulnerabilities.

Graph Studio 5.4.1

  • ​CVE-2022-1471: Modified the SnakeYaml dependency to use the SafeConstructor when parsing content.
  • CVE-2022-40152: The Woodstox dependency was updated to version 6.4.0 to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2021-37533: The Apache Commons Net dependency was updated to version 3.9.0 to remediate this vulnerability.
  • CVE-2022-40150: The Jettison dependency was updated to version 1.5.3 to remediate a possible Denial of Service (DoS) vulnerability.
  • SONATYPE-2019-0870, SONATYPE-2021-0887, SONATYPE-2019-0992, and SONATYPE-2014-0257: The freemarker, passay, jcommander, and javaassit dependencies were updated to remediate these vulnerabilities.
  • CVE-2022-25168: The Apache Hadoop file utility dependency was updated to version 3.3.4 to remediate this vulnerability.
  • CVE-2022-38900: The decode-uri-component dependency was updated to remediate this possible Denial of Service (DoS) vulnerability.

Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/relnotes/security-patches.htm · retrieved 2026-08-23