GraphKnowledge

graph-studio

Graph Lakehouse Patched Vulnerabilities

This page provides information about the common security vulnerabilities that were patched in Graph Lakehouse.

Graph Lakehouse Releases

|

Graph Lakehouse 2026.1 DB 3.4.0

  • CVE-2025-48734: The Apache Commons BeanUtils dependency was updated to remediate a potential Improper Access Control vulnerability.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.
  • CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
  • CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.
  • CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
  • CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
  • GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2026-3805: curl has been updated to address an issue in which it accesses memory that has already been freed when handling a second server message block (SMB) request to the same host.
  • CVE-2025-53864: Upgraded com.nimbusds:nimbus-jose-jwt to address medium-severity vulnerabilities.
  • CVE-2026-33870, CVE-2026-33871: The Netty library dependency was updated to version 4.1.132.Final to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2026-33186: The golang /grpc package was updated to remediate this potential critical security vulnerability.

Graph Lakehouse 2026.0 DB 3.3.1

  • CVE-2025-68121, CVE-2025-61726, CVE-2025-681728, and CVE-2025-61730: The Go standard library was updated to mitigate critical security vulnerabilities including DoS attacks, memory exhaustion, and unauthorized session resumption.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
  • CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
  • CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
  • CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.

Graph Lakehouse 2026.0 DB 3.3.0

  • CVE-2025-46762: The org.apache.parquet dependency was updated to remediate this vulnerability.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-32989, CVE-2025-32990, CVE-2025-32988, CVE-2025-6395: The GnuTLS library was updated to remediate various potential vulnerabilities related to this dependency.

Graph Lakehouse 2025.0 DB 3.2.2

  • CVE-2025-22870 : The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-27553 : The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-22871 : The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872 : The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-1948 : The Eclipse Jetty dependency was updated to remediate this vulnerability in the Jetty HTTP/2 server.

Graph Lakehouse 2025.0 DB 3.2.1

Graph Lakehouse 2025.0 DB 3.2.0

Graph Lakehouse 3.1.9

  • GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
  • CVE-2026-25646: The libpng library was updated to remediate this potential out-of-bounds read vulnerability.
  • CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
  • CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
  • CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-54988: The Apache Tika package was updated to remediate this potential security vulnerability.
  • CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
  • CVE-2025-9086: curl has been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.

Graph Lakehouse 3.1.8

  • CVE-2024-45336: The golang net/http package dependency was updated to remediate this vulnerability.
  • CVE-2024-45341: The golang crypto/x509 package dependency was updated to remediate this vulnerability.
  • CVE-2025-22870: The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-27553: The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-48734: The Apache commons dependency was updated to remediate this potential Improper Access Control vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-47907: The golang database/sql package dependency was updated to remediate vulnerability.
  • CVE-2025-4674: The golang package was updated to remediate issues related to unexpected code execution.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-5115: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential HTTP/2 MadeYouReset DoS vulnerability.

Graph Lakehouse 3.1.7

Graph Lakehouse 3.1.6

  • GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XML external entity (XXE) vulnerability in the jetty XmlParser.
  • CVE-2024-43382: The Snowflake JDBC driver dependency was updated to remediate this incorrect security setting vulnerability.
  • GHSA-w32m-9786-jp63, CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

Graph Lakehouse 3.1.5

  • CVE-2024-47554: The Apache Commons IO dependency of the Neptune extension library of Graph Lakehouse DB was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-48910: The DOMPurify dependency was upgraded to version 2.4.2 to remediate this Prototype Pollution vulnerability.

Graph Lakehouse 3.1.4

  • CVE-2024-34156: The encoding/gob package dependency was updated to remediate this stack exhaustion vulnerability (Go upgraded to version 1.23.1).
  • CVE-2024-7254: The Protocol Buffers parser dependency was updated to remediate this improper input validation vulnerability.
  • CVE-2024-45801: The DOMPurify dependency was upgraded to remediate this XSS attack vulnerability.
  • CVE-2024-43591: The Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability was remediated.
  • CVE-2024-2398: The libcurl dependency was upgraded from version 8.1.2 to 8.10.1 to further remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-47554: The Apache Commons IO dependency was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-8184: The Eclipse jetty dependency was updated to version 12.0.12 to remediate a potential remote Denial of Service (DoS) attack vulnerability.

Graph Lakehouse 3.1.3

  • CVE-2024-2398: The libcurl dependency was updated to remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-6345: The pypa/setuptools dependency was upgraded to remediate this vulnerability.

Graph Lakehouse 3.1.2

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).
  • CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
  • CVE-2023-6597: The CPython dependency for the frontend user interface was updated to remediate this tempfile.TemporaryDirectory class vulnerability.
  • CVE-2023-52424: A dependency for the frontend user interface was updated to remediate the SSID Confusion Attack vulnerability.
  • CVE-2024-24788: A golang dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).

Graph Lakehouse 3.1.1

  • CVE-2024-30172: The BC Java Cryptography API dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-21634: The BC Java, BC-FJA, and BC C# .Net library dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-29857: The ion-java dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.

Graph Lakehouse 3.1.0

Graph Lakehouse 3.0.0

  • CVE-2023-32067: The c-ares dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.
  • CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.
  • CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.
  • CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.
  • CVE-2022-46175: The JSON5 dependency for the frontend user interface was updated to remediate this vulnerability.
  • CVE-2022-31129: The moment JavaScript library dependency for the frontend user interface was upgraded to remediate this vulnerability.
  • CVE-2021-0341: The com.squareup.okhttp dependency for the frontend user interface was updated to remediate this possible improper certificate validation vulnerability.
  • GHSA-v78c-4p63-2j6c: The moment-timezone dependency for the frontend user interface was updated to remediate this vulnerability.
  • SONATYPE-2022-4402: The Postgres JDBC driver was updated to remediate this possible SQL injection vulnerability.
  • SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.

AnzoGraph 2.5.23

  • CVE-2025-52999: The jackson-core dependency was updated to remediate a potential Denial-of-Service vulnerability.

  • CVE-2025-24970, CVE-2024-29025, CVE-2025-25193, CVE-2024-47535, CVE-2023-34462: The Netty library dependency for GDI and the front-end user interface was updated to remediate this vulnerability.

  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2020-13956: The org.apache.httpcomponents package dependency was updated to remediate this vulnerability.

  • SONATYPE-2012-0050: The Apache commons-codec package was updated to remediate this vulnerability.

  • CVE-2023-35116: The jackson-databind dependency was updated to remediate this vulnerability.

  • CVE-2024-43382: The Snowflake JDBC driver was updated to remediate this security setting vulnerability.

  • CVE-2024-48910, CVE-2024-45801: The DOMPurify JavaScript library was updated to remediate this vulnerability, preventing security bypasses and unauthorized modifications of application behavior.

  • CVE-2024-43591: The Azure CLI and Azure Service Connector was updated to remediate this Azure Command Line Integration (CLI) Elevation of Privilege vulnerability.

  • CVE-2024-47554: The Apache Commons IO dependency was updated to address this potential Denial of Service (DoS) vulnerability.

  • CVE-2024-8184: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2024-34156: The encoding/gob package of the Golang standard library was updated to remediate a potential Denial of Service (DoS) vulnerability.

  • CVE-2024-7254: The protobuf dependency for the frontend user interface was updated to address this potential Denial of Service (DoS) vulnerability.

  • CVE-2019-5827, CVE-2014-3566: The nss, nss-tools, sqlite, and nss-sysinit libraries were updated to remediate these vulnerabilities.

  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.

  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.

  • CVE-2025-27553: The Apache Commons VFS dependency was updated to remediate this Relative Path Traversal vulnerability.

  • CVE-2025-0665, CVE-2025-0725, CVE-2024-2398: The libcurl library dependency was upgraded to version 8.12.0 to remediate this vulnerability.

  • CVE-2023-2976, CVE-2020-8908: The Google Guava library dependency was updated to remediate these vulnerabilities.

AnzoGraph 2.5.22

  • CVE-2022-30187: Azure Storage client library dependencies were updated to remediate the Azure Storage Library Information Disclosure Vulnerability.
  • CVE-2023-2976: The Google Guava dependency was updated to remediate this vulnerability.
  • CVE-2024-29025: The io.netty:netty-codec-http dependency was updated to remediate this HttpPostRequestDecoder out-of-memory vulnerability.
  • CVE-2024-29131 and CVE-2024-29133: The Apache Commons Configuration dependency was updated to remediate this Out-of-bounds Write vulnerability.
  • CVE-2023-52428: The Connect2id Nimbus JOSE+JWT dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

AnzoGraph 2.5.21

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability.
  • CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
  • CVE-2023-45283: The golang path/filepath package dependency was updated to remediate this vulnerability.
  • CVE-2024-24791: The golang net/http HTTP/1.1 client dependency for AnzoGraphDB and frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XmlParser XML external entity (XXE) vulnerability.
  • CVE-2022-36944: The Scala dependency for AnzoGraphDB was upgraded to remediate this vulnerability.

AnzoGraph 2.5.20

AnzoGraph 2.5.19

The Jetty dependency for the frontend user interface was updated to remediate the following vulnerabilities:

GHSA-jjjh-jjxp-wpff, GHSA-rgv9-q543-rqg4, GHSA-wgh7-54f2-x98r, GHSA-58qw-p7qm-5rvh, CVE-2022-25647, CVE-2007-1652, CVE-2022-2048, CVE-2009-5045, CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2017-9735, CVE-2022-2048, CVE-2020-27216, CVE-2023-44487, CVE-2023-40167, CVE-2023-36478, CVE-2023-36479, and CVE-2023-41900.

AnzoGraph 2.5.17

  • CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.

AnzoGraph 2.5.15

  • CVE-2023-28154: The Webpack dependency for the frontend user interface was updated to remediate this vulnerability.
  • CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.

AnzoGraph 2.5.14

  • CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.

AnzoGraph 2.5.13

AnzoGraph 2.5.12

  • SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.
  • GHSA-h4h5-3hr4-j3g2: The com.google.protobuf and woodstox-core dependencies were updated to remediate this vulnerability.

AnzoGraph 2.5.11

  • CVE-2022-42889: The Apache Commons Text (commons-text) dependency was updated to remediate this vulnerability.
  • CVE-2022-42003 and CVE-2022-42004: The FasterXML jackson-databind dependencies were updated to remediate these vulnerabilities.
  • CVE-2022-41853: To mitigate this vulnerability, the HyperSQL DataBase driver was removed from the product.
  • CVE-2022-36944: The Scala library was updated to version 2.13.9 to remediate this vulnerability.
  • CVE-2020-15250: The JUnit dependency was updated to version 4.13.1 to remediate this vulnerability.

AnzoGraph 2.5.10

  • CVE-2015-6420: The Apache Commons Collections (ACC) library (commons-collections) dependency was updated to remediate this vulnerability.
  • CVE-2022-25168: The Apache Hadoop file utility (hadoop-common) dependency was updated to remediate this vulnerability.
  • CVE-2022-2309: The python2-lxml dependency was updated to remediate this vulnerability.

AnzoGraph 2.5.8

  • CVE-2022-31129: The moment JavaScript library dependency in the AnzoGraph user interface was upgraded to remediate this vulnerability.

AnzoGraph 2.5.7

  • CVE-2021-0341: The unused Java component OkHostnameVerifier.java was removed from the AnzoGraph user interface to remediate this vulnerability.

AnzoGraph 2.5.6

  • CVE-2020-8908: Updated the GDI Guava dependency to remediate a temp directory creation vulnerability.
  • CVE-2021-22573: Updated the GDI com.google.oauth-client:google-oauth-client dependency to version 1.33.3 to remediate a vulnerability where the IDToken verifier did not verify if a token was properly signed.
  • CVE-2022-24823: Updated the GDI Netty IO dependency to version 4.1.77.Final to remediate this vulnerability.

AnzoGraph 2.5.5

  • CVE-2020-36518: The jackson-databind dependency for AnzoGraph extensions and the frontend user interface was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.

AnzoGraph 2.5.4

  • CVE-2021-3807: The ansi-regex dependency in the frontend user interface was updated to remediate an Inefficient Regular Expression Complexity vulnerability.
  • CVE-2022-0778: The MySQL driver was updated to remediate a Denial of Service (DoS) vulnerability related to certificate parsing.
  • CVE-2022-29078: The Embedded JavaScript templates package for Node.js, which is used in the frontend user interface, was updated to remediate a vulnerability that could allow server-side template injection.

AnzoGraph 2.5.3

  • CVE-2022-24785: The Moment.js JavaScript date library frontend user interface dependency was updated to remediate a path traversal vulnerability.
  • CVE-2020-15366, CVE-2021-3757, CVE-2021-3918, CVE-2021-23807: The Another JSON Schema Validator (AJV), json-schema, jsonpointer, and immer frontend user interface dependencies were updated to remediate "prototype pollution" vulnerabilities.
  • CVE-2021-23364, CVE-2021-27290, and CVE-2021-23382: The package browserslist, ssri, and postcss frontend user interface dependencies were updated to remediate a Regular Expression Denial of Service (ReDoS) vulnerability.
  • CVE-2021-3803: The nth-check frontend user interface dependency was updated to remediate an Inefficient Regular Expression Complexity vulnerability.

AnzoGraph 2.5.2

  • CVE-2020-36518: The jackson-databind dependency in the GDI and Neptune and Geospatial extensions was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.
  • CVE-2021-3807 and CVE-2021-44906: The ansi-regex and Minimist dependencies in the AnzoGraph frontend container were updated to remediate vulnerabilities.
  • CVE-2022-25315: The Expat library for Red Hat Enterprise Linux and CentOS 7 was updated to remediate the integer overflow flaw in libexpat.

AnzoGraph 2.5.1

Updated 2.5.1 Docker Images

The following Docker images were re-released to resolve the vulnerabilities listed below:

docker.io/cambridgesemantics/anzograph-frontend:latest docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912-b202202242300 docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 docker.io/cambridgesemantics/anzograph-frontend:2.5.1 docker.io/cambridgesemantics/anzograph-db:latest docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-db:2.5.1 docker.io/cambridgesemantics/anzograph:latest docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph:2.5.1 docker.io/cambridgesemantics/anzograph-devel:latest docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-devel:2.5.1

  • CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
  • CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.

Released 2.5.1 Red Hat Marketplace Images

The following release of Red Hat Marketplace images resolve the vulnerabilities listed below:

cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202282115 cambridgesemantics/anzograph:2.5.1-r202202161817-b202202282115

  • CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
  • CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.

Initial 2.5.1 Release of all Deployment Methods Except Red Hat Marketplace

Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/relnotes/security-patches-azg.htm · retrieved 2026-08-23