Skip to content

fix(QTDI-3283): CVE-2026-49844 upgrade Log4j to 2.25.5 - #1263

Open
pyzhou-talend wants to merge 1 commit into
masterfrom
pyzhou/QTDI-3283_CVE_log4j
Open

fix(QTDI-3283): CVE-2026-49844 upgrade Log4j to 2.25.5#1263
pyzhou-talend wants to merge 1 commit into
masterfrom
pyzhou/QTDI-3283_CVE_log4j

Conversation

@pyzhou-talend

@pyzhou-talend pyzhou-talend commented Aug 17, 2026

Copy link
Copy Markdown

Requirements

  • Any code change adding any logic MUST be tested through a unit test executed with the default build
  • Any API addition MUST be done with a documentation update if relevant

Why this PR is needed?

Log4j 2.20.0 is affected by CVE-2026-49844. The minimum safe same-major release is 2.25.5.

What does this PR adds (design/code thoughts)?

Upgrades the centralized Log4j version property to 2.25.5. No API or runtime logic is changed. Dependency resolution was checked; the default build is blocked by the repository's missing external Spotless formatter file.

Review

Mandatory scope/design and standards/compliance reviews reran with no actionable findings.

AI generated code

https://internal.qlik.dev/general/ways-of-working/code-reviews/#guidelines-for-ai-generated-code

  • this PR has been written with the help of GitHub Copilot or another generative AI tool

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pyzhou-talend pyzhou-talend changed the title fix(QTDI-3283): Upgrade Log4j to 2.25.5 fix(QTDI-3283): CVE-2026-49844 upgrade Log4j to 2.25.5 Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant