diff --git a/build.gradle b/build.gradle index 52d25bc33b51..6cfd2941bf4a 100644 --- a/build.gradle +++ b/build.gradle @@ -196,6 +196,7 @@ subprojects { resolutionStrategy { dependencySubstitution { substitute module("org.lz4:lz4-java") using module(libs.lz4Java.get().toString()) because("Enforce lz4-java that contains CVE-2025-12183 and CVE-2025-66566 fixes") + substitute module("io.airlift:aircompressor") using module(libs.aircompressor.get().toString()) because("Enforce aircompressor that contains CVE-2025-67721 fix") } } } diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index b16cd5349030..7cc1167dd5df 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -27,7 +27,7 @@ aliyun-tea = "1.4.1" analyticsaccelerator = "1.3.1" antlr = "4.9.3" antlr413 = "4.13.1" # For Spark 4.0 support -aircompressor = "0.27" +aircompressor = "2.0.3" apiguardian = "1.1.2" arrow = "15.0.2" avro = "1.12.1" diff --git a/open-api/LICENSE b/open-api/LICENSE index 4910f902e5d1..244ce3953515 100644 --- a/open-api/LICENSE +++ b/open-api/LICENSE @@ -389,7 +389,7 @@ License (from POM): Apache License, Version 2.0 - http://apache.org/licenses/LIC -------------------------------------------------------------------------------- -Group: io.airlift Name: aircompressor Version: 0.27 +Group: io.airlift Name: aircompressor Version: 2.0.3 Project URL (from POM): https://github.com/airlift/aircompressor License (from POM): Apache License 2.0 - https://www.apache.org/licenses/LICENSE-2.0.html