Skip to content

Upgrade swagger-core from version 2.2.41 to 2.2.42#3206

Merged
bnasslahsen merged 1 commit intospringdoc:mainfrom
Mattias-Sehlstedt:swagger-core-bump
Feb 9, 2026
Merged

Upgrade swagger-core from version 2.2.41 to 2.2.42#3206
bnasslahsen merged 1 commit intospringdoc:mainfrom
Mattias-Sehlstedt:swagger-core-bump

Conversation

@Mattias-Sehlstedt
Copy link
Contributor

Upgrades swagger-core from version 2.2.41 to 2.2.42 to utilize the fix for reported issue #3191.

@burneyy
Copy link

burneyy commented Jan 20, 2026

Ha, I was about to do the same 😄 nice 👍

@JBSopra
Copy link

JBSopra commented Feb 9, 2026

Please can these be merged ASAP for a new version due to vulnerability in 2.2.41

@Mattias-Sehlstedt
Copy link
Contributor Author

Mattias-Sehlstedt commented Feb 9, 2026

Hi @JBSopra, could we share a reference to the vulnerability so that users can assess to what degree a force-bump is necessary if this repo was to be delayed with its upgrade?

@JBSopra
Copy link

JBSopra commented Feb 9, 2026

@Mattias-Sehlstedt

Vulnerability is the following: https://nvd.nist.gov/vuln/detail/CVE-2025-48924

See the chain in the image below:
Screenshot 2026-02-09 174846

Hopefully I haven't confused the package update

@Mattias-Sehlstedt
Copy link
Contributor Author

Thanks for the additional details 👍

@bnasslahsen bnasslahsen merged commit e19bd5c into springdoc:main Feb 9, 2026
1 check passed
@bnasslahsen
Copy link
Collaborator

@Mattias-Sehlstedt, Thank you for amazing work!

@JBSopra
Copy link

JBSopra commented Feb 10, 2026

@bnasslahsen any sort of timeframes for the next release for 2.8.16 and 3.0.2?

@bnasslahsen
Copy link
Collaborator

@JBSopra,

Hopefully by the end of the month.
There are still quite a few issues that need to be addressed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants