Skip to content

馃攼 Update dependencies to fix vulnerabilities - #89

Merged
kaklakariada merged 3 commits into
mainfrom
dependency-update/2026-09-13_22-46-47
Sep 14, 2026
Merged

kaklakariada merged 3 commits into
mainfrom
dependency-update/2026-09-13_22-46-47

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

This Pull Request was created by dependencies_update.yml workflow.
It updates dependencies to fix the following vulnerabilities:

@sonarqubecloud

Copy link
Copy Markdown

@kaklakariada
kaklakariada enabled auto-merge (squash) September 14, 2026 11:20
This release fixes the following vulnerability:

### CVE-2026-86231 (CWE-298) in dependency `com.github.mwiede:jsch:jar:2.28.4:provided`
A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should upgrade the affected component.

Clarity: I know that is text from the original description. Without context it might be confusing to users as they might read this as if it were their job to update. I think an additional sentence in the summary might set this straight.

Meta problem: formulations like these might appear in other CVE descriptions, so we should better add that explanatory sentence to the workflow.

@kaklakariada
kaklakariada merged commit 325294f into main Sep 14, 2026
10 checks passed
@kaklakariada
kaklakariada deleted the dependency-update/2026-09-13_22-46-47 branch September 14, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-86231: com.github.mwiede:jsch:jar:2.28.4:provided

2 participants