Skip to content

Bump the maven-dependencies group with 3 updates - #4326

Merged
github-actions[bot] merged 1 commit into
2.5.xfrom
dependabot/maven/2.5.x/maven-dependencies-1e093a174d
Sep 18, 2026
Merged

github-actions[bot] merged 1 commit into
2.5.xfrom
dependabot/maven/2.5.x/maven-dependencies-1e093a174d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-dependencies group with 3 updates: org.mongodb:mongodb-driver-sync, org.mongodb:mongodb-driver-legacy and net.bytebuddy:byte-buddy.

Updates org.mongodb:mongodb-driver-sync from 5.11.0 to 5.11.1

Release notes

Sourced from org.mongodb:mongodb-driver-sync's releases.

Java Driver 5.11.1 (September 10, 2026)

What's Changed

[!WARNING] Starting from driver version 3.3.0, an improper neutralization of a query operator in the GridFS delete methods allowed unintended data deletion.

See JAVA-6283 / CVE-2026-88033]

Upgrade reactive/sync driver version to 5.11.1 or later.

If you cannot upgrade, applications using older driver versions should call another delete overload delete(ObjectId). The driver constructs the BsonObjectId internally from a typed value, so no document can reach the filter.

[!WARNING] Starting from driver version 4.2.0, cancelling or timing out an encrypted operation while the driver fetches cloud KMS credentials makes it call into freed native memory, crashing or corrupting the application.

See JAVA-6266 / CVE-2026-88032

Upgrade both reactive driver and mongodb-crypt to version 5.11.1 or later.

Full Changelog: mongodb/mongo-java-driver@r5.11.0...r5.11.1

Commits

Updates org.mongodb:mongodb-driver-legacy from 5.11.0 to 5.11.1

Release notes

Sourced from org.mongodb:mongodb-driver-legacy's releases.

Java Driver 5.11.1 (September 10, 2026)

What's Changed

[!WARNING] Starting from driver version 3.3.0, an improper neutralization of a query operator in the GridFS delete methods allowed unintended data deletion.

See JAVA-6283 / CVE-2026-88033]

Upgrade reactive/sync driver version to 5.11.1 or later.

If you cannot upgrade, applications using older driver versions should call another delete overload delete(ObjectId). The driver constructs the BsonObjectId internally from a typed value, so no document can reach the filter.

[!WARNING] Starting from driver version 4.2.0, cancelling or timing out an encrypted operation while the driver fetches cloud KMS credentials makes it call into freed native memory, crashing or corrupting the application.

See JAVA-6266 / CVE-2026-88032

Upgrade both reactive driver and mongodb-crypt to version 5.11.1 or later.

Full Changelog: mongodb/mongo-java-driver@r5.11.0...r5.11.1

Commits

Updates org.mongodb:mongodb-driver-legacy from 5.11.0 to 5.11.1

Release notes

Sourced from org.mongodb:mongodb-driver-legacy's releases.

Java Driver 5.11.1 (September 10, 2026)

What's Changed

[!WARNING] Starting from driver version 3.3.0, an improper neutralization of a query operator in the GridFS delete methods allowed unintended data deletion.

See JAVA-6283 / CVE-2026-88033]

Upgrade reactive/sync driver version to 5.11.1 or later.

If you cannot upgrade, applications using older driver versions should call another delete overload delete(ObjectId). The driver constructs the BsonObjectId internally from a typed value, so no document can reach the filter.

[!WARNING] Starting from driver version 4.2.0, cancelling or timing out an encrypted operation while the driver fetches cloud KMS credentials makes it call into freed native memory, crashing or corrupting the application.

See JAVA-6266 / CVE-2026-88032

Upgrade both reactive driver and mongodb-crypt to version 5.11.1 or later.

Full Changelog: mongodb/mongo-java-driver@r5.11.0...r5.11.1

Commits

Updates net.bytebuddy:byte-buddy from 1.18.13 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-dependencies group with 3 updates: [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver), [org.mongodb:mongodb-driver-legacy](https://github.com/mongodb/mongo-java-driver) and [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy).


Updates `org.mongodb:mongodb-driver-sync` from 5.11.0 to 5.11.1
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.11.0...r5.11.1)

Updates `org.mongodb:mongodb-driver-legacy` from 5.11.0 to 5.11.1
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.11.0...r5.11.1)

Updates `org.mongodb:mongodb-driver-legacy` from 5.11.0 to 5.11.1
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.11.0...r5.11.1)

Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14)

---
updated-dependencies:
- dependency-name: org.mongodb:mongodb-driver-sync
  dependency-version: 5.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.mongodb:mongodb-driver-legacy
  dependency-version: 5.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.mongodb:mongodb-driver-legacy
  dependency-version: 5.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 18, 2026
@github-actions
github-actions Bot merged commit 658410b into 2.5.x Sep 18, 2026
3 checks passed
@github-actions
github-actions Bot deleted the dependabot/maven/2.5.x/maven-dependencies-1e093a174d branch September 18, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants