Skip to content

chore(deps): bump log4j2 from 2.20.0 to 2.26.1 - #5435

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/log4j2-2.26.0
Open

chore(deps): bump log4j2 from 2.20.0 to 2.26.1#5435
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/log4j2-2.26.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 14, 2026

Copy link
Copy Markdown
Contributor

Bumps log4j2 from 2.20.0 to 2.26.1.
Updates org.apache.logging.log4j:log4j-api from 2.20.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.20.0 to 2.26.1

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file Java SDK labels May 14, 2026
@dependabot
dependabot Bot requested review from adinauer, markushi and romtsn as code owners May 14, 2026 04:35
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 14, 2026
@dependabot dependabot Bot added the Java SDK label May 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/gradle/log4j2-2.26.0 branch from fcfe3bc to 4c8440b Compare June 2, 2026 21:45
@runningcode

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps `log4j2` from 2.20.0 to 2.26.1.

Updates `org.apache.logging.log4j:log4j-api` from 2.20.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.20.0 to 2.26.1

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump log4j2 from 2.20.0 to 2.26.0 chore(deps): bump log4j2 from 2.20.0 to 2.26.1 Aug 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/gradle/log4j2-2.26.0 branch from 4c8440b to eb5f7f1 Compare August 7, 2026 12:48
@socket-security

Copy link
Copy Markdown

Warning

Socket is a new tool Security team is testing out, feel free to ignore this alert for now but we encourage you to act on it.
Please provide any feedback you have in #discuss-security slack channel ❤️

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Apache Tomcat - Digest authenticator will authenticate any unknown user in maven org.apache.tomcat.embed:tomcat-embed-core

CVE: GHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown user (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: ?maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.108maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Apache Tomcat - Security constraints not correctly applied in maven org.apache.tomcat.embed:tomcat-embed-core

CVE: GHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly applied (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: ?maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.108maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Apache Tomcat - HTTP/2 request headers not validated in maven org.apache.tomcat.embed:tomcat-embed-core

CVE: GHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validated (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: ?maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.108maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Apache Tomcat - Digest authenticator will authenticate any unknown user in maven org.apache.tomcat:tomcat-catalina

CVE: GHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown user (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: gradle/libs.versions.tomlmaven/org.apache.tomcat/tomcat-catalina@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat/tomcat-catalina@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Apache Tomcat - Security constraints not correctly applied in maven org.apache.tomcat:tomcat-catalina

CVE: GHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly applied (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: gradle/libs.versions.tomlmaven/org.apache.tomcat/tomcat-catalina@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat/tomcat-catalina@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Apache Tomcat - HTTP/2 request headers not validated in maven org.apache.tomcat:tomcat-catalina

CVE: GHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validated (CRITICAL)

Affected versions: < 9.0.118; >= 10.1.0-M1 < 10.1.55; >= 11.0.0-M1 < 11.0.22

Patched version: 9.0.118

From: gradle/libs.versions.tomlmaven/org.apache.tomcat/tomcat-catalina@9.0.108

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.tomcat/tomcat-catalina@9.0.108. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Java SDK

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant