[Bug] Upgrade shaded org.asynchttpclient:async-http-client <3.0.1 due to CVE #23745
Closed
3 tasks done
Labels
type/bug
The PR fixed a bug or issue reported a bug
Search before asking
Read release policy
Version
pulsar-client:3.3.2
Minimal reproduce step
pulsar-client has a dependence on async-http-client in a version (2.12.1) that has a critical CVE:
GHSA-mfj5-cf8g-g2fv
What did you expect to see?
I'd like to be able to use pulsar-client without any critical/high CVEs included.
What did you see instead?
A critical CVE is detected when I use pulsar-client.
Anything else?
No response
Are you willing to submit a PR?
The text was updated successfully, but these errors were encountered: