Skip to content

fix(QTDI-3275): bump jsoup 1.15.3 -> 1.23.2 (CVE-2026-71497) - #1281

Open
wwang-talend wants to merge 1 commit into
masterfrom
fix/QTDI-3275-cve-71497
Open

wwang-talend wants to merge 1 commit into
masterfrom
fix/QTDI-3275-cve-71497

Conversation

@wwang-talend

@wwang-talend wwang-talend commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Requirements

N/A — dependency version bump only, no logic change.

Why this PR is needed?

Fixes QTDI-3275CVE-2026-71497 in org.jsoup:jsoup (XSS via malformed tag names with custom raw-text Safelists). Affects documentation and component-runtime-testing (internal build/test tooling modules, not Studio-facing).

What does this PR adds (design/code thoughts)?

Bumps the jsoup.version property in the root pom.xml from 1.15.3 to 1.23.2 (patched line is 1.23.1+; 1.23.2 is the latest available patch release).

This CVE affects 6 repos in total (connectors-ee, connectors-se, cloud-components, component-runtime, components-ee, studio) — companion PRs are being opened in each under the same branch name fix/QTDI-3275-cve-71497.

AI generated code

https://internal.qlik.dev/general/ways-of-working/code-reviews/#guidelines-for-ai-generated-code

  • this PR has been written with the help of GitHub Copilot or another generative AI tool

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@sonar-rnd

sonar-rnd Bot commented Sep 16, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant