Skip to content

[Backport 2.13] Bump org.apache.logging.log4j:log4j-bom from 2.25.1 to 2.25.3 in /data-prepper-core#6516

Merged
dlvenable merged 1 commit into
2.13from
backport/backport-6376-to-2.13
Feb 16, 2026
Merged

[Backport 2.13] Bump org.apache.logging.log4j:log4j-bom from 2.25.1 to 2.25.3 in /data-prepper-core#6516
dlvenable merged 1 commit into
2.13from
backport/backport-6376-to-2.13

Conversation

@opensearch-trigger-bot

Copy link
Copy Markdown
Contributor

Backport 1ed9cfb from #6376

Bumps [org.apache.logging.log4j:log4j-bom](https://github.com/apache/logging-log4j2) from 2.25.1 to 2.25.3.
- [Release notes](https://github.com/apache/logging-log4j2/releases)
- [Changelog](https://github.com/apache/logging-log4j2/blob/2.x/RELEASE-NOTES.adoc)
- [Commits](apache/logging-log4j2@rel/2.25.1...rel/2.25.3)

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-bom
  dependency-version: 2.25.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit 1ed9cfb)
@dlvenable dlvenable merged commit d936db9 into 2.13 Feb 16, 2026
47 of 49 checks passed
@dlvenable

Copy link
Copy Markdown
Member

Fixes CVE-2025-68161

@dlvenable dlvenable added this to the v.2.13.1 milestone Feb 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant