Hi,
The following vulnerabilities were published for jackrabbit.
CVE-2026-92414[0]:
| : Session Fixation / Session Reuse across Users vulnerability in
| Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached
| authenticated session on any Lock-
| Token/TransactionId/SubscriptionId/If-header field token match with
| no credential check. This issue affects Apache Jackrabbit: from
| 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0
| through 2.20.17. Users are recommended to upgrade to
| versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
CVE-2026-92415[1]:
| — Use of Externally-Controlled Input to Select Classes or Code
| vulnerability in Apache Jackrabbit's WebDAV/Davex client. A
| malicious WebDAV/DavEx server, or an attacker able to intercept the
| connection, can cause the client to instantiate arbitrary classes
| from its classpath, which can lead to arbitrary file creation or
| truncation. Only applications that use jackrabbit-spi2dav (directly
| or through jackrabbit-jcr2dav) to connect to a remote repository are
| affected. Jackrabbit servers are not affected. Category: unsafe
| reflection on wire data (HIGH). This issue affects Apache
| Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4,
| from 2.20.0 through 2.20.17. Users are recommended to upgrade to
| versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-92414
https://www.cve.org/CVERecord?id=CVE-2026-92414
https://www.openwall.com/lists/oss-security/2026/10/07/27
[1] https://security-tracker.debian.org/tracker/CVE-2026-92415
https://www.cve.org/CVERecord?id=CVE-2026-92415
https://www.openwall.com/lists/oss-security/2026/10/07/28
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore