Skip to content

Upgrade version of antisamy to 1.7.8 to update transitive dependency affected by CVE-2025-27820 #876

@NilsRenaud

Description

@NilsRenaud

The issue

ESAPI 2.6.0.0 depends on antisamy 1.7.7 which depends on apache http client 5.4.1 which has a known vulnerability: CVE-2025-27820.

The solution

Antisamy released a new version: 1.7.8 which uses on a fixed Apache HTTP Client. ESAPI only have to update its version of antisamy.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions