Skip to content

Upgrade version of antisamy to 1.7.8 to update transitive dependency affected by CVE-2025-27820 #876

@NilsRenaud

Description

@NilsRenaud

The issue

ESAPI 2.6.0.0 depends on antisamy 1.7.7 which depends on apache http client 5.4.1 which has a known vulnerability: CVE-2025-27820.

The solution

Antisamy released a new version: 1.7.8 which uses on a fixed Apache HTTP Client. ESAPI only have to update its version of antisamy.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions