Patched Vulnerabilities

This page provides information about the common security vulnerabilities that were patched in Graph Studio and Graph Lakehouse releases.

Graph Studio Releases Graph Lakehouse Releases

Altair Graph Studio Releases

Graph Studio 2025.1 Engine v6.1

  • Fixes for Grapstudio Distributed Unstructured CVE-2025-48734: This addresses the need for a fix related to CVE-2025-48734 for Graph Studio Distributed Unstructured Users.
  • DOMPurify js library updated due to CVE: This updates DOMPurify JavaScript library due to a CVE.
  • Journal query performance regression: This fix addresses a regression in journal query performance.

Graph Studio 2025.0.1 Engine v6.0.1

  • CVE-2024-21235 (Medium Severity): Addresses multiple CVEs in openjdk and jetty components, enhancing core Java security.
  • Multiple High Severity CVEs in Unstructured Components: Resolves multiple high-severity CVEs in okio and openjdk, preventing unauthenticated network compromise and data manipulation.
  • CVE-2025-25193 (Medium Severity) in Netty: Fixes CVE-2025-25193 in netty-common, improving network communication integrity.
  • CVE-2025-1391 in Keycloak Services: Resolves CVE-2025-1391 in keycloak-services, strengthening SSO security.
  • CVE-2025-27553 (High Severity) in Commons VFS2: Patches high-severity CVE-2025-27553 in commons-vfs2, critical for secure pipeline data flows.
  • CVE-2024-13009 (High Severity) in Jetty Server: Fixes high-severity CVE-2024-13009 in jetty-server, preventing data corruption and sharing issues.
  • Keycloak CVE-2025-3501: Resolves Keycloak CVE-2025-3501, which allowed bypassing trust store verification. CVE-2019-9628 was a false positive.
  • Update to Latest Keycloak Libraries: Updates Keycloak libraries to version 26.1.5 to mitigate various CVEs and enhance authentication security.
  • Elasticsearch Update: Updates Elasticsearch to address CVE-2024-52981, securing search and indexing functions.
  • XSS Security Fix for Object Titles: Patches an XSS vulnerability that allowed malicious scripts in object titles, improving UI security.

Graph Lakehouse / AnzoGraph Releases

Graph Lakehouse 2026.0 Database v3.3.0

  • CVE-2025-46762: The org.apache.parquet dependency was updated to remediate this vulnerability.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-32989, CVE-2025-32990, CVE-2025-32988, CVE-2025-6395: The GnuTLS library was updated to remediate various potential vulnerabilities related to this dependency.

Graph Lakehouse 2025.0 Database v3.2.2

  • CVE-2025-22870 : The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-27553 : The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-22871 : The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872 : The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-1948 : The Eclipse Jetty dependency was updated to remediate this vulnerability in the Jetty HTTP/2 server.

Graph Lakehouse 2025.0 Database v3.2.1

Graph Lakehouse 2025.0 Database v3.2.0

AnzoGraph 3.1.8

  • CVE-2024-45336: The golang net/http package dependency was updated to remediate this vulnerability.
  • CVE-2024-45341: The golang crypto/x509 package dependency was updated to remediate this vulnerability.
  • CVE-2025-22870: The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-27553: The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
  • CVE-2025-48734: The Apache commons dependency was updated to remediate this potential Improper Access Control vulnerability.
  • CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
  • CVE-2025-47907: The golang database/sql package dependency was updated to remediate vulnerability.
  • CVE-2025-4674: The golang package was updated to remediate issues related to unexpected code execution.
  • CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
  • CVE-2025-5115: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential HTTP/2 MadeYouReset DoS vulnerability.

AnzoGraph 3.1.7

AnzoGraph 3.1.6

  • GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XML external entity (XXE) vulnerability in the jetty XmlParser.
  • CVE-2024-43382: The Snowflake JDBC driver dependency was updated to remediate this incorrect security setting vulnerability.
  • GHSA-w32m-9786-jp63, CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.

AnzoGraph 3.1.5

  • CVE-2024-47554: The Apache Commons IO dependency of the Neptune extension library of Graph Lakehouse DB was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-48910: The DOMPurify dependency was upgraded to version 2.4.2 to remediate this Prototype Pollution vulnerability.

AnzoGraph 3.1.4

  • CVE-2024-34156: The encoding/gob package dependency was updated to remediate this stack exhaustion vulnerability (Go upgraded to version 1.23.1).
  • CVE-2024-7254: The Protocol Buffers parser dependency was updated to remediate this improper input validation vulnerability.
  • CVE-2024-45801: The DOMPurify dependency was upgraded to remediate this XSS attack vulnerability.
  • CVE-2024-43591: The Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability was remediated.
  • CVE-2024-2398: The libcurl dependency was upgraded from version 8.1.2 to 8.10.1 to further remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-47554: The Apache Commons IO dependency was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
  • CVE-2024-8184: The Eclipse jetty dependency was updated to version 12.0.12 to remediate a potential remote Denial of Service (DoS) attack vulnerability.

AnzoGraph 3.1.3

  • CVE-2024-2398: The libcurl dependency was updated to remediate this HTTP/2 push headers memory-leak vulnerability.
  • CVE-2024-6345: The pypa/setuptools dependency was upgraded to remediate this vulnerability.

AnzoGraph 3.1.2

  • CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).
  • CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
  • CVE-2023-6597: The CPython dependency for the frontend user interface was updated to remediate this tempfile.TemporaryDirectory class vulnerability.
  • CVE-2023-52424: A dependency for the frontend user interface was updated to remediate the SSID Confusion Attack vulnerability.
  • CVE-2024-24788: A golang dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).

AnzoGraph 3.1.1

  • CVE-2024-30172: The BC Java Cryptography API dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-21634: The BC Java, BC-FJA, and BC C# .Net library dependencies for the frontend user interface were updated to remediate this vulnerability.
  • CVE-2024-29857: The ion-java dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.

AnzoGraph 3.1.0

AnzoGraph 2.5.23

  • CVE-2025-52999: The jackson-core dependency was updated to remediate a potential Denial-of-Service vulnerability.
  • CVE-2025-24970, CVE-2024-29025, CVE-2025-25193, CVE-2024-47535, CVE-2023-34462: The Netty library dependency for GDI and the front-end user interface was updated to remediate this vulnerability.
  • CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2020-13956: The org.apache.httpcomponents package dependency was updated to remediate this vulnerability.
  • SONATYPE-2012-0050: The Apache commons-codec package was updated to remediate this vulnerability.
  • CVE-2023-35116: The jackson-databind dependency was updated to remediate this vulnerability.
  • CVE-2024-43382: The Snowflake JDBC driver was updated to remediate this security setting vulnerability.
  • CVE-2024-48910, CVE-2024-45801: The DOMPurify JavaScript library was updated to remediate this vulnerability, preventing security bypasses and unauthorized modifications of application behavior.
  • CVE-2024-43591: The Azure CLI and Azure Service Connector was updated to remediate this Azure Command Line Integration (CLI) Elevation of Privilege vulnerability.
  • CVE-2024-47554: The Apache Commons IO dependency was updated to address this potential Denial of Service (DoS) vulnerability.
  • CVE-2024-8184: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2024-34156: The encoding/gob package of the Golang standard library was updated to remediate a potential Denial of Service (DoS) vulnerability.
  • CVE-2024-7254: The protobuf dependency for the frontend user interface was updated to address this potential Denial of Service (DoS) vulnerability.
  • CVE-2019-5827, CVE-2014-3566: The nss, nss-tools, sqlite, and nss-sysinit libraries were updated to remediate these vulnerabilities.
  • CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
  • CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
  • CVE-2025-27553: The Apache Commons VFS dependency was updated to remediate this Relative Path Traversal vulnerability.

  • CVE-2025-0665, CVE-2025-0725, CVE-2024-2398: The libcurl library dependency was upgraded to version 8.12.0 to remediate this vulnerability.

  • CVE-2023-2976, CVE-2020-8908: The Google Guava library dependency was updated to remediate these vulnerabilities.