Bump: Remediating CVE-2026-66755?

Hi,

I hope it’s okay to bump this topic, since it’s gotten no replies more than a week ago. Let me know otherwise and I can delete.

I created an issue for the CVE mentioned in the title, it is something to do with metabase v0.63.14.2 using an out-of-date version of Apache Tika Core. My org and I want to roll out an up-to-date version of Metabase to production but this one CVE blocks the pipeline from deploying it successfully. Our scanner picked it up and it is of high severity. I hope this is the right place to bring it up; can we get an ETA from Metabase team on when the dependency update can be merged to master?

Issue: Bump Apache Tika Core from 3.2.3 to 3.3.2 to patch CVE-2026-66755 · Issue #81031 · metabase/metabase · GitHub

Let me know if more information is required. Thanks.

-Ryan