Remediating CVE-2026-66755

Hi,

I created an issue for the CVE mentioned in the title, it is something to do with metabase v0.63.14.2 using an out-of-date version of Apache Tika Core. My org and I want to roll out an up-to-date version of Metabase to production but this one CVE blocks the pipeline from deploying it successfully. Our scanner picked it up and it is of high severity. I hope this is the right place to bring it up; can we get an ETA on when the dependency update can be merged to master?

Thanks,

Ryan

this should get fixed in 64

1 Like

Thanks for the confirmation!

Do you have an ETA on when 64 will come out? I cannot find that information anywhere

we’ll decide that in the next few days

1 Like

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.