Third-party vulnerabilities

GraphDB uses a number of third-party libraries as dependencies. To ensure a secure and reliable product, Ontotext performs regular vulnerability scans and takes appropriate actions to address any newly identified vulnerabilities.

Typically, vulnerabilities are addressed by upgrading the affected libraries to a newer version, where the vulnerability was fixed.

When it is not possible to upgrade a library, Ontotext addresses each case individually. This may include a statement that a vulnerability does not apply to GraphDB, an Ontotext patch for that vulnerability, or both.

Currently, there is one high vulnerability, and there are no known identified critical vulnerabilities in GraphDB 11.3.3:

Vulnerability

Severity

Description

CVE-2026-2332

7.4 High

CVE-2026-2332 is an HTTP/1.1 request smuggling vulnerability in Jetty’s server-side HttpParser. Our usage of jetty-http is exclusively as an outbound HTTP client. The vulnerable server-side parsing code path is never executed in our deployment. The attack preconditions are not met. Therefore this is not exploitable in this configuration.