Skip to content

Bump owasp.encoder.version from 1.4.0 to 1.4.1 - #391

Merged
dschadow merged 1 commit into
mainfrom
dependabot/maven/owasp.encoder.version-1.4.1
Sep 30, 2026
Merged

dschadow merged 1 commit into
mainfrom
dependabot/maven/owasp.encoder.version-1.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps owasp.encoder.version from 1.4.0 to 1.4.1.
Updates org.owasp.encoder:encoder from 1.4.0 to 1.4.1

Release notes

Sourced from org.owasp.encoder:encoder's releases.

v1.4.1 — Security release

OWASP Java Encoder 1.4.1

Version 1.4.1 is available from Maven Central. Published on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles) from the original retained signed bundle. All 12 binary/source/Javadoc JARs, five POMs, and their 17 signatures were downloaded from Central and matched the original release byte for byte. Versions through 1.4.0 remain affected.

Central artifacts: encoder, encoder-jsp, encoder-jakarta-jsp, encoder-esapi, encoder-parent.

Security fixes

Upgrade all OWASP Java Encoder dependencies to 1.4.1. Versions through 1.4.0 are affected by the following issues:

  • GHSA-57jg-769q-93vh: EncodedWriter could lose encoding context when pending lookahead overflowed its output buffer, allowing CDATA or XML comment delimiters to escape and dropping or duplicating characters. The fix preserves unconsumed input across buffer flushes.
  • GHSA-q6jj-5396-8mq2: EncodedWriter could loop indefinitely when a write did not supply enough input to resolve pending lookahead. The fix retains pending input for the next write or close instead of spinning.
  • GHSA-p9ff-j89j-9xhx: long runs of U+2028 or U+2029 could cause the String overloads of Encode.forCssString and Encode.forCssUrl to throw AssertionError. The fix corrects the maximum encoded output size. The JSP/Jakarta CSS EL functions and the ESAPI CSS adapter also benefit from this fix.

The first two issues require direct use of EncodedWriter; the Encode facade, JSP/Jakarta tags, and ESAPI adapter do not call it internally. The CSS size issue affects String-returning APIs; Writer overloads and CSS tags are unaffected.

Compatibility and other changes

  • Java 8 remains the minimum runtime. Build and test with JDK 17.
  • Public method signatures, Maven coordinates, explicit JPMS module names, and historical Automatic-Module-Name values are retained.
  • The JSP, Jakarta, and ESAPI module descriptors now expose their public API dependencies transitively (#98).
  • The ESAPI adapter now uses a fixed ESAPI 2.7.0.0 dependency; tested compatibility is documented in esapi/README.md (#99).
  • Build tooling, packaged OSGi compatibility tests, project metadata, and Jakarta test dependency alignment have been updated (#90, #106).

Maven artifacts

Use version 1.4.1 for every artifact you consume:

Group ID Artifact ID
org.owasp.encoder encoder
org.owasp.encoder encoder-jsp
org.owasp.encoder encoder-jakarta-jsp
org.owasp.encoder encoder-esapi

... (truncated)

Changelog

Sourced from org.owasp.encoder:encoder's changelog.

1.4.1 — 2026-09-26 UTC

Signed GitHub release (tag created 2026-09-25 in America/Los_Angeles). Available from Maven Central. Upgrade all four Java Encoder artifacts; versions through 1.4.0 are affected. Central publication was verified on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles); all artifacts and signatures match the retained release.

  • Fix EncodedWriter context corruption during buffer overflow (GHSA-57jg-769q-93vh).
  • Fix insufficient-lookahead infinite loops in EncodedWriter (GHSA-q6jj-5396-8mq2).
  • Fix CSS String API maximum-output sizing for long U+2028/U+2029 runs (GHSA-p9ff-j89j-9xhx).
  • Preserve Java 8 runtime, public method signatures, Maven and JPMS identities; make adapter API dependencies transitively readable in module descriptors.
  • Pin the ESAPI adapter's default to 2.7.0.0 rather than a Maven version range.

See the full release record for affected entry points, coordinates, verification and publication status. Later 1.5 changes do not alter these retained artifacts.

Commits
  • ab76d58 Use primary OWASP release email and document pending Central access
  • b51c575 Prepare 1.4.1 security release with a dedicated project signing key
  • 0583c22 Fix EncodedWriter handling of pending lookahead characters
  • d15c6fe Fix CSSEncoder.maxEncodedLength for U+2028 and U+2029
  • b52a954 Merge pull request #150 from OWASP/docs/security-policy
  • 80851e3 Qualify the SECURITY.md upgrade note with the Java 8 baseline
  • 16312e6 Expand the security policy now that private reporting is enabled
  • 14fd1c5 Merge pull request #106 from OWASP/fix/jakarta-test-encoder-version
  • 2a55ccc Merge pull request #98 from OWASP/fix/jpms-adapter-dependencies
  • 316290a Merge main into fix/jpms-adapter-dependencies
  • Additional commits viewable in compare view

Updates org.owasp.encoder:encoder-jsp from 1.4.0 to 1.4.1

Release notes

Sourced from org.owasp.encoder:encoder-jsp's releases.

v1.4.1 — Security release

OWASP Java Encoder 1.4.1

Version 1.4.1 is available from Maven Central. Published on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles) from the original retained signed bundle. All 12 binary/source/Javadoc JARs, five POMs, and their 17 signatures were downloaded from Central and matched the original release byte for byte. Versions through 1.4.0 remain affected.

Central artifacts: encoder, encoder-jsp, encoder-jakarta-jsp, encoder-esapi, encoder-parent.

Security fixes

Upgrade all OWASP Java Encoder dependencies to 1.4.1. Versions through 1.4.0 are affected by the following issues:

  • GHSA-57jg-769q-93vh: EncodedWriter could lose encoding context when pending lookahead overflowed its output buffer, allowing CDATA or XML comment delimiters to escape and dropping or duplicating characters. The fix preserves unconsumed input across buffer flushes.
  • GHSA-q6jj-5396-8mq2: EncodedWriter could loop indefinitely when a write did not supply enough input to resolve pending lookahead. The fix retains pending input for the next write or close instead of spinning.
  • GHSA-p9ff-j89j-9xhx: long runs of U+2028 or U+2029 could cause the String overloads of Encode.forCssString and Encode.forCssUrl to throw AssertionError. The fix corrects the maximum encoded output size. The JSP/Jakarta CSS EL functions and the ESAPI CSS adapter also benefit from this fix.

The first two issues require direct use of EncodedWriter; the Encode facade, JSP/Jakarta tags, and ESAPI adapter do not call it internally. The CSS size issue affects String-returning APIs; Writer overloads and CSS tags are unaffected.

Compatibility and other changes

  • Java 8 remains the minimum runtime. Build and test with JDK 17.
  • Public method signatures, Maven coordinates, explicit JPMS module names, and historical Automatic-Module-Name values are retained.
  • The JSP, Jakarta, and ESAPI module descriptors now expose their public API dependencies transitively (#98).
  • The ESAPI adapter now uses a fixed ESAPI 2.7.0.0 dependency; tested compatibility is documented in esapi/README.md (#99).
  • Build tooling, packaged OSGi compatibility tests, project metadata, and Jakarta test dependency alignment have been updated (#90, #106).

Maven artifacts

Use version 1.4.1 for every artifact you consume:

Group ID Artifact ID
org.owasp.encoder encoder
org.owasp.encoder encoder-jsp
org.owasp.encoder encoder-jakarta-jsp
org.owasp.encoder encoder-esapi

... (truncated)

Changelog

Sourced from org.owasp.encoder:encoder-jsp's changelog.

1.4.1 — 2026-09-26 UTC

Signed GitHub release (tag created 2026-09-25 in America/Los_Angeles). Available from Maven Central. Upgrade all four Java Encoder artifacts; versions through 1.4.0 are affected. Central publication was verified on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles); all artifacts and signatures match the retained release.

  • Fix EncodedWriter context corruption during buffer overflow (GHSA-57jg-769q-93vh).
  • Fix insufficient-lookahead infinite loops in EncodedWriter (GHSA-q6jj-5396-8mq2).
  • Fix CSS String API maximum-output sizing for long U+2028/U+2029 runs (GHSA-p9ff-j89j-9xhx).
  • Preserve Java 8 runtime, public method signatures, Maven and JPMS identities; make adapter API dependencies transitively readable in module descriptors.
  • Pin the ESAPI adapter's default to 2.7.0.0 rather than a Maven version range.

See the full release record for affected entry points, coordinates, verification and publication status. Later 1.5 changes do not alter these retained artifacts.

Commits
  • ab76d58 Use primary OWASP release email and document pending Central access
  • b51c575 Prepare 1.4.1 security release with a dedicated project signing key
  • 0583c22 Fix EncodedWriter handling of pending lookahead characters
  • d15c6fe Fix CSSEncoder.maxEncodedLength for U+2028 and U+2029
  • b52a954 Merge pull request #150 from OWASP/docs/security-policy
  • 80851e3 Qualify the SECURITY.md upgrade note with the Java 8 baseline
  • 16312e6 Expand the security policy now that private reporting is enabled
  • 14fd1c5 Merge pull request #106 from OWASP/fix/jakarta-test-encoder-version
  • 2a55ccc Merge pull request #98 from OWASP/fix/jpms-adapter-dependencies
  • 316290a Merge main into fix/jpms-adapter-dependencies
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `owasp.encoder.version` from 1.4.0 to 1.4.1.

Updates `org.owasp.encoder:encoder` from 1.4.0 to 1.4.1
- [Release notes](https://github.com/owasp/owasp-java-encoder/releases)
- [Changelog](https://github.com/OWASP/owasp-java-encoder/blob/main/CHANGELOG.md)
- [Commits](OWASP/owasp-java-encoder@v1.4.0...v1.4.1)

Updates `org.owasp.encoder:encoder-jsp` from 1.4.0 to 1.4.1
- [Release notes](https://github.com/owasp/owasp-java-encoder/releases)
- [Changelog](https://github.com/OWASP/owasp-java-encoder/blob/main/CHANGELOG.md)
- [Commits](OWASP/owasp-java-encoder@v1.4.0...v1.4.1)

---
updated-dependencies:
- dependency-name: org.owasp.encoder:encoder
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.owasp.encoder:encoder-jsp
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 30, 2026
@dschadow
dschadow merged commit ce6d9e1 into main Sep 30, 2026
3 checks passed
@dschadow
dschadow deleted the dependabot/maven/owasp.encoder.version-1.4.1 branch September 30, 2026 06:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant