Third-Party Package Updates in Splunk SOAR - February 2026

Advisory ID: SVD-2026-0201

CVE ID:  Multiple

Published: 2026-02-04

Last Update: 2026-02-04

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk SOAR version 7.1.0.

PackageRemediationCVESeverity
sha.jsUpgraded to v2.4.12CVE-2025-9288Critical
cipher-baseUpgraded to v1.0.5CVE-2025-9287Critical
jspdfUpgraded to v3.0.2CVE-2025-57810High
postgresql1Upgraded to v15.4MultipleHigh
djangoUpgraded to v4.2.22CVE-2025-32873Medium
brace-expansionUpgraded to v2.0.2CVE-2025-5889Low
requestsUpgraded to v2.32.4CVE-2024-47081Medium
tornadoUpgraded to v6.5.2CVE-2025-47287High

1 Upgraded posgresql to v15.4 to remediate CVE-2025-8715, CVE-2025-8714 and CVE-2025-8713

Solution

Upgrade Splunk SOAR to versions 7.1.0 or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk SOAR7.1Below 7.1.07.1.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.