Third-Party Package Updates in Splunk DB Connect - February 2026

Advisory ID: SVD-2026-0212

CVE ID:  Multiple

Published: 2026-02-18

Last Update: 2026-02-18

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk DB Connect version 4.2.0 including the following:

PackageRemediationCVESeverity
qsUpgraded to version 6.14.1CVE-2025-15284Low
urllib3Upgraded to version 2.6.3CVE-2026-21441High

Solution

Upgrade Splunk DB Connect to versions 4.2.0 or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk DB Connect4.2Below 4.2.04.2.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.