Hi, will it be possible to cut a patch release that fixes, https://spring.io/security/cve-2023-34062. It looks like the main branch targeting 3.2.x already pulls in the right version of reactor-bom(https://github.com/reactor/reactor/releases/tag/2023.0.0) with the fix for reactor-netty-http
Comment From: philwebb
We have releases planned for Thursday (you can always find our release schedule at https://calendar.spring.io/). If you need to upgrade before then you should update your pom.xml or build.gradle file directly.