Skip to content

Jackson update because of multiple CVEs #7054

Description

@beth-soptim

Describe the bug

https://github.com/FasterXML/jackson-databind/security/advisories

Some CVEs are classified as critical by OSS Index, e.g. https://guide.sonatype.com/vulnerability/CVE-2026-54512

It seems that the Jackson GHSAs are not in the "global GHSA database".

This triggers our vulnerability scanners.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Jackson version used without vulnerabilities.

Current Behavior

Jackson version with security issues

Reproduction Steps

not relevant

Possible Solution

Update Jackson

#7018

Additional Information/Context

No response

AWS Java SDK version used

2 2.46.14

JDK version used

openjdk version "25.0.3" 2026-04-21 LTS OpenJDK Runtime Environment Zulu25.34+17-CA (build 25.0.3+9-LTS) OpenJDK 64-Bit Server VM Zulu25.34+17-CA (build 25.0.3+9-LTS, mixed mode, sharing)

Operating System and version

Windows 11

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis issue is a bug.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions