Replies: 5 comments 8 replies
-
|
there are some comments on FasterXML/jackson-databind#6041 (comment) |
Beta Was this translation helpful? Give feedback.
-
|
We should keep this open so that we can centralise all the question traffic. There is a fix for CVE-2026-54515 / GHSA-5jmj-h7xm-6q6v in jackson 3.1.4 and 3.2.0 (already released) |
Beta Was this translation helpful? Give feedback.
-
|
Coming from #6073: The main issue I filed the other report is that Spring boot uses both Jackson 2 and 3. We bumped jackson 3 to 3.1.4 last week, so that one is fine; but we had to bump jackson 2, too. The Issue was marked to be fixed in 2.21.5, which is unavailable, so I had to bump to 2.22.0, but CVE-2026-54515 now is marked to be in 2.22.0, too. Best, Jan |
Beta Was this translation helpful? Give feedback.
-
|
Cannot move to Jackson3 at this point and vulnerability fix is not available for CVE-2026-54515. Commenting here so as to get the update on release of 2.21.5 or 2.22.1. |
Beta Was this translation helpful? Give feedback.
-
|
Jackson 2.21.5 release starting now. EDIT: and now completed. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello!
Is there any current information about the planned release date for Jackson 2.22.1? We're monitoring the updates to fix
CVE-2026-54515, but we'd like to confirm the approximate timeframe so we can adjust our plans accordingly. Thank you in advance for your response!Beta Was this translation helpful? Give feedback.
All reactions