The project currently depends on Jackson 2.10.3 which has a known CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-36518. Should update to jackson-databind 2.12.6.1 or later.