Skip to content

UID2-8029, UID2-8030, UID2-8031, UID2-8032: upgrade jackson to 2.21.7 (CVE-2026-89407, CVE-2026-89425, CVE-2026-91776, CVE-2026-91777) - #434

Merged
swibi-ttd merged 1 commit into
mainfrom
swi-UID2-8030-jackson-2.21.7
Oct 6, 2026
Merged

swibi-ttd merged 1 commit into
mainfrom
swi-UID2-8030-jackson-2.21.7

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Upgrades jackson 2.21.6 → 2.21.7 (jackson.version).

  • CVE-2026-89407 (HIGH, jackson-core): Fixed in 2.21.7.
  • CVE-2026-89425 (HIGH, jackson-core): Vulnerable code path is not reachable in this configuration.
  • CVE-2026-91776 (HIGH, jackson-databind): Vulnerable code path is not reachable in this configuration.
  • CVE-2026-91777 (HIGH, jackson-databind): Vulnerable code path is not reachable in this configuration.

The assessment is recorded on the ticket in the title.

🤖 Generated with Claude Code

@swibi-ttd
swibi-ttd merged commit 0ae704b into main Oct 6, 2026
5 checks passed
@swibi-ttd
swibi-ttd deleted the swi-UID2-8030-jackson-2.21.7 branch October 6, 2026 05:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants