Skip to content

Bump jackson-bom to 2.18.11 to fix jackson-databind vulnerabilities - #7

Merged
anishi1222 merged 1 commit into
Reactor-Basedfrom
copilot/address-dependency-vulnerabilities
Oct 1, 2026
Merged

anishi1222 merged 1 commit into
Reactor-Basedfrom
copilot/address-dependency-vulnerabilities

Conversation

Copilot AI commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This fixes the known vulnerabilities in the resolved dependency tree. The only affected package was jackson-databind 2.18.9, which the Azure SDK pulls in through jackson-bom.

-        <jackson.bom.version>2.18.9</jackson.bom.version>
+        <jackson.bom.version>2.18.11</jackson.bom.version>

Advisories addressed (jackson-databind, fixed in 2.18.11)

  • Quadratic forward-reference completion: CPU denial of service. Affects 2.5.0 through 2.18.10.
  • Retention of every unknown raw type ID: unbounded memory growth. Affects 2.0.0 through 2.18.10.
  • Unbounded number parsing for Duration / XMLGregorianCalendar: denial of service. Affects 2.14.0 up to, but not including, 2.18.10.

Scope

  • The bump also moves jackson-core, jackson-annotations and jackson-datatype-jsr310 to 2.18.11. The GitHub Advisory Database reports nothing against them.
  • It stays on the 2.18.x line to avoid a minor-version jump under the Azure SDK BOM.
  • Every other resolved dependency was checked against the GitHub Advisory Database, including transitive ones (Azure SDK, msal4j, Netty, Reactor, JNA and the test libraries). None had advisories, so they are unchanged.
  • The open Dependabot alerts were not cross-checked directly, so please confirm none remain after merge.

Co-authored-by: anishi1222 <11570959+anishi1222@users.noreply.github.com>
@anishi1222
anishi1222 marked this pull request as ready for review October 1, 2026 06:59
@anishi1222
anishi1222 merged commit ca019cd into Reactor-Based Oct 1, 2026
2 checks passed
@anishi1222
anishi1222 deleted the copilot/address-dependency-vulnerabilities branch October 1, 2026 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants