Skip to content

Upgrade to Jackson 3.1.7 and Jackson 2.21.7 due to vulnerability (CVE-2026-91776) in jackson-databind - #51929

Closed
oikonomopo-k wants to merge 1 commit into
spring-projects:mainfrom
oikonomopo-k:gh-51928
Closed

oikonomopo-k wants to merge 1 commit into
spring-projects:mainfrom
oikonomopo-k:gh-51928

Conversation

Upgrades jacksonVersion to 3.1.7 and jackson2Version to 2.21.7 to address CVE-2026-91776 in jackson-databind.

Closes spring-projectsgh-51928
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Oct 1, 2026
@bclozel bclozel closed this Oct 1, 2026
@bclozel bclozel added status: invalid An issue that we don't feel is valid and removed status: waiting-for-triage An issue we've not yet triaged labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: invalid An issue that we don't feel is valid

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-91776 - vulnerability in jackson-databind

3 participants