lhotari opened a new issue, #26126: URL: https://github.com/apache/pulsar/issues/26126
> `2.21.4` resolves six of the seven advisories, but `CVE-2026-54515` is only fixed in `2.21.5`, which was never published to Maven Central (the 2.21.x line went straight from 2.21.4 to 2.22.0). `2.22.0` is therefore the lowest available version that clears all seven. I think that we should downgrade back to 2.21.x [since it's a LTS branch](https://github.com/FasterXML/jackson/wiki/Jackson-Releases#open-branches). The 2.21.5 release is planned, but it hasn't been released yet: https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.21 _Originally posted by @lhotari in https://github.com/apache/pulsar/issues/26101#issuecomment-4852680356_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
