Hi Colm

Not a problem. I am canceling this vote to prepare RC2 including the
jackson update.

Regards
JB

On Fri, Jul 24, 2026 at 8:23 AM Colm O hEigeartaigh <[email protected]> wrote:
>
> Hi JB,
>
> Is it too late to cherry-pick
> https://github.com/apache/activemq/commit/d1fd0aa953060c7d933def98691d90ac17da174d
> and re-spin the releases? There are some Jackson CVEs:
>
> │ com.fasterxml.jackson.core:jackson-core                   │
> GHSA-r7wm-3cxj-wff9 │ HIGH     │ fixed  │ 2.22.0            │ 2.18.8,
> 2.21.4, 2.22.1                     │ jackson-core: Async parser
> maxNumberLength bypass via      │
> │ (jackson-core-2.22.0.jar)                                 │
>            │          │        │                   │
>                          │ chunked digit accumulation (incomplete fix
> for...          │
> │                                                           │
>            │          │        │                   │
>                          │
> https://github.com/advisories/GHSA-r7wm-3cxj-wff9          │
> ├───────────────────────────────────────────────────────────┼─────────────────────┼──────────┤
>        │
> ├────────────────────────────────────────────┼────────────────────────────────────────────────────────────┤
> │ com.fasterxml.jackson.core:jackson-databind               │
> CVE-2026-54515      │ MEDIUM   │        │                   │ 3.1.4,
> 2.18.9, 2.21.5, 2.22.1              │ jackson-databind:
> jackson-databind: Ignored properties can │
> │ (jackson-databind-2.22.0.jar)                             │
>            │          │        │                   │
>                          │ be unexpectedly modified
>                │
> │                                                           │
>            │          │        │                   │
>                          │ https://avd.aquasec.com/nvd/cve-2026-54515
>                │
> │
> ├─────────────────────┤          │        │
> ├────────────────────────────────────────────┼────────────────────────────────────────────────────────────┤
> │                                                           │
> CVE-2026-59889      │          │        │                   │ 2.21.5,
> 2.18.9, 2.22.1                     │ jackson-databind: @JsonView
> ypassed for @JsonUnwrapped     │
> │                                                           │
>            │          │        │                   │
>                          │ container properties on deserialization
>                │
> │                                                           │
>            │          │        │                   │
>                          │ https://avd.aquasec.com/nvd/cve-2026-59889
>                │
> ├───────────────────────────────────────────────────────────┼───────────────────
>
> Colm.
>
> On Fri, Jul 24, 2026 at 5:34 AM Jean-Baptiste Onofré <[email protected]> 
> wrote:
> >
> > Hi everyone,
> >
> > I propose Apache ActiveMQ 6.2.8 (rc1) release for your vote.
> >
> > This is a maintenance release for the 6.2.x series, including:
> > - Add better frame size validation for AMQP
> > - Prevent cursor from using more than 100% temp store
> > - Fire message discarded advisory on format errors
> > - Add metrics about error and reconnect counts to network connector
> > - Expose NetworkConnector URI and local URI in JMX MBean
> >
> > You can review the Pre-Release Notes for details:
> > https://github.com/apache/activemq/releases/tag/activemq-6.2.8
> >
> > Staging Maven Repository:
> > https://repository.apache.org/content/repositories/orgapacheactivemq-1495/
> >
> > Staging Dist Repository:
> > https://dist.apache.org/repos/dist/dev/activemq/activemq/6.2.8/
> >
> > Git tag:
> > https://github.com/apache/activemq/tree/activemq-6.2.8
> >
> > Please vote to approve this release:
> > [ ] +1 Approve the release
> > [ ] 0 I don't care
> > [ ] -1 Don't approve the release (please provide specific comment)
> >
> > This vote will be open for at least 72 hours.
> >
> > Thanks!
> > Regards
> > JB
> >
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> > For further information, visit: https://activemq.apache.org/contact
> >
> >

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact


Reply via email to