Crusherbone, a 9x patch bump to jackson fixes 4 CVEs:

| CVE | Component | Problem fixed |
|---|---|---|
| CVE-2026-89407 | jackson-core | Excessive regex processing when validating 
numbers |
| CVE-2026-89425 | jackson-core | Unbounded malformed-token error messages |
| CVE-2026-91776 | jackson-databind | Unbounded type-ID cache growth |
| CVE-2026-91777 | jackson-databind | Quadratic processing during 
forward-reference resolution |

All four are explicitly listed in the 
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.22.3.

If we have a respin of 9.11 we can pull this in.   I don't think we should 
delay 9.11 however if RC2 works! 

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to