Crusherbone, a 9x patch bump to jackson fixes 4 CVEs: | CVE | Component | Problem fixed | |---|---|---| | CVE-2026-89407 | jackson-core | Excessive regex processing when validating numbers | | CVE-2026-89425 | jackson-core | Unbounded malformed-token error messages | | CVE-2026-91776 | jackson-databind | Unbounded type-ID cache growth | | CVE-2026-91777 | jackson-databind | Quadratic processing during forward-reference resolution |
All four are explicitly listed in the https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.22.3. If we have a respin of 9.11 we can pull this in. I don't think we should delay 9.11 however if RC2 works! --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
