Skip to content

UID2-7364: Suppress CVE-2026-54512 / CVE-2026-54513 (jackson-databind)#2621

Merged
BehnamMozafari merged 1 commit into
mainfrom
bmz-UID2-7364-jackson-databind-cve
Jun 25, 2026
Merged

UID2-7364: Suppress CVE-2026-54512 / CVE-2026-54513 (jackson-databind)#2621
BehnamMozafari merged 1 commit into
mainfrom
bmz-UID2-7364-jackson-databind-cve

Conversation

@BehnamMozafari

Copy link
Copy Markdown
Contributor

UID2-7364: Suppress jackson-databind CVE-2026-54512 / CVE-2026-54513

The scheduled vulnerability scan flagged two HIGH CVEs in com.fasterxml.jackson.core:jackson-databind:

  • CVE-2026-54512 (HIGH) — jackson-databind general-purpose data-binding
  • CVE-2026-54513 (HIGH) — jackson-databind general-purpose data-binding

Impact

jackson-databind is pulled in transitively via uid2-shared in this repo (not a direct dependency). The version fix is owned and tracked in uid2-shared (PR #631, bumping to 2.19.0) and will flow into this repo automatically on the next uid2-shared release bump.

Decision

Suppress both CVEs in .trivyignore (expiry 2026-07-25, 1 month) in the interim. No fixed version is available in a compatible jackson line yet (upstream fix targets are 2.18.8 / 2.21.4 / 3.1.4); the real version fix arrives via the uid2-shared release. This matches the approach approved in uid2-shared PR #631.

Tracked in UID2-7364.

🤖 Generated with Claude Code

jackson-databind is transitive via uid2-shared; version fix tracked in
uid2-shared PR #631 and flows here on the next uid2-shared release.
Suppress both CVEs (exp 2026-07-25) in the interim.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@BehnamMozafari BehnamMozafari merged commit eb8029f into main Jun 25, 2026
9 checks passed
@BehnamMozafari BehnamMozafari deleted the bmz-UID2-7364-jackson-databind-cve branch June 25, 2026 01:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants