Skip to content

[Security] UID2-7569/7570/7571-7574: Upgrade jackson to 2.21.4 and Netty to 4.1.136.Final#2667

Merged
swibi-ttd merged 1 commit into
mainfrom
kchen-UID2-7569-jackson-netty-sec
Jul 27, 2026
Merged

[Security] UID2-7569/7570/7571-7574: Upgrade jackson to 2.21.4 and Netty to 4.1.136.Final#2667
swibi-ttd merged 1 commit into
mainfrom
kchen-UID2-7569-jackson-netty-sec

Conversation

@cYKatherine

Copy link
Copy Markdown
Contributor

Summary

Resolves HIGH-severity dependency vulnerabilities flagged by the scheduled Trivy vulnerability scan.

Dependency CVEs Fix
jackson-databind CVE-2026-54512 (RCE), CVE-2026-54513 (bypass) jackson-bom 2.21.4 in dependencyManagement
io.netty CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-59901 netty.version 4.1.135.Final4.1.136.Final

Reachable production dependencies (JSON handling + vert.x transport) → real upgrade, not suppression. The netty.version property applies to all operator images (default / Azure-CC / GCP-OIDC).

Tickets

UID2-7569, UID2-7570 (jackson); UID2-7571–7574 (Netty)

Testing

Build + unit tests run in CI (no local Maven available).

Resolves HIGH-severity vulnerabilities flagged by the Trivy scan:
- jackson-databind: CVE-2026-54512 (arbitrary code execution), CVE-2026-54513
  (security bypass). Fixed via jackson-bom 2.21.4 import in dependencyManagement.
- Netty: CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-59901.
  netty.version 4.1.135.Final -> 4.1.136.Final.

UID2-7569 UID2-7570 UID2-7571 UID2-7572 UID2-7573 UID2-7574

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@swibi-ttd
swibi-ttd merged commit 2cb3e98 into main Jul 27, 2026
10 checks passed
@swibi-ttd
swibi-ttd deleted the kchen-UID2-7569-jackson-netty-sec branch July 27, 2026 03:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants