Skip to content

fix(security): jackson-bom 2.21.5 -> 2.21.7 (CVE-2026-68497 + 2 more HIGH, unblocks nightly) - #142

Merged
WolfTasks merged 1 commit into
mainfrom
worktree-jackson-2216-security-bump
Sep 30, 2026
Merged

WolfTasks merged 1 commit into
mainfrom
worktree-jackson-2216-security-bump

Conversation

@WolfTasks

Copy link
Copy Markdown
Owner

Warum

Die Nightly Security Scan ist am 2026-09-29 und 2026-09-30 rot gelaufen (Issues #140, #141) — ohne Code-Änderung auf unserer Seite. Geändert hat sich die Trivy-Vuln-DB: am 29.09. wurde CVE-2026-68497 (HIGH) gegen jackson-databind veröffentlicht, und unser BOM-Override stand auf 2.21.5.

CVE-2026-68497: CoreXMLDeserializers gibt einen JSON-String unverändert an DatatypeFactory.newDuration / newXMLGregorianCalendar weiter, wodurch BigInteger(String) / BigDecimal(String) beliebig lange Ziffernfolgen quadratisch parsen. Die Deserializer sind per Default registriert (kein Opt-in), und der maxNumberLength-Guard von jackson-core greift bei String-Tokens nicht — ein einzelner Request von wenigen MB kann Minuten Single-Thread-CPU verbrennen.

Warum 2.21.7 und nicht 2.21.6

Das Advisory nennt 2.21.6 als Fix. Gegen eine aktuelle Trivy-DB verifiziert fällt 2.21.6 aber weiter durch den HIGH-Gate:

CVE Fix ab
CVE-2026-91776 (TypeDeserializerBase._findDeserializer) 2.21.7
CVE-2026-91777 (@JsonIdentityInfo forward-reference completion) 2.21.7

2.21.7 ist der neueste Release auf Maven Central (2.21.8 existiert nicht). Er räumt zusätzlich drei Mediums ab: CVE-2026-83557, CVE-2026-19032, CVE-2026-77310 (Dependabot #103/#101/#100).

Warum BOM-Override und nicht Dependabot

jackson-databind ist hier transitive-only, deshalb kann Dependabots direkter Security-Updater es nicht patchen — das sind die wiederkehrend roten security_update_dependency_not_found-Jobs auf den gradle-Updates. Der Override der gemeinsamen jackson-bom-Property ist der Fix und zieht die ganze Jackson-Familie (databind, core, module-kotlin, dataformat-, datatype-) mit.

Änderungen

  • backend/build.gradle.kts: extra["jackson-bom.version"] 2.21.5 → 2.21.7, Begründung im Kommentar
  • backend/gradle.lockfile: mit --write-locks regeneriert (9 Jackson-Artefakte auf 2.21.7)

Verifikation (lokal)

  • ./gradlew test bootJar → BUILD SUCCESSFUL, 382 Tests, 0 failures, 0 errors
  • trivy 0.70.0 fs --scanners vuln --severity HIGH,CRITICAL --exit-code 1 (dieselbe Version wie CI) → 0 Findings, exit 0
    (zum Vergleich: auf 2.21.6 → exit 1 mit 2× HIGH)

Closes #140
Closes #141

Offen (nicht in diesem PR)

Nicht vom FS-Gate erfasst, separat zu behandeln:

🤖 Generated with Claude Code

https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi

…HIGH)

The nightly Trivy scan went red on 2026-09-29 and 2026-09-30 (issues #140,
#141) with no code change on our side — CVE-2026-68497 (HIGH) was published
against jackson-databind that day and our BOM override pinned 2.21.5.

CVE-2026-68497: CoreXMLDeserializers hands a JSON *string* straight to
DatatypeFactory.newDuration / newXMLGregorianCalendar, so BigInteger(String)
and BigDecimal(String) parse arbitrarily long digit runs quadratically. Those
deserializers are registered by default and jackson-core's maxNumberLength
guard does not apply to string tokens, so a single few-MB unauthenticated
request can burn minutes of single-threaded CPU.

2.21.6 is the version the advisory names, but verifying it against a current
Trivy DB still failed the HIGH gate: CVE-2026-91776
(TypeDeserializerBase._findDeserializer) and CVE-2026-91777 (@JsonIdentityInfo
forward-reference completion) are fixed only in 2.21.7. 2.21.7 is the newest
release on Maven Central. It also clears three mediums: CVE-2026-83557,
CVE-2026-19032, CVE-2026-77310.

jackson-databind is transitive-only here, so Dependabot's direct-only security
updater cannot patch it (the recurring security_update_dependency_not_found
failures on the gradle jobs) — the shared jackson-bom property override is the
fix, and it moves the whole Jackson family together.

Verified locally:
- ./gradlew test bootJar -> BUILD SUCCESSFUL, 382 tests, 0 failures
- trivy 0.70.0 fs --severity HIGH,CRITICAL (same version as CI) -> 0 findings,
  exit 0 (was exit 1 with 2 HIGH on 2.21.6)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi
@WolfTasks
WolfTasks merged commit 1341afa into main Sep 30, 2026
11 checks passed
@WolfTasks
WolfTasks deleted the worktree-jackson-2216-security-bump branch September 30, 2026 20:25
WolfTasks pushed a commit that referenced this pull request Sep 30, 2026
Ships the jackson-databind DoS fix and the pending frontend-deps group:
- jackson-bom 2.21.5 -> 2.21.7 (#142), clears CVE-2026-68497 (HIGH) plus
  CVE-2026-91776 and CVE-2026-91777 (both HIGH) and three mediums. The
  CVE-2026-68497 advisory was published on 2026-09-29 and broke the nightly
  Trivy gate that night and the next, against an unchanged repo (issues #140,
  #141). The advisory names 2.21.6 as the fix, but 2.21.6 still failed the
  HIGH gate against a current Trivy DB — CVE-2026-91776/91777 are fixed only
  in 2.21.7.
- Dependabot could not fix this itself: jackson-databind is transitive-only
  here and its security job may only touch direct dependencies (the recurring
  security_update_dependency_not_found failures), so the shared jackson-bom
  property is overridden instead and moves the whole Jackson family together.
- frontend-deps group, 23 updates (#134), unreleased since v1.0.18.

Trivy reports 0 HIGH/CRITICAL across gradle.lockfile and package-lock.json;
backend suite green (382 tests).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Nightly security scan failed (2026-09-30) Nightly security scan failed (2026-09-29)

1 participant