fix(security): jackson-bom 2.21.5 -> 2.21.7 (CVE-2026-68497 + 2 more HIGH, unblocks nightly) - #142
Merged
Merged
Conversation
…HIGH) The nightly Trivy scan went red on 2026-09-29 and 2026-09-30 (issues #140, #141) with no code change on our side — CVE-2026-68497 (HIGH) was published against jackson-databind that day and our BOM override pinned 2.21.5. CVE-2026-68497: CoreXMLDeserializers hands a JSON *string* straight to DatatypeFactory.newDuration / newXMLGregorianCalendar, so BigInteger(String) and BigDecimal(String) parse arbitrarily long digit runs quadratically. Those deserializers are registered by default and jackson-core's maxNumberLength guard does not apply to string tokens, so a single few-MB unauthenticated request can burn minutes of single-threaded CPU. 2.21.6 is the version the advisory names, but verifying it against a current Trivy DB still failed the HIGH gate: CVE-2026-91776 (TypeDeserializerBase._findDeserializer) and CVE-2026-91777 (@JsonIdentityInfo forward-reference completion) are fixed only in 2.21.7. 2.21.7 is the newest release on Maven Central. It also clears three mediums: CVE-2026-83557, CVE-2026-19032, CVE-2026-77310. jackson-databind is transitive-only here, so Dependabot's direct-only security updater cannot patch it (the recurring security_update_dependency_not_found failures on the gradle jobs) — the shared jackson-bom property override is the fix, and it moves the whole Jackson family together. Verified locally: - ./gradlew test bootJar -> BUILD SUCCESSFUL, 382 tests, 0 failures - trivy 0.70.0 fs --severity HIGH,CRITICAL (same version as CI) -> 0 findings, exit 0 (was exit 1 with 2 HIGH on 2.21.6) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi
WolfTasks
pushed a commit
that referenced
this pull request
Sep 30, 2026
Ships the jackson-databind DoS fix and the pending frontend-deps group: - jackson-bom 2.21.5 -> 2.21.7 (#142), clears CVE-2026-68497 (HIGH) plus CVE-2026-91776 and CVE-2026-91777 (both HIGH) and three mediums. The CVE-2026-68497 advisory was published on 2026-09-29 and broke the nightly Trivy gate that night and the next, against an unchanged repo (issues #140, #141). The advisory names 2.21.6 as the fix, but 2.21.6 still failed the HIGH gate against a current Trivy DB — CVE-2026-91776/91777 are fixed only in 2.21.7. - Dependabot could not fix this itself: jackson-databind is transitive-only here and its security job may only touch direct dependencies (the recurring security_update_dependency_not_found failures), so the shared jackson-bom property is overridden instead and moves the whole Jackson family together. - frontend-deps group, 23 updates (#134), unreleased since v1.0.18. Trivy reports 0 HIGH/CRITICAL across gradle.lockfile and package-lock.json; backend suite green (382 tests). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warum
Die Nightly Security Scan ist am 2026-09-29 und 2026-09-30 rot gelaufen (Issues #140, #141) — ohne Code-Änderung auf unserer Seite. Geändert hat sich die Trivy-Vuln-DB: am 29.09. wurde CVE-2026-68497 (HIGH) gegen
jackson-databindveröffentlicht, und unser BOM-Override stand auf 2.21.5.CVE-2026-68497:CoreXMLDeserializersgibt einen JSON-String unverändert anDatatypeFactory.newDuration/newXMLGregorianCalendarweiter, wodurchBigInteger(String)/BigDecimal(String)beliebig lange Ziffernfolgen quadratisch parsen. Die Deserializer sind per Default registriert (kein Opt-in), und dermaxNumberLength-Guard von jackson-core greift bei String-Tokens nicht — ein einzelner Request von wenigen MB kann Minuten Single-Thread-CPU verbrennen.Warum 2.21.7 und nicht 2.21.6
Das Advisory nennt 2.21.6 als Fix. Gegen eine aktuelle Trivy-DB verifiziert fällt 2.21.6 aber weiter durch den HIGH-Gate:
TypeDeserializerBase._findDeserializer)@JsonIdentityInfoforward-reference completion)2.21.7 ist der neueste Release auf Maven Central (2.21.8 existiert nicht). Er räumt zusätzlich drei Mediums ab: CVE-2026-83557, CVE-2026-19032, CVE-2026-77310 (Dependabot #103/#101/#100).
Warum BOM-Override und nicht Dependabot
jackson-databindist hier transitive-only, deshalb kann Dependabots direkter Security-Updater es nicht patchen — das sind die wiederkehrend rotensecurity_update_dependency_not_found-Jobs auf den gradle-Updates. Der Override der gemeinsamenjackson-bom-Property ist der Fix und zieht die ganze Jackson-Familie (databind, core, module-kotlin, dataformat-, datatype-) mit.Änderungen
backend/build.gradle.kts:extra["jackson-bom.version"]2.21.5 → 2.21.7, Begründung im Kommentarbackend/gradle.lockfile: mit--write-locksregeneriert (9 Jackson-Artefakte auf 2.21.7)Verifikation (lokal)
./gradlew test bootJar→BUILD SUCCESSFUL, 382 Tests, 0 failures, 0 errorstrivy 0.70.0 fs --scanners vuln --severity HIGH,CRITICAL --exit-code 1(dieselbe Version wie CI) → 0 Findings, exit 0(zum Vergleich: auf 2.21.6 → exit 1 mit 2× HIGH)
Closes #140
Closes #141
Offen (nicht in diesem PR)
Nicht vom FS-Gate erfasst, separat zu behandeln:
log4j-api 2.24.3(Alert feat(i18n): localize servicedesk errors + guard against un-keyed throws (#16 Phase-2 close-out) #90 / Code-Scanning Nightly security scan failed (2026-09-04) #121, medium, CVE-2026-49844, Fix 2.25.5) — steckt imapp.jarhttpcore5/httpclient5(#16 Backend i18n Phase 2 — Session 4 (integrations + orgs + content) #87/build(deps): bump the backend-deps group in /backend with 3 updates #89, HIGH) undkotlin-gradle-plugin(build(deps): bump the actions group with 6 updates #88) — stehen nicht ingradle.lockfile, also nicht im Runtime-Classpath🤖 Generated with Claude Code
https://claude.ai/code/session_013U7fTQGgewiKtW8N9ikHBi