Skip to content

Track: jackson-databind CVE-2026-54515 — awaiting released fix (2.21.5) #33

Description

@WolfTasks

What

Backend Trivy MEDIUM finding CVE-2026-54515jackson-databind: ignored properties can be unexpectedly modified.

Why it's not fixed yet

Every fix version the advisory names is currently uninstallable, so there is no valid bump today:

Advisory fix Status
2.21.5 not released (latest 2.21.x in Maven Central is 2.21.4)
2.22.1 not released (latest is 2.22.0, itself still vulnerable)
2.18.9 older line — a downgrade from 2.21
3.1.4 jackson 3.x major — incompatible with Spring Boot 3.5's jackson 2.x

Not urgent

CI's blocking Trivy gate is HIGH,CRITICAL only; this MEDIUM is visible-but-non-blocking by design. It does not fail the build.

Resolution path

Let the Spring Boot BOM carry the fix once jackson-databind 2.21.5 ships — Dependabot's backend-deps group will pull it via a Spring Boot patch bump. No manual override needed (and none is currently possible).

When 2.21.5 is released, verify it's picked up:

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions