← All tasks
javaapache/shenyu #6599Not a task: already works

[Task] Vulnerable jackson-databind 2.13.3 pinned in shenyu-e2e BOM (CVE-2022-42003/42004)

envgap__apache__shenyu-6599

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
936eef8b5615d7befe95bb2a1cecf5801a7cabb0
Manifest
shenyu-e2e/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

apache/shenyu #6599 · read the original issue
## Description
Forces jackson-databind 2.13.3 across the e2e reactor. Root is `pom.xml:155` `2.15.3`. 2.13.3 is vulnerable to CVE-2022-42003 / CVE-2022-42004 (DoS via cyclic deserialization), fixed in 2.13.4.2.

## Location
```
shenyu-e2e/pom.xml:52 (<jackson.version>2.13.3</jackson.version>)
shenyu-e2e/pom.xml:201-205 (jackson-bom import)
root pom.xml:155 (2.15.3)
```

## Impact
E2E test harness runs a vulnerable jackson; 6 minor patches behind main.

## Suggested fix
Raise to `2.15.3` (match root).

## Related existing issue(s)
None — not covered by the #6372/#6367 dependency-governance cluster.

_Identified during the 2026-08-02 audit; full list in [`docs/issue-candidates-2026-08-02.md`](docs/issue-candidates-2026-08-02.md)._
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]