Backport Jackson fix for CVE-2026-68494 to stable/8.6
envgap__camunda__camunda-63853
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
3823084fda4d6fe0573655a6a980b9e700082077- Manifest
parent/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
camunda/camunda #63853 · read the original issue
## Description `stable/8.6` manages Jackson through `parent/pom.xml` and currently imports Jackson BOM 2.18.6, whose `jackson-core` is affected by [CVE-2026-68494](https://github.com/advisories/GHSA-r7wm-3cxj-wff9). Its non-blocking parser can defer number-length validation across input chunks and allocate excess memory. Update the shared Jackson BOM to the fixed 2.18.8 release. Confirm a representative module resolves `jackson-core` 2.18.8, without changing unrelated dependencies.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]