← All tasks
javacamunda/camunda #63853Not a task: already works

Backport Jackson fix for CVE-2026-68494 to stable/8.6

envgap__camunda__camunda-63853

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
3823084fda4d6fe0573655a6a980b9e700082077
Manifest
parent/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

camunda/camunda #63853 · read the original issue
## Description

`stable/8.6` manages Jackson through `parent/pom.xml` and currently imports Jackson BOM 2.18.6, whose `jackson-core` is affected by [CVE-2026-68494](https://github.com/advisories/GHSA-r7wm-3cxj-wff9). Its non-blocking parser can defer number-length validation across input chunks and allocate excess memory.

Update the shared Jackson BOM to the fixed 2.18.8 release. Confirm a representative module resolves `jackson-core` 2.18.8, without changing unrelated dependencies.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]