Skip to content

fix: bump jackson to 2.18.11 for CVE-2026-68497 - #1172

Merged
dkropachev merged 1 commit into
scylladb:scylla-3.xfrom
nikagra:fix/jackson-cve-2026-68497
Oct 1, 2026
Merged

dkropachev merged 1 commit into
scylladb:scylla-3.xfrom
nikagra:fix/jackson-cve-2026-68497

Conversation

@nikagra

@nikagra nikagra commented Oct 1, 2026

Copy link
Copy Markdown

jackson-databind 2.18.9 has CVE-2026-68497 (HIGH), CVE-2026-19032 and CVE-2026-83557. It is shaded into scylla-cdc-driver3, so the CDC connector can only be fixed from here.

  • jackson.version 2.18.9 → 2.18.11 (latest 2.18.x; the fix is in 2.18.10)

Verified: mvn -pl driver-core -am dependency:tree -Dincludes=com.fasterxml.jackson.core:* shows jackson-core/databind/annotations at 2.18.11; driver-core compiles. Tests not run locally; relying on CI.

Refs: scylladb/scylla-cdc-source-connector#304
Jira: https://scylladb.atlassian.net/browse/DRIVER-1144

🤖 Generated with Claude Code

Remediates jackson-databind CVE-2026-68497 (HIGH), CVE-2026-19032 and
CVE-2026-83557, fixed in 2.18.10. Takes the latest 2.18.x patch. The
shaded scylla-cdc-driver3 jar inherits this version, so the connector
can only be fixed from here.

Refs: scylladb/scylla-cdc-source-connector#304
Jira: https://scylladb.atlassian.net/browse/DRIVER-1144

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: d0368bab-a9f0-47d8-8019-e5fb5039f40c

📥 Commits

Reviewing files that changed from the base of the PR and between a5a6089 and 3b1640b.

📒 Files selected for processing (1)
  • pom.xml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The managed Jackson version in pom.xml changes from 2.18.9 to 2.18.11.

Suggested reviewers: scylladb-promoter

Priority: ⬆️ High

Change: Other

Merge Risk: ⚪ Minimal · up to 3b164

The Jackson update reaches driver-core through the managed BOM, with no introduced merge-blocking issue evident. Merge risk is minimal.

Architecture Summary

Architecture risk: 🔵 Low · up to 3b164

The change affects 1 system.

Changed systems: pom.xml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pom.xml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in pom.xml: The managed Jackson version changes from 2.18.9 to 2.18.11.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description directly explains the Jackson version update, the CVEs addressed, verification performed, and related tracking issues.
Title check ✅ Passed The title clearly identifies the Jackson dependency update and its security purpose.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 OSV Scanner (2.6.0)
pom.xml

OSV Scanner exited with code 128 without a usable report


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nikagra
nikagra requested a review from dkropachev October 1, 2026 20:16
@dkropachev
dkropachev merged commit b1f7e8d into scylladb:scylla-3.x Oct 1, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants