Skip to content

fix(deps): update jackson-databind to fix high CVE (uncontrolled resource consumption)#5

Merged
stremovsky merged 1 commit into
securitybunker:mainfrom
sstremovsky:fix/security-deps-20260609
Jun 9, 2026
Merged

fix(deps): update jackson-databind to fix high CVE (uncontrolled resource consumption)#5
stremovsky merged 1 commit into
securitybunker:mainfrom
sstremovsky:fix/security-deps-20260609

Conversation

@sstremovsky

Copy link
Copy Markdown

Security Dependency Updates

Resolves Dependabot security alerts by updating vulnerable packages.

Packages updated

  • jackson-databind: 2.13.4 → 2.19.0 (≥2.13.4.2 required; CVE: uncontrolled resource consumption)

Notes

See the Dependabot alerts in the repository Security tab for full CVE details.


🤖 Generated with Claude Code

@stremovsky stremovsky merged commit 854db1d into securitybunker:main Jun 9, 2026
1 check passed
Packages updated:
- jackson-databind: 2.13.4 → 2.19.0 (≥2.13.4.2 required; CVE: uncontrolled resource consumption)

Fixes Dependabot security alerts.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants