Skip to content

Bump jackson.version from 2.22.2 to 2.22.3 - #3834

Open
manuzhang wants to merge 1 commit into
apache:masterfrom
manuzhang:bump-jackson-2.22.3
Open

manuzhang wants to merge 1 commit into
apache:masterfrom
manuzhang:bump-jackson-2.22.3

Conversation

@manuzhang

@manuzhang manuzhang commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Rationale for this change

Jackson 2.22.2, which parquet-jackson shades, is affected by CVE-2026-89407 and CVE-2026-89425 (HIGH) in jackson-core. Both are fixed in 2.22.3. Projects that bundle parquet-jackson cannot upgrade the shaded copy themselves; for example, Apache Iceberg has to ignore these findings in its Kafka Connect runtime CVE scan (Build: Ignore jackson-core CVEs shaded into parquet-jackson).

What changes are included in this PR?

Bump jackson.version and jackson-databind.version from 2.22.2 to 2.22.3. The 2.22.3 jars have the same multi-release versions as 2.22.2 (9, 11, 17, and 21), which the parquet-jackson shading already relocates.

Are these changes tested?

Built parquet-jackson and checked that the shaded jar embeds jackson-core and jackson-databind 2.22.3. Existing tests cover the rest.

Are there any user-facing changes?

No.

This PR was prepared with Claude Code (Claude Opus 5.5).

Jackson 2.22.2, which parquet-jackson shades, is affected by
CVE-2026-89407 and CVE-2026-89425 in jackson-core. Both are fixed in
2.22.3.

Generated-by: Claude Code
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@manuzhang
manuzhang force-pushed the bump-jackson-2.22.3 branch from 2a82c8c to df44fdc Compare October 2, 2026 02:34
@manuzhang manuzhang changed the title MINOR: Bump Jackson to 2.22.3 Bump jackson.version from 2.22.2 to 2.22.3 Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants