Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 10, 2022

This PR contains the following updates:

Package Change Age Confidence
com.fasterxml.jackson.core:jackson-core 2.14.12.15.0 age confidence

GitHub Vulnerability Alerts

CVE-2025-52999

Impact

With older versions of jackson-core, if you parse an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large.

Patches

jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. Change is in https://github.com/FasterXML/jackson-core/pull/943. jackson-core will throw a StreamConstraintsException if the limit is reached.
jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs.

Workarounds

Users should avoid parsing input files from untrusted sources.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/jackson.version branch 3 times, most recently from e1f8f23 to d791718 Compare January 10, 2022 11:56
@renovate renovate bot force-pushed the renovate/jackson.version branch from d791718 to 900fb2c Compare January 29, 2022 03:51
@renovate renovate bot changed the title Update jackson.version to v2.13.1 Update jackson.version Jan 29, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from 900fb2c to 8c15d64 Compare January 29, 2022 05:31
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.13.1 Jan 29, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from 8c15d64 to d3924f1 Compare March 6, 2022 20:22
@renovate renovate bot changed the title Update jackson.version to v2.13.1 Update jackson.version Mar 6, 2022
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.13.2 Mar 7, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from d3924f1 to dbae391 Compare May 15, 2022 23:04
@renovate renovate bot changed the title Update jackson.version to v2.13.2 Update jackson.version to v2.13.3 May 15, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from dbae391 to 33da59c Compare September 25, 2022 18:35
@renovate renovate bot changed the title Update jackson.version to v2.13.3 Update jackson.version to v2.13.4 Sep 25, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from 33da59c to f2f3deb Compare November 20, 2022 11:27
@renovate renovate bot changed the title Update jackson.version to v2.13.4 Update jackson.version to v2.14.0 Nov 20, 2022
@renovate renovate bot force-pushed the renovate/jackson.version branch from f2f3deb to b87fab5 Compare March 16, 2023 17:49
@renovate renovate bot changed the title Update jackson.version to v2.14.0 Update jackson.version to v2.14.2 Mar 16, 2023
@renovate renovate bot force-pushed the renovate/jackson.version branch from b87fab5 to e843751 Compare May 28, 2023 09:37
@renovate renovate bot changed the title Update jackson.version to v2.14.2 Update jackson.version to v2.15.1 May 28, 2023
@renovate renovate bot changed the title Update jackson.version to v2.15.1 Update jackson.version May 30, 2023
@renovate renovate bot force-pushed the renovate/jackson.version branch from e843751 to e8e6c01 Compare May 31, 2023 00:13
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.15.2 May 31, 2023
@renovate renovate bot changed the title Update jackson.version to v2.15.2 Update jackson.version Oct 12, 2023
@renovate renovate bot force-pushed the renovate/jackson.version branch from e8e6c01 to acc876b Compare October 13, 2023 01:17
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.15.3 Oct 13, 2023
@renovate renovate bot force-pushed the renovate/jackson.version branch from acc876b to dd976ff Compare November 16, 2023 01:33
@renovate renovate bot changed the title Update jackson.version to v2.15.3 Update jackson.version to v2.16.0 Nov 16, 2023
@renovate renovate bot force-pushed the renovate/jackson.version branch from dd976ff to 1145fed Compare December 24, 2023 06:50
@renovate renovate bot changed the title Update jackson.version to v2.16.0 Update jackson.version to v2.16.1 Dec 24, 2023
@renovate renovate bot changed the title Update jackson.version to v2.16.2 Update jackson.version Mar 12, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from 1872ee9 to ebac3a2 Compare March 13, 2024 01:47
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.17.0 Mar 13, 2024
@renovate renovate bot changed the title Update jackson.version to v2.17.0 Update jackson.version May 5, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from ebac3a2 to fac0e52 Compare May 5, 2024 03:42
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.17.1 May 5, 2024
@renovate renovate bot changed the title Update jackson.version to v2.17.1 Update jackson.version to v2.17.2 Jul 5, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from fac0e52 to 7e3c20b Compare July 5, 2024 20:06
@renovate renovate bot force-pushed the renovate/jackson.version branch from 7e3c20b to df267d7 Compare August 17, 2024 15:23
@renovate renovate bot force-pushed the renovate/jackson.version branch from df267d7 to e4474b6 Compare September 27, 2024 05:04
@renovate renovate bot changed the title Update jackson.version to v2.17.2 Update jackson.version to v2.18.0 Sep 27, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from e4474b6 to 8904c61 Compare October 29, 2024 00:43
@renovate renovate bot changed the title Update jackson.version to v2.18.0 Update jackson.version Oct 29, 2024
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.18.1 Oct 29, 2024
@renovate renovate bot changed the title Update jackson.version to v2.18.1 Update jackson.version Nov 28, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from 8904c61 to d9d3c3c Compare November 28, 2024 21:18
@renovate renovate bot changed the title Update jackson.version Update jackson.version to v2.18.2 Nov 29, 2024
@renovate renovate bot changed the title Update jackson.version to v2.18.2 Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.18.2 Dec 16, 2024
@renovate renovate bot force-pushed the renovate/jackson.version branch from d9d3c3c to a432f42 Compare March 1, 2025 01:58
@renovate renovate bot changed the title Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.18.2 Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.18.3 Mar 1, 2025
@renovate renovate bot force-pushed the renovate/jackson.version branch from a432f42 to 0dd7a54 Compare April 25, 2025 02:01
@renovate renovate bot changed the title Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.18.3 Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.19.0 Apr 25, 2025
@renovate renovate bot force-pushed the renovate/jackson.version branch 2 times, most recently from 7f3d8e9 to fde9e23 Compare May 3, 2025 13:08
@renovate renovate bot force-pushed the renovate/jackson.version branch from fde9e23 to 14100c8 Compare June 14, 2025 05:30
@renovate renovate bot changed the title Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.19.0 Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.19.1 Jun 14, 2025
@renovate renovate bot force-pushed the renovate/jackson.version branch from 14100c8 to 0b5fef8 Compare June 27, 2025 19:00
@renovate renovate bot changed the title Update dependency com.fasterxml.jackson.datatype:jackson-datatype-joda to v2.19.1 Update jackson.version Jun 27, 2025
@renovate renovate bot changed the title Update jackson.version Update dependency com.fasterxml.jackson.core:jackson-core to v2.15.0 [SECURITY] Dec 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants