Package
spark-4.1-scala-2.13
Component
jackson-databind
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-4.1 ships jackson-databind 2.21.4 directly (the fixed version; this CVE affects jackson-databind >=2.21.0 <2.21.4). This advisory tracks the jackson-databind 2.21.3 copy shaded inside the pre-built parquet-jackson-1.17.1.jar. The fix (jackson-databind 2.21.4) is released, but parquet-jackson 1.17.1 (2026-05-08) is the latest Apache Parquet release and no release shading jackson >=2.21.4 exists. Embedded dependencies of shaded artifacts cannot be updated independently; this requires a new upstream Apache Parquet release with updated bundled jackson.
Status