Package
apache-nifi-2.12
Component
jackson-databind
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The affected jackson-databind / jackson-core is a shaded copy inside the Hazelcast client library bundled in nifi-hazelcast-services-nar (hazelcast-5.7.0.jar, relocated under com.hazelcast.shaded). It is not governed by NiFi's Maven dependency management, so raising the jackson version in the NiFi build does not reach it; every other NiFi bundle already ships a fixed jackson. Hazelcast 5.7.0 is the most recent release and still bundles jackson 2.21.2 (and Jackson 3.1.2). Hazelcast maintainers have stated (https://github.com/hazelcast/hazelcast/issues/26597, https://github.com/hazelcast/hazelcast/issues/26623) that the updated jackson will ship in the next minor/major open-source release, that no patch releases are made for the open-source edition, and that Hazelcast's own JSON paths do not use the polymorphic typing pattern required by CVE-2026-54512 and CVE-2026-54513. Resolution requires that Hazelcast release, followed by Apache NiFi adopting it.
Status