DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-8525-4263-v223

Package

pinot

Component

jackson-databind

Latest update

Pending upstream fix

Aliases

Severity

7.5

High

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-91776

Updates

Status

Pending upstream fix

Impact

The jackson-databind copy reported here is shaded inside Apache Parquet's parquet-jackson module under shaded.parquet, which parquet-hadoop-bundle also includes, and cannot be updated independently of Apache Parquet. CVE-2026-91776 is fixed in jackson-databind 2.22.3. No Apache Parquet release ships it: 1.18.1, the latest release, shades jackson-databind 2.22.2, and the 1.18.x and 1.19.x release branches and the development branch also pin 2.22.2. The upgrade to jackson-databind 2.22.3 is open upstream and not yet merged. Waiting for the first upstream release containing the fix.

References: https://nvd.nist.gov/vuln/detail/CVE-2026-91776 https://github.com/advisories/GHSA-wv8q-qhhj-9h54 https://github.com/apache/parquet-java/pull/3834 https://github.com/apache/parquet-java/blob/f5fc25beecfc4fd50234cb589aa9b0efe4449f54/pom.xml#L78 https://repo1.maven.org/maven2/org/apache/parquet/parquet-jackson/

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.