Package
kayenta-fips-2026.2
Component
jackson-databind
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-59888 (GHSA-3pjw-73gf-8qr5) is fixed in jackson-databind 2.18.8 (https://github.com/advisories/GHSA-3pjw-73gf-8qr5). This copy of jackson-databind 2.18.2 is relocated inside the prebuilt signalfx-java 1.0.49 fat jar (under com.signalfx.shaded.fasterxml.jackson), so a dependency version override cannot replace it. signalfx-java 1.0.49 is the latest release (https://repo1.maven.org/maven2/com/signalfx/public/signalfx-java/) and still bundles jackson-databind 2.18.2. Waiting for the first upstream release containing the fix.
Status