Package
apache-polaris-fips
Component
jackson-databind
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Apache Polaris bundles hadoop-client-runtime 3.5.0, the latest Apache Hadoop release, which shades jackson-databind 2.18.6 inside the Hadoop client jar. CVE-2026-91777 is fixed in jackson-databind 2.18.11 for the 2.18 line, and no Apache Hadoop release ships 2.18.11 or later. This copy is part of Hadoop's release artifact and cannot be updated independently. Waiting for the first upstream release containing the fix.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-91777 https://github.com/advisories/GHSA-cxp5-3px4-pw24 https://repo1.maven.org/maven2/org/apache/hadoop/hadoop-client-runtime/
Status