Package
kayenta-2026.2
Component
jackson-databind
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-91776 (GHSA-wv8q-qhhj-9h54) is fixed in jackson-databind 2.18.11 (https://github.com/advisories/GHSA-wv8q-qhhj-9h54). This copy of jackson-databind 2.18.2 is relocated inside the prebuilt signalfx-java 1.0.49 fat jar (under com.signalfx.shaded.fasterxml.jackson), so a dependency version override cannot replace it. signalfx-java 1.0.49 is the latest release (https://repo1.maven.org/maven2/com/signalfx/public/signalfx-java/) and still bundles jackson-databind 2.18.2. Waiting for the first upstream release containing the fix.
Status