Package
spark-3.5-scala-2.13
Component
jackson-databind
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
spark-3.5 ships jackson-databind 2.21.5 directly as of 3.5.8-r16 (fixed). This advisory tracks the jackson-databind copies bundled inside prebuilt shaded uber-jars: hadoop-client-runtime-3.3.6.jar (shades 2.12.7.1) and parquet-jackson-1.15.2.jar (shades 2.18.1). No hadoop 3.3.x release bundles a fixed jackson, and hadoop >=3.5.0 / parquet >=1.17.x are Java-11 bytecode that the Java-8 spark 3.5 build cannot adopt (banned by spark's enforce-bytecode-version rule). Awaiting upstream hadoop/parquet releases bundling jackson >=2.21.4 (>=2.21.5 for CVE-2026-54515).
Status
Status