Package
geoserver-2.27
Component
jackson-databind
Latest update
Fixed version
2.27.5-r17
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
2.27.5-r17Status
Impact
CVE-2026-54515 in bundled jackson-databind. Fix only in unreleased 2.21.5/2.22.1 and jackson 3.1.4 (3.x, unused by GeoServer 2.27); published 2.22.0 predates the fix. Pending upstream 2.x release.
Status
Status