Package
spark-fips-4.1-scala-2.13
Component
jackson-databind
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
jackson-databind is present as spark's own dependency (2.21.4) and bundled inside the hadoop-client-runtime and parquet-jackson shaded jars. The fix for CVE-2026-54515 is slated for the unreleased jackson-databind 2.21.5 / 2.22.1 (the released 2.22.0 predates the fix). No released jackson version resolves this; awaiting an upstream FasterXML release.
Status