Package
pinot
Component
jackson-databind
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The bundled jackson-databind is flagged for GHSA-5jmj-h7xm-6q6v (CVE-2026-54515), a case-insensitive deserialization bypass of per-property @JsonIgnoreProperties. No fixed release exists on the jackson-databind 2.x line: the advisory marks all 2.x releases from 2.8.0 onward as affected, including the latest 2.18.8, 2.21.4 and 2.22.0, and the only patched artifact (tools.jackson.core 3.1.4) is a new major under a different Maven coordinate that is not a drop-in update. The dependency will be updated once upstream publishes a patched 2.x release.
Status
Status