Skip to content

The aws-sdk ships with a vulnerable version of jackson-core #7379

Description

@juan-comesana-curity

Describe the bug

Our vulnerability scan is reporting CVE-2026-68498, affecting software.amazon.awssdk : third-party-jackson-core
The CVE is fixed in recent versions of jackson-core (2.22.2).

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

No vulnerabilities reported

Current Behavior

The vulnerability scan reports CVE-2026-68498 with a base score of 8.7.

Reproduction Steps

Run a vulnerability scan

Possible Solution

Update jackson-core to 2.22.2 or newer.

Additional Information/Context

No response

AWS Java SDK version used

2.42.5

JDK version used

openjdk 21.0.12 2026-07-21

Operating System and version

Ubuntu Linux 22.04

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugThis issue is a bug.closing-soonThis issue will close in 4 days unless further comments are made.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions