Skip to content

fix(deps): bump tomcat-embed to 10.1.60 and jackson to 2.21.7 - #95

Merged
lekhrocks merged 1 commit into
mainfrom
fix/cve-tomcat-jackson
Oct 4, 2026
Merged

lekhrocks merged 1 commit into
mainfrom
fix/cve-tomcat-jackson

Conversation

@lekhrocks

@lekhrocks lekhrocks commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

Resolves 5 critical/high CVEs by overriding the vulnerable version pins in Spring Boot 3.5.16's BOM via gradle.properties project properties (the dependency-management plugin gives project properties precedence over BOM properties).

CVE Component Was Now
CVE-2026-68525 (CRITICAL) tomcat-embed-core — FORM auth bypass 10.1.55 10.1.60
CVE-2026-65905 (CRITICAL) tomcat-embed-core — DIGEST replay 10.1.55 10.1.60
CVE-2026-65182 (CRITICAL) tomcat-embed-core — security constraint bypass 10.1.55 10.1.60
CVE-2026-89425 (HIGH) jackson-core — DoS via unbounded StringBuilder 2.21.5 2.21.7
CVE-2026-91777 (HIGH) jackson-databind — quadratic forward-reference DoS 2.21.5 2.21.7

10.1.58 (the advertised Tomcat fix) was never published to Maven Central; 10.1.60 is the first available release containing the fixes.

Changes

  • gradle.properties (new): tomcat.version=10.1.60, jackson-bom.version=2.21.7
  • gradle/libs.versions.toml: catalog jackson pin 2.18.3 → 2.21.7 — syncflow-common has no Spring BOM, so the catalog was its only version source (2.18.3 was also vulnerable)
  • syncflow-api/build.gradle: dropped the jackson-bom:2.21.5 re-import, superseded by the central property (still covers GHSA-mhm7-754m-9p8w)

Verification

dependencyInsight on runtimeClasspath confirms every module resolves the patched versions:

syncflow-api         tomcat-embed-{core,el,websocket} 10.1.55 -> 10.1.60
syncflow-api         jackson-databind 2.16.2/2.18.2/2.21.4 -> 2.21.7
syncflow-common      jackson-core 2.18.3 -> 2.21.7
syncflow-agent       jackson-core 2.16.2/2.21.4 -> 2.21.7
syncflow-persistence jackson-core/databind 2.21.4 -> 2.21.7

Override Spring Boot 3.5.16 BOM pins via gradle.properties project
properties (dependency-management gives them precedence):

- tomcat.version=10.1.60: CVE-2026-68525 (FORM auth bypass),
  CVE-2026-65905 (DIGEST replay), CVE-2026-65182 (constraint bypass).
  10.1.58 was never published; 10.1.60 carries the fixes.
- jackson-bom.version=2.21.7: CVE-2026-89425 (jackson-core DoS),
  CVE-2026-91777 (jackson-databind DoS), GHSA-mhm7-754m-9p8w.

Also bump the version-catalog jackson pin to 2.21.7 (syncflow-common
has no Spring BOM, so the catalog was its only version source at the
vulnerable 2.18.3), and drop syncflow-api's jackson-bom 2.21.5
re-import, superseded by the central property.
@lekhrocks
lekhrocks merged commit 69a258f into main Oct 4, 2026
19 checks passed
@lekhrocks
lekhrocks deleted the fix/cve-tomcat-jackson branch October 4, 2026 02:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant