π [IBM OSPO Security Notification] β IBM/appconfiguration-java-sdk
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @srikanthkm @varunkrishnaGithub @ibm-cloud-appconfiguration
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Deadline |
Fix PR |
| π high |
CVE-2026-68497 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.14.0, < 2.18.10 |
2.18.10 |
2026-10-29 |
PR |
| π‘ medium |
CVE-2026-83557 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.11.0, < 2.18.10 |
2.18.10 |
2026-12-29 |
PR |
| π‘ medium |
CVE-2026-19032 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.8.0, < 2.18.10 |
2.18.10 |
2026-12-29 |
PR |
| π‘ medium |
CVE-2026-77310 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.0.0, < 2.18.9 |
2.18.9 |
2026-12-29 |
PR |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π [IBM OSPO Security Notification] β IBM/appconfiguration-java-sdk
Attention: @srikanthkm @varunkrishnaGithub @ibm-cloud-appconfiguration
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.