<div class="container">
<h1>Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:2801-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-07-08T19:05:27Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268603">bsc#1268603</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268897">bsc#1268897</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268898">bsc#1268898</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268899">bsc#1268899</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268902">bsc#1268902</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54512.html">CVE-2026-54512</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54513.html">CVE-2026-54513</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54514.html">CVE-2026-54514</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54515.html">CVE-2026-54515</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54512</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54512</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54514</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54514</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54515</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54515</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">Basesystem Module 15-SP7</li>
<li class="list-group-item">Development Tools Module 15-SP7</li>
<li class="list-group-item">SUSE Linux Enterprise Desktop 15 SP7</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing LTSS 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing LTSS 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Real Time 15 SP7</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP4 LTSS</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP5 LTSS</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP6</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP6 LTSS</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP7</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP6</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP7</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves four vulnerabilities and has one security fix can now be installed.</p>
<h2>Description:</h2>
<p>This update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent fixes the following issues</p>
<ul>
<li>CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows
arbitrary class instantiation (bsc#1268897).</li>
<li>CVE-2026-54513: jackson-databind: array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898).</li>
<li>CVE-2026-54514: jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899).</li>
<li>CVE-2026-54515: jackson-databindi: case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
(bsc#1268902).</li>
<li>jackson-core: document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603).</li>
</ul>
<p>Changes for jackson-annotations:</p>
<ul>
<li>Update to 2.18.8</li>
<li>No changes since 2.17.3</li>
</ul>
<p>Changes for jackson-bom:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes</li>
<li>
<h1>68: Remove 'junit' 4.x dependency from 'jackson-base' 2.18.x</h1>
to help junit5 migration</li>
<li>'base/pom.xml' now creates '${project.version.underscore}' for
"cleansed" version of '${project.version}'</li>
</ul>
<p>Changes for jackson-core:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes of 2.18.8</li>
<li>
<h1>1611: Apply number-length validator on streaming integer path</h1>
of async parser</li>
<li>Changes of 2.18.7</li>
<li>
<h1>1570: Fail parsing from 'DataInput' if 'StreamReadConstraints</h1>
.getMaxDocumentLength()' set
(bsc#1268603, GHSA-2m67-wjpj-xhg9)</li>
<li>
<h1>1600: Rework 3rd party licenses in jar</h1>
</li>
<li>
<h1>1602: 'UTF8DataInputJsonParser' needs to enforce</h1>
'StreamReadConstraints.maxNameLength' limit</li>
<li>Changes of 2.18.6</li>
<li>
<h1>1512: Number-parsing fix for 'UTF8DataInputJsonParser'</h1>
</li>
<li>
<h1>1548: 'StreamReadConstraints.maxDocumentLength' not checked</h1>
when creating parser with fixed buffer</li>
<li>
<h1>1555: Enforce 'StreamReadConstraints.maxNumberLength' for</h1>
non-blocking (async) parser</li>
<li>Changes of 2.18.5</li>
<li>
<h1>1433: 'JsonParser#getNumberType()' throws</h1>
'JsonParseException' when the current token is non-numeric
instead of returning null</li>
<li>
<h1>1446: Invalid package reference to "java.lang.foreign" from</h1>
'com.fasterxml.jackson.core:jackson-core' (from
'FastDoubleParser')</li>
<li>Changes of 2.18.3</li>
<li>
<h1>1391: Fix issue where the parser can read back old number</h1>
state when parsing later numbers</li>
<li>
<h1>1397: Jackson changes additional values to infinite in case</h1>
of special JSON structures and existing infinite values</li>
<li>
<h1>1398: Fix issue that feature</h1>
COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom
characterEscape is used</li>
<li>Changes of 2.18.2</li>
<li>
<h1>1359: Non-surrogate characters being incorrectly combined</h1>
when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is
enabled</li>
<li>Changes of 2.18.1</li>
<li>
<h1>1353: Use fastdoubleparser 1.0.90</h1>
</li>
<li>Changes of 2.18.</li>
<li>
<h1>223: 'UTF8JsonGenerator' writes supplementary characters as a</h1>
surrogate pair: should use 4-byte encoding</li>
<li>
<h1>1230: Improve performance of 'float' and 'double' parsing</h1>
from 'TextBuffer'</li>
<li>
<h1>1251: 'InternCache' replace synchronized with 'ReentrantLock'</h1>
</li>
<li>the cache size limit is no longer strictly enforced for
performance reasons but we should never go far about the limit</li>
<li>
<h1>1252: 'ThreadLocalBufferManager' replace synchronized with</h1>
'ReentrantLock'</li>
<li>
<h1>1257: Increase InternCache default max size from 100 to 200</h1>
</li>
<li>
<h1>1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool'</h1>
</li>
<li>
<h1>1264: Rename shaded 'ch.randelshofer:fastdoubleparser'</h1>
classes to prevent use by downstream consumers</li>
<li>
<h1>1271: Deprecate 'LockFreePool' implementation in 2.18 (remove</h1>
from 3.0)</li>
<li>
<h1>1274: 'NUL'-corrupted keys, values on JSON serialization</h1>
</li>
<li>
<h1>1277: Add back Java 22 optimisation in FastDoubleParser</h1>
</li>
<li>
<h1>1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue()</h1>
/getDecimalValue()' to avoid String allocation</li>
<li>
<h1>1305: Make helper methods of 'WriterBasedJsonGenerator'</h1>
non-final to allow overriding</li>
<li>
<h1>1310: Add new 'StreamReadConstraints' ('maxTokenCount') to</h1>
limit maximum number of Tokens allowed per document#</li>
<li>
<h1>1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal'</h1>
decoding proble</li>
</ul>
<p>Changes for jackson-databind:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes of 2.18.8</li>
<li>
<h1>5950: Improve 'UUIDeserializer' error handling</h1>
</li>
<li>
<h1>5951: Improve 'InetSocketAddress' deserialization</h1>
(bsc#1268899, CVE-2026-54514)</li>
<li>
<h1>5969: '@JsonView' by-passed for some "setterless" creator</h1>
properties</li>
<li>
<h1>5971: '@JsonView' by-passed for unwrapped creator parameters</h1>
</li>
<li>
<h1>5974: '@JsonIgnore' on Record property ignored with</h1>
'PropertyNamingStrategy'</li>
<li>
<h1>5981: 'BasicPolymorphicTypeValidator' setting</h1>
'allowIfSubTypeIsArray()' should validate element type
(bsc#1268898, CVE-2026-54513)</li>
<li>
<h1>5988: 'PolymorphicTypeValidator' needs to validate generic</h1>
type parameters too (bsc#1268897, CVE-2026-54512)</li>
<li>
<h1>5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls'</h1>
fold case using JVM default locale (Turkish-I bug)</li>
<li>Changes of 2.18.4</li>
<li>
<h1>4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on</h1>
Record property ignored for deserialization</li>
<li>
<h1>5049: Duplicate creator property "b" (index 0 vs 1) on simple</h1>
java record</li>
<li>Changes of 2.18.3</li>
<li>
<h1>4444: The 'KeyDeserializer' specified in the class with</h1>
'@JsonDeserialize(keyUsing = ...)' is overwritten by the
'KeyDeserializer' specified in the 'ObjectMapper'.</li>
<li>
<h1>4827: Subclassed Throwable deserialization fails since</h1>
v2.18.0 - no creator index for property 'cause'</li>
<li>
<h1>4844: Fix wrapped array handling wrt 'null' by</h1>
'StdDeserializer'</li>
<li>
<h1>4848: Avoid type pollution in 'StringCollectionDeserializer'</h1>
</li>
<li>
<h1>4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not</h1>
work with multiple constructors since 2.18</li>
<li>
<h1>4878: When serializing a Map via</h1>
Converter(StdDelegatingSerializer), a NullPointerException is
thrown due to missing key serializer</li>
<li>
<h1>4908: Deserialization behavior change with @JsonCreator and</h1>
@ConstructorProperties between 2.17 and 2.18</li>
<li>
<h1>4917: 'BigDecimal' deserialization issue when using</h1>
'@JsonCreator'</li>
<li>
<h1>4920: Creator properties are ignored on abstract types when</h1>
collecting bean properties, breaking AsExternalTypeDeserializer</li>
<li>
<h1>4922: Failing '@JsonMerge' with a custom Map</h1>
</li>
<li>
<h1>4932: Conversion of 'MissingNode' throws</h1>
'JsonProcessingException'</li>
<li>Changes of 2.18.2</li>
<li>
<h1>4733: Wrong serialization of Type Ids for certain types of</h1>
Enum values</li>
<li>
<h1>4742: Deserialization with Builder, External type id,</h1>
'@JsonCreator' failing</li>
<li>
<h1>4777: 'StdValueInstantiator.withArgsCreator' is now set for</h1>
creators with no arguments</li>
<li>
<h1>4783 Possibly wrong behavior of @JsonMerge</h1>
</li>
<li>
<h1>4787: Wrong 'String.format()' in 'StdDelegatingDeserializer'</h1>
hides actual error</li>
<li>
<h1>4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides</h1>
'@JsonProperty' values</li>
<li>
<h1>4790: Fix '@JsonAnySetter' issue with "setter" method</h1>
(related to #4639)</li>
<li>
<h1>4807: Improve 'FactoryBasedEnumDeserializer' to work better</h1>
with XML module</li>
<li>
<h1>4810: Deserialization using '@JsonCreator' with renamed</h1>
property failing (since 2.18)</li>
<li>Changes of 2.18.1</li>
<li>
<h1>4508: Deserialized JsonAnySetter field in Kotlin data class</h1>
is null</li>
<li>
<h1>4639: @JsonAnySetter on field ignoring unrecognized</h1>
properties if they are declared before the last recognized
properties in JSON</li>
<li>
<h1>4718: Should not fail on trying to serialize</h1>
'java.time.DateTimeException'</li>
<li>
<h1>4724: Deserialization behavior change with Records,</h1>
'@JsonCreator' and '@JsonValue' between 2.17 and 2.18</li>
<li>
<h1>4727: Eclipse having issues due'module-info' class "lost" on</h1>
2.18.0 jars</li>
<li>
<h1>4741: When 'Include.NON_DEFAULT' setting is used on POJO,</h1>
empty values are not included in json if default is 'null'</li>
<li>
<h1>4749: Fixed a problem with</h1>
'StdDelegatingSerializer#serializeWithType' looking up the
serializer with the wrong argument</li>
<li>Changes of 2.18.0</li>
<li>
<h1>562: Allow '@JsonAnySetter' to flow through Creators</h1>
</li>
<li>
<h1>806: Problem with 'NamingStrategy', creator methods with</h1>
implicit names</li>
<li>
<h1>2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and</h1>
field level '@JsonProperty'</li>
<li>
<h1>3120: Return 'ListIterator' from 'ArrayNode.elements()'</h1>
</li>
<li>
<h1>3241: 'constructorDetector' seems to invalidate</h1>
'defaultSetterInfo' for nullability</li>
<li>
<h1>3439: Java Record '@JsonAnySetter' value is null after</h1>
deserialization</li>
<li>
<h1>4085: '@JsonView' does not work on class-level for records</h1>
</li>
<li>
<h1>4119: Exception when deserialization uses a record with a</h1>
constructor property with 'access=READ_ONLY'</li>
<li>
<h1>4356: 'BeanDeserializerModifier::updateBuilder()' doesn't</h1>
work for beans with Creator methods</li>
<li>
<h1>4407: 'null' type id handling does not work with</h1>
'writeTypePrefix()'</li>
<li>
<h1>4452: '@JsonProperty' not serializing field names properly on</h1>
'@JsonCreator' in Record</li>
<li>
<h1>4453: Allow JSON Integer to deserialize into a single-arg</h1>
constructor of parameter type 'double'</li>
<li>
<h1>4456: Rework locking in 'DeserializerCache'</h1>
</li>
<li>
<h1>4458: Rework synchronized block from 'BeanDeserializerBase'</h1>
</li>
<li>
<h1>4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()'</h1>
method is not called on the serializer</li>
<li>
<h1>4472: Rework synchronized block in 'TypeDeserializerBase'</h1>
</li>
<li>
<h1>4483: Remove 'final' on method BeanSerializer.serialize()</h1>
</li>
<li>
<h1>4515: Rewrite Bean Property Introspection logic in Jackson</h1>
2.x</li>
<li>
<h1>4545: Unexpected deserialization behavior with</h1>
'@JsonCreator', '@JsonProperty' and javac '-parameters'</li>
<li>
<h1>4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper</h1>
.canSerialize()'</li>
<li>
<h1>4580: Add 'MapperFeature</h1>
.SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator
properties' declaration order for sorting</li>
<li>
<h1>4584: Provide extension point for detecting "primary"</h1>
Constructor for Kotlin (and similar) data classes</li>
<li>
<h1>4602: Possible wrong use of _arrayDelegateDeserializer in</h1>
BeanDeserializerBase::deserializeFromObjectUsingNonDefault()</li>
<li>
<h1>4617: Record property serialization order not preserved</h1>
</li>
<li>
<h1>4626: '@JsonIgnore' on Record property ignored for</h1>
deserialization, if there is getter override</li>
<li>
<h1>4630: '@JsonIncludeProperties', '@JsonIgnoreProperties'</h1>
ignored when serializing Records, if there is getter override</li>
<li>
<h1>4634: '@JsonAnySetter' not working when annotated on both</h1>
constructor parameter & field</li>
<li>
<h1>4678: Java records don't serialize with 'MapperFeature</h1>
.REQUIRE_SETTERS_FOR_GETTERS'</li>
<li>
<h1>4688: Should allow deserializing with no-arg</h1>
'@JsonCreator(mode = DELEGATING)'</li>
<li>
<h1>4694: Deserializing 'BigDecimal' with large number of</h1>
decimals result in incorrect value</li>
<li>
<h1>4699: Add extra 'writeNumber()' method in 'TokenBuffer'</h1>
</li>
<li>
<h1>4709: Add 'JacksonCollectors' with 'toArrayNode()'</h1>
implementation</li>
<li>Fix #5962: Case-insensitive deserialization may use wrong
@JsonIgnoreProperties (bsc#1268902, CVE-2026-54515)</li>
<li>Fix "Not fully interpolated version" error with Maven 4</li>
</ul>
<p>Changes for jackson-dataformats-binary:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes of 2.18.8</li>
<li>
<h1>696: (ion) Incomplete number length validation in Ion decoder</h1>
(for 'BigDecimal' and/or 'BigInteger')</li>
<li>Changes of 2.18.6</li>
<li>
<h1>645: (avro) Remove use of Avro 'Schema.Parser()</h1>
.setValidate()' to allow use of Avro core 1.12.1 (2.x)</li>
<li>
<h1>649: (cbor, smile) 'StreamReadConstraints.maxDocumentLength'</h1>
not checked when creating parser with fixed buffer</li>
<li>
<h1>651: (smile) Ensure Smile backend supports</h1>
'StreamReadConstraints.maxTokenCount'</li>
<li>
<h1>652: (cbor) Ensure CBOR backend supports</h1>
</li>
<li>Minor fix to 'ProtobufGenerator._reportEnumError()' helper
method</li>
<li>Changes of 2.18.5</li>
<li>
<h1>599: (cbor) Unable to deserialize stringref-enabled CBOR with</h1>
ignored properties</li>
<li>
<h1>623: (ion) Upgrade 'ion-java' dep to 1.11.11 (from 1.11.10)</h1>
</li>
<li>Changes of 2.18.4</li>
<li>
<h1>569: (ion) 'IonParser' fails to parse some 'long' values</h1>
saying they are out of range when they are not</li>
<li>
<h1>584: (protobuf) Missing 'JsonToken.END_OBJECT' for nested</h1>
Protobuf Objects</li>
<li>(ion) Upgrade 'ion-java' to 1.11.10 (from 1.11.9)</li>
<li>Changes of 2.18.3</li>
<li>
<h1>541: (cbor, protobuf, smile) 'SmileParser.getValueAsString()'</h1>
FIELD_NAME bug</li>
<li>Changes of 2.18.1</li>
<li>
<h1>518: Should not read past end for CBOR string values</h1>
</li>
<li>Changes of 2.18.0</li>
<li>
<h1>167: (avro) Incompatibility with Avro >=1.9.0 (upgrade to</h1>
Avro 1.11.3)</li>
<li>
<h1>484: (protobuf) Rework synchronization in 'ProtobufMapper'</h1>
</li>
<li>
<h1>494: (avro) Avro Schema generation: allow mapping Java Enum</h1>
properties to Avro String values</li>
<li>
<h1>508: (avro) Ignore 'specificData' field on serialization</h1>
</li>
<li>
<h1>509: IonValueMapper.builder() not implemented, does not</h1>
register modules</li>
<li>(ion) Upgrade 'ion-java' to 1.11.9 (from 1.11.8)
value</li>
</ul>
<p>Changes for jackson-modules-base:</p>
<ul>
<li>Upgrade to 2.18.8</li>
<li>No changes since 2.18.0</li>
<li>Changes of 2.18.0</li>
<li>
<h1>233: (jaxb) Tolerate JAX-RS 2.2 in</h1>
jackson-module-jaxb-annotations so that it can be deployed in
Liberty alongside features which use 2.2</li>
<li>
<h1>248: (android-record) jClass annotations and polymorphic</h1>
types are ignored when deserializing Android Record fields</li>
<li>
<h1>251: (android-record) Constructor is not recognized when a</h1>
record uses both arrays and generic types</li>
</ul>
<p>Changes for jackson-parent:</p>
<ul>
<li>Update to 2.18.4</li>
<li>Changes of 2.18.4</li>
<li>Update to latest 'oss-parent' (69)</li>
<li>Changes of 2.18.3</li>
<li>Update to latest 'oss-parent' (68)</li>
<li>Switch to publishing via Sonatype Central Portal repo</li>
<li>Changes of 2.18.2</li>
<li>Update to latest 'oss-parent' (66); future-proof for Sonatype
Central Portal</li>
<li>Changes of 2.18.1</li>
<li>
<h1>15: Add override to downgrade 'moditect-maven-plugin' from</h1>
1.2.2 to 1.1.0 to work around Eclipse issues</li>
<li>Changes of 2.18</li>
<li>Update to oss-parent 61 (plugin version updates)</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2801=1</code>
</li>
<li class="list-group-item">
Development Tools Module 15-SP7
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP6
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP5
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2801=1</code>
</li>
<li class="list-group-item">
Basesystem Module 15-SP7
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP5 LTSS
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP4 LTSS
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP6 LTSS
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2801=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2801=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
<ul>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
<ul>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
Basesystem Module 15-SP7 (noarch)
<ul>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
<ul>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
<ul>
<li>jackson-annotations-2.18.8-150200.3.22.3</li>
<li>jackson-databind-2.18.8-150200.3.28.2</li>
<li>jackson-core-2.18.8-150200.3.22.3</li>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
<li>
Development Tools Module 15-SP7 (noarch)
<ul>
<li>jackson-dataformat-cbor-2.18.8-150200.3.21.3</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54512.html">https://www.suse.com/security/cve/CVE-2026-54512.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54513.html">https://www.suse.com/security/cve/CVE-2026-54513.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54514.html">https://www.suse.com/security/cve/CVE-2026-54514.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54515.html">https://www.suse.com/security/cve/CVE-2026-54515.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268603">https://bugzilla.suse.com/show_bug.cgi?id=1268603</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268897">https://bugzilla.suse.com/show_bug.cgi?id=1268897</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268898">https://bugzilla.suse.com/show_bug.cgi?id=1268898</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268899">https://bugzilla.suse.com/show_bug.cgi?id=1268899</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268902">https://bugzilla.suse.com/show_bug.cgi?id=1268902</a>
</li>
</ul>
</div>