{"id":"CGA-p452-3jc4-366m","modified":"2026-09-04T10:17:39.480229541Z","published":"2026-08-05T19:05:31Z","upstream":["GHSA-mhm7-754m-9p8w"],"references":[{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"},{"type":"PACKAGE","url":"https://github.com/FasterXML/jackson-databind"}],"affected":[{"package":{"name":"spark-fips-4.2-scala-2.13","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/spark-fips-4.2-scala-2.13?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.0-r7"}]}],"ecosystem_specific":{"components":[{"component_name":"jackson-databind","component_version":"2.18.6","component_type":"java-archive","component_location":"/usr/lib/spark/jars/hadoop-client-runtime-3.5.0.jar","component_purl":"pkg:maven/jackson-databind@2.18.6","latest_event_status":"fixed","latest_event_timestamp":"2026-09-04T05:51:12Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-p452-3jc4-366m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}