Skip to content

fix(security): bound Jackson fallback cache for TFS bug 712021 - #162

Open
dev-bot-laserfiche wants to merge 1 commit into
v2from
devbot/veracode/sca-app-1791266-comp-5bc97c69-5880-48b2-aead-85df2b6ee5dd
Open

dev-bot-laserfiche wants to merge 1 commit into
v2from
devbot/veracode/sca-app-1791266-comp-5bc97c69-5880-48b2-aead-85df2b6ee5dd

Conversation

@dev-bot-laserfiche

@dev-bot-laserfiche dev-bot-laserfiche commented Oct 1, 2026 •

Copy link
Copy Markdown

Description of changes: Fix CVE-2026-91776 in the Jackson dependency used by the v2 Repository API client, tracked by TFS bug 712021.

The finding is reachable, not a component-match false positive: Entry uses JsonTypeInfo.Id.NAME with defaultImpl = Entry.class, and repository responses are deserialized through the reusable TokenClientObjectMapper. EntryType.fromValue() returns null for unknown values rather than rejecting them before polymorphic resolution. A bounded reproduction using that actual mapper and model retained 10,000 cache entries after 10,000 distinct unknown entryType values on 2.21.6, versus one entry when the same value was repeated.

Update the shared jackson-version property from 2.21.6 to 2.21.7. This upgrades jackson-databind and jackson-core together, remains in the existing 2.21 LTS policy, and leaves the separately versioned jackson-annotations at 2.21. Maven Central confirms 2.21.7 is the latest patch in this line. Its upstream TypeDeserializerBase patch bounds the type-ID cache to 1,000 entries and skips caching IDs longer than 256 characters. Jackson is used at runtime by the mapper and cannot be removed as an unused dependency. This Maven project has no dependency lockfile.

Add four unit regressions using the actual mapper/model: 10,000 distinct versus repeated unknown IDs, overlong IDs, and preservation of all four known subtypes. Update the changelog. Existing PRs 159 and 160 target older Jackson versions and do not address this CVE; merged PR 161 established the current 2.21.6 baseline.

Verification on JDK 8:

  • The cache-bound and overlong-ID regressions fail against 2.21.6; repeated-ID and known-subtype controls pass.
  • mvn -B -q -Dspotless.apply.skip=true -Dtest='com.laserfiche.repository.api.unit.**' clean package passes all 29 unit tests and packages successfully. The lifecycle formatter is skipped to avoid unrelated reformatting of existing generated sources.
  • mvn -B -q spotless:check -DspotlessFiles=src/test/java/com/laserfiche/repository/api/unit/EntryDeserializationTest.java passes.
  • The same standalone reproduction retains only 1,000 entries for 10,000 distinct IDs on 2.21.7, while the repeated-ID control remains one.
  • dependency:tree resolves jackson-databind/core 2.21.7 and jackson-annotations 2.21. Live cloud integration tests require CI secrets and were not run locally.

Hosted CI: build, all 29 unit tests, and CodeQL pass. build-n-test and integration-test-results-cloud are red in the PR run because the live cloud suite reports empty search results, six missing-entry fixture errors, and an invalid/expired access token; cleanup also reports an authentication error. A fresh unchanged v2 baseline run at commit 82188486112c77786fe8390cfc82df536130a3a8, still using Jackson 2.21.6, reproduces the same three search failures, six missing-entry errors, and invalid/expired token failure. These main integration failures therefore exist without this change. Documentation and publishing jobs are skipped after the integration failure. No unrelated test/environment changes are included.

Work item links

Upgrade Jackson databind/core to 2.21.7 within the existing LTS line to
bound the polymorphic fallback type-ID cache (CVE-2026-91776).
Add regression coverage with the actual client mapper and Entry model.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

unit-test-results

29 tests  +4   29 ✅ +4   0s ⏱️ ±0s
 4 suites +1    0 💤 ±0 
 4 files   +1    0 ❌ ±0 

Results for commit acd03b1. ± Comparison against base commit 8218848.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

integration-test-results-cloud

78 tests  +1   66 ✅  - 10   3m 43s ⏱️ + 1m 2s
16 suites ±0    1 💤 ± 0 
16 files   ±0    3 ❌ + 3   8 🔥 +8 

For more details on these failures and errors, see this check.

Results for commit acd03b1. ± Comparison against base commit 8218848.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant