Skip to content

PolymorphicTypeValidator needs to validate generic type parameters too [CVE-2026-54512] - #5988

Merged
cowtowncoder merged 9 commits into
2.18from
tatu-claude/2.18/jdb-011-generic-polymorphic-type-validation
May 12, 2026
Merged

PolymorphicTypeValidator needs to validate generic type parameters too [CVE-2026-54512]#5988
cowtowncoder merged 9 commits into
2.18from
tatu-claude/2.18/jdb-011-generic-polymorphic-type-validation

Conversation

@cowtowncoder

Copy link
Copy Markdown
Member

No description provided.

@cowtowncoder cowtowncoder self-assigned this May 11, 2026
@cowtowncoder cowtowncoder added the 2.18 Issues planned at 2.18 or later label May 11, 2026
@cowtowncoder
cowtowncoder marked this pull request as ready for review May 12, 2026 00:41
|| Modifier.isAbstract(subClass.getModifiers())) {
return Validity.ALLOWED;
}
// After array unwrap, also consult name-based matchers against the

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

note: Unrelated to main fix, unifies handling by fixing earlier code.

@cowtowncoder cowtowncoder added this to the 2.18.8 milestone May 12, 2026
@cowtowncoder
cowtowncoder merged commit 434d6c5 into 2.18 May 12, 2026
7 of 8 checks passed
@cowtowncoder
cowtowncoder deleted the tatu-claude/2.18/jdb-011-generic-polymorphic-type-validation branch May 12, 2026 01:40
cowtowncoder added a commit that referenced this pull request May 12, 2026
dongjoon-hyun added a commit to apache/spark that referenced this pull request Jun 5, 2026
### What changes were proposed in this pull request?

This PR upgrades `FasterXML` `Jackson` to 2.21.4.

### Why are the changes needed?

- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.21.4 (2026-05-28)
  - FasterXML/jackson-core#1611
  - FasterXML/jackson-databind#5931
  - FasterXML/jackson-databind#5950
  - FasterXML/jackson-databind#5951
  - FasterXML/jackson-databind#5967
  - FasterXML/jackson-databind#5969
  - FasterXML/jackson-databind#5971
  - FasterXML/jackson-databind#5974
  - FasterXML/jackson-databind#5981
  - FasterXML/jackson-databind#5988
  - FasterXML/jackson-databind#5993

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass the CIs.

### Was this patch authored or co-authored using generative AI tooling?

Generated-by: Claude Code (Claude Opus 4.8)

Closes #56338 from dongjoon-hyun/SPARK-57273.

Authored-by: Dongjoon Hyun <dongjoon@apache.org>
Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
@cowtowncoder cowtowncoder changed the title PolymorphicTypeValidator needs to validate generic type parameters too PolymorphicTypeValidator needs to validate generic type parameters too [CVE-2026-54512] Jun 16, 2026
@cowtowncoder cowtowncoder added the CVE Issues related to public CVEs (security vuln reports) label Jun 16, 2026
cowtowncoder added a commit that referenced this pull request Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2.18 Issues planned at 2.18 or later CVE Issues related to public CVEs (security vuln reports)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant