Skip to content

Improve GHSA-r7wm-3cxj-wff9 - #8984

Open
anthonydahanne wants to merge 1 commit into
github:anthonydahanne/advisory-improvement-8984from
anthonydahanne:anthonydahanne-GHSA-r7wm-3cxj-wff9
Open

Improve GHSA-r7wm-3cxj-wff9#8984
anthonydahanne wants to merge 1 commit into
github:anthonydahanne/advisory-improvement-8984from
anthonydahanne:anthonydahanne-GHSA-r7wm-3cxj-wff9

Conversation

@anthonydahanne

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • References

Comments
Adding the CVE ID assigned by HeroDevs (CNA): CVE-2026-68494, published 2026-08-04. The CVE record cites this GHSA as its source advisory and links CVE-2026-18401 as the incomplete-fix parent.

Three corrections to the affected-version data:

The 2.22.x and 3.2.x lines appear to be missing. Per the upstream release notes the fix also shipped in 2.22.1 and 3.2.1, so >= 2.22.0, < 2.22.1 and >= 3.2.0, < 3.2.1 should be listed as affected. Users on those lines currently receive no alert.
The 2.x range has no lower bound (introduced: 0). maxNumberLength was introduced in 2.15.0, so releases before that have no constraint to bypass. Note GHSA-72hv-8253-57qq's OSV export already uses introduced: 2.15.0.
Minor factual error in the description: "The parent advisory was scored CVSS 8.7 High" — GHSA-72hv-8253-57qq is scored 6.9 Moderate. 8.7 is this advisory's score.

Copilot AI balanced review requested due to automatic review settings August 4, 2026 22:39
@github-actions
github-actions Bot changed the base branch from main to anthonydahanne/advisory-improvement-8984 August 4, 2026 22:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Jackson async-parser advisory with new CVE metadata and revised affected-version information.

Changes:

  • Adds CVE-2026-68494 and its reference.
  • Corrects the lower bound and parent CVSS score.
  • Adds 2.22.x and 3.2.x ranges, though upstream evidence shows those releases already contain the fix.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread advisories/github-reviewed/2026/07/GHSA-r7wm-3cxj-wff9/GHSA-r7wm-3cxj-wff9.json Outdated
Comment thread advisories/github-reviewed/2026/07/GHSA-r7wm-3cxj-wff9/GHSA-r7wm-3cxj-wff9.json Outdated
Comment thread advisories/github-reviewed/2026/07/GHSA-r7wm-3cxj-wff9/GHSA-r7wm-3cxj-wff9.json Outdated
@anthonydahanne
anthonydahanne force-pushed the anthonydahanne-GHSA-r7wm-3cxj-wff9 branch from cd30fc0 to fd7a673 Compare August 5, 2026 01:46
@anthonydahanne
anthonydahanne force-pushed the anthonydahanne-GHSA-r7wm-3cxj-wff9 branch from fd7a673 to 1fedaa7 Compare August 5, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants