Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

High Severity CVE in transitive dependency `jackson-core`

Open
#1,198 3 comments 0 reactions 1 assignee View on GitHub

@lahirumaramba is already working on this.

Since May 27, 2026.

Assessment

This issue has not been assessed yet.

Description

api: core

firebase-admin-java 9.8.0 has a transitive dependency on com.fasterxml.jackson.core:jackson-core:2.18.2, which has https://osv.dev/vulnerability/GHSA-72hv-8253-57qq

here's the dependencyInsights output:

com.fasterxml.jackson.core:jackson-core:2.18.2 -> 2.18.6
--- com.google.cloud:google-cloud-storage:2.63.0
+--- runtimeClasspath (requested com.google.cloud:google-cloud-storage:{strictly 2.63.0})
+--- com.google.firebase:firebase-admin:9.8.0

(i couldnt find an open source repo for google-cloud-storage otherwise would have reported it there. Also tried to report through the security channel, but they said it wasnt severe enough to track as a security bug and to report on Github)

Dominant language
Java
Stars
620
Forks
305
Avg merge
3h 23m
Merged PRs (30d)
1

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from firebase/firebase-admin-java

All issues in firebase/firebase-admin-java

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.