Hi JB,

Is it too late to cherry-pick
https://github.com/apache/activemq/commit/d1fd0aa953060c7d933def98691d90ac17da174d
and re-spin the releases? There are some Jackson CVEs:

│ com.fasterxml.jackson.core:jackson-core                   │
GHSA-r7wm-3cxj-wff9 │ HIGH     │ fixed  │ 2.22.0            │ 2.18.8,
2.21.4, 2.22.1                     │ jackson-core: Async parser
maxNumberLength bypass via      │
│ (jackson-core-2.22.0.jar)                                 │
           │          │        │                   │
                         │ chunked digit accumulation (incomplete fix
for...          │
│                                                           │
           │          │        │                   │
                         │
https://github.com/advisories/GHSA-r7wm-3cxj-wff9          │
├───────────────────────────────────────────────────────────┼─────────────────────┼──────────┤
       │
├────────────────────────────────────────────┼────────────────────────────────────────────────────────────┤
│ com.fasterxml.jackson.core:jackson-databind               │
CVE-2026-54515      │ MEDIUM   │        │                   │ 3.1.4,
2.18.9, 2.21.5, 2.22.1              │ jackson-databind:
jackson-databind: Ignored properties can │
│ (jackson-databind-2.22.0.jar)                             │
           │          │        │                   │
                         │ be unexpectedly modified
               │
│                                                           │
           │          │        │                   │
                         │ https://avd.aquasec.com/nvd/cve-2026-54515
               │
│
├─────────────────────┤          │        │
├────────────────────────────────────────────┼────────────────────────────────────────────────────────────┤
│                                                           │
CVE-2026-59889      │          │        │                   │ 2.21.5,
2.18.9, 2.22.1                     │ jackson-databind: @JsonView
ypassed for @JsonUnwrapped     │
│                                                           │
           │          │        │                   │
                         │ container properties on deserialization
               │
│                                                           │
           │          │        │                   │
                         │ https://avd.aquasec.com/nvd/cve-2026-59889
               │
├───────────────────────────────────────────────────────────┼───────────────────

Colm.

On Fri, Jul 24, 2026 at 5:34 AM Jean-Baptiste Onofré <[email protected]> wrote:
>
> Hi everyone,
>
> I propose Apache ActiveMQ 6.2.8 (rc1) release for your vote.
>
> This is a maintenance release for the 6.2.x series, including:
> - Add better frame size validation for AMQP
> - Prevent cursor from using more than 100% temp store
> - Fire message discarded advisory on format errors
> - Add metrics about error and reconnect counts to network connector
> - Expose NetworkConnector URI and local URI in JMX MBean
>
> You can review the Pre-Release Notes for details:
> https://github.com/apache/activemq/releases/tag/activemq-6.2.8
>
> Staging Maven Repository:
> https://repository.apache.org/content/repositories/orgapacheactivemq-1495/
>
> Staging Dist Repository:
> https://dist.apache.org/repos/dist/dev/activemq/activemq/6.2.8/
>
> Git tag:
> https://github.com/apache/activemq/tree/activemq-6.2.8
>
> Please vote to approve this release:
> [ ] +1 Approve the release
> [ ] 0 I don't care
> [ ] -1 Don't approve the release (please provide specific comment)
>
> This vote will be open for at least 72 hours.
>
> Thanks!
> Regards
> JB
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> For further information, visit: https://activemq.apache.org/contact
>
>

Reply via email to