We're using Flowable 8.0.0, the latest release (2026-02-27):
org.flowable:flowable-engine:8.0.0
org.flowable:flowable-dmn-engine:8.0.0
org.flowable:flowable-dmn-engine-configurator:8.0.0
Our vulnerability scanner reports several HIGH vulnerabilities in the Jackson 3 dependencies. org.flowable:flowable-engine-common:8.0.0 pulls in tools.jackson.core:jackson-core and tools.jackson.core:jackson-databind in version 3.0.1.
Vulnerabilities
Jackson 3.1.7 fixes all of them.
Workaround
As a workaround, we import tools.jackson:jackson-bom:3.1.7 in our <dependencyManagement>. Our test suite passes with Flowable 8.0.0 on Jackson 3.1.7.
Question
Could you upgrade Jackson to 3.1.7 (or 3.2.3), and is a release with the upgrade planned?
We're using Flowable
8.0.0, the latest release (2026-02-27):org.flowable:flowable-engine:8.0.0org.flowable:flowable-dmn-engine:8.0.0org.flowable:flowable-dmn-engine-configurator:8.0.0Our vulnerability scanner reports several HIGH vulnerabilities in the Jackson 3 dependencies.
org.flowable:flowable-engine-common:8.0.0pulls intools.jackson.core:jackson-coreandtools.jackson.core:jackson-databindin version3.0.1.Vulnerabilities
Jackson
3.1.7fixes all of them.Workaround
As a workaround, we import
tools.jackson:jackson-bom:3.1.7in our<dependencyManagement>. Our test suite passes with Flowable8.0.0on Jackson3.1.7.Question
Could you upgrade Jackson to
3.1.7(or3.2.3), and is a release with the upgrade planned?