Skip to content

[Snyk] Security upgrade com.hubspot.jinjava:jinjava from 2.6.0 to 2.8.1 - #13

Open
lyhbee wants to merge 1 commit into
mainfrom
snyk-fix-75a52af38164dc8e9be913dfc9bcaa61
Open

[Snyk] Security upgrade com.hubspot.jinjava:jinjava from 2.6.0 to 2.8.1#13
lyhbee wants to merge 1 commit into
mainfrom
snyk-fix-75a52af38164dc8e9be913dfc9bcaa61

Conversation

@lyhbee

@lyhbee lyhbee commented Jan 6, 2026

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 26 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • java/ql/test/utils/flowtestcasegenerator/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
  709   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
  670   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
  643   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
  587   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
  479   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
critical severity Improper Neutralization of Special Elements Used in a Template Engine
SNYK-JAVA-COMHUBSPOTJINJAVA-12878604
  460   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
  450   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
  428   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
  417   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
  405   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
  364   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
  311   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
  308   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
  308   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
  304   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
  300   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
  282   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
  281   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
  280   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
  279   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
  278   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
  278   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
  277   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
  275   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
  274   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
  274   com.hubspot.jinjava:jinjava:
2.6.0 -> 2.8.1
Reachable No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Deserialization of Untrusted Data

…rabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMHUBSPOTJINJAVA-12878604
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
@github-actions github-actions Bot added the java Pull requests that update Java code label Jan 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants