This CVE - https://avd.aquasec.com/nvd/2022/cve-2022-42003/ - references an issue in < 2.14.0 jackson-databind . #1377 will get us onto 2.13.4 of jackson-databind, and 2.14.0 is not yet available - it's at rc2 as of today. Once 2.14.0 is available, we'll want to upgrade to it, along with 2.14.0 for all jackson dependencies.