Skip to content

springdoc 3.1.1 lifts Jackson to 2.22.x in Gradle builds on Spring Boot 4.1, which manages 2.21.x #3373

Description

@mgeri

Describe the bug

Springdoc-openapi 3.1.1 targets Spring Boot 4.1, whose BOM manages Jackson 2 at 2.21.5 (4.2.0-M2 manages 2.21.6). In the same patch release, springdoc moves to swagger-core 2.2.55, which is built against Jackson 2.22.1. In a Gradle build that imports the Spring Boot BOM as a native platform, Gradle resolves the version conflict by taking the highest version. The whole Jackson 2 family then moves from 2.21.5 to 2.22.1 as soon as springdoc is added.

As a result, applications ship a Jackson line that Spring Boot does not manage. Right now that line is also vulnerable: jackson-databind 2.22.1 is affected by CVE-2026-68497 (GHSA-q4xh-88c3-wmh7, HIGH, fixed in 2.22.2 and 2.21.6).

With the io.spring.dependency-management plugin, or with Maven and the Spring Boot parent, the BOM wins instead, and swagger-core 2.2.55 runs on Jackson 2.21.5. That is below the version it declares.

To Reproduce

plugins {
    id 'java'
    id 'org.springframework.boot' version '4.1.1' apply false
}
repositories { mavenCentral() }
dependencies {
    implementation platform('org.springframework.boot:spring-boot-dependencies:4.1.1')
    implementation 'org.springframework.boot:spring-boot-starter-webmvc'
    implementation 'org.springdoc:springdoc-openapi-starter-webmvc-ui:3.1.1'
}
./gradlew dependencyInsight --configuration runtimeClasspath --dependency com.fasterxml.jackson.core:jackson-databind

com.fasterxml.jackson.core:jackson-databind:2.22.1
   Selection reasons:
      - By conflict resolution: between versions 2.22.1 and 2.21.5

The same build with id 'io.spring.dependency-management' in place of platform(...) resolves 2.21.5.

Expected behavior

A springdoc release that targets a given Spring Boot line should not move applications off the Jackson line that Spring Boot manages, least of all in a patch release (3.1.0 to 3.1.1). Two possible directions: keep swagger-core on a version built for Jackson 2.21 while Spring Boot 4.1/4.2 manage 2.21.x, or state the required Jackson version in the release notes, so Gradle users know they must pin it.

Versions

  • springdoc-openapi 3.1.1 (swagger-core 2.2.55)
  • Spring Boot 4.1.1 (Jackson 2.21.5 managed)
  • Gradle 9.7.1, Java 21

Additional context
As a workaround we force every com.fasterxml.jackson artifact to 2.21.7 via resolutionStrategy.eachDependency. All 257 Jackson classes, methods and fields that swagger-core 2.2.55 references exist in 2.21.7, and the generated OpenAPI document is identical to the one produced with 2.22.1.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions