Describe the bug
Springdoc-openapi 3.1.1 targets Spring Boot 4.1, whose BOM manages Jackson 2 at 2.21.5 (4.2.0-M2 manages 2.21.6). In the same patch release, springdoc moves to swagger-core 2.2.55, which is built against Jackson 2.22.1. In a Gradle build that imports the Spring Boot BOM as a native platform, Gradle resolves the version conflict by taking the highest version. The whole Jackson 2 family then moves from 2.21.5 to 2.22.1 as soon as springdoc is added.
As a result, applications ship a Jackson line that Spring Boot does not manage. Right now that line is also vulnerable: jackson-databind 2.22.1 is affected by CVE-2026-68497 (GHSA-q4xh-88c3-wmh7, HIGH, fixed in 2.22.2 and 2.21.6).
With the io.spring.dependency-management plugin, or with Maven and the Spring Boot parent, the BOM wins instead, and swagger-core 2.2.55 runs on Jackson 2.21.5. That is below the version it declares.
To Reproduce
plugins {
id 'java'
id 'org.springframework.boot' version '4.1.1' apply false
}
repositories { mavenCentral() }
dependencies {
implementation platform('org.springframework.boot:spring-boot-dependencies:4.1.1')
implementation 'org.springframework.boot:spring-boot-starter-webmvc'
implementation 'org.springdoc:springdoc-openapi-starter-webmvc-ui:3.1.1'
}
./gradlew dependencyInsight --configuration runtimeClasspath --dependency com.fasterxml.jackson.core:jackson-databind
com.fasterxml.jackson.core:jackson-databind:2.22.1
Selection reasons:
- By conflict resolution: between versions 2.22.1 and 2.21.5
The same build with id 'io.spring.dependency-management' in place of platform(...) resolves 2.21.5.
Expected behavior
A springdoc release that targets a given Spring Boot line should not move applications off the Jackson line that Spring Boot manages, least of all in a patch release (3.1.0 to 3.1.1). Two possible directions: keep swagger-core on a version built for Jackson 2.21 while Spring Boot 4.1/4.2 manage 2.21.x, or state the required Jackson version in the release notes, so Gradle users know they must pin it.
Versions
- springdoc-openapi 3.1.1 (swagger-core 2.2.55)
- Spring Boot 4.1.1 (Jackson 2.21.5 managed)
- Gradle 9.7.1, Java 21
Additional context
As a workaround we force every com.fasterxml.jackson artifact to 2.21.7 via resolutionStrategy.eachDependency. All 257 Jackson classes, methods and fields that swagger-core 2.2.55 references exist in 2.21.7, and the generated OpenAPI document is identical to the one produced with 2.22.1.
Describe the bug
Springdoc-openapi 3.1.1 targets Spring Boot 4.1, whose BOM manages Jackson 2 at 2.21.5 (4.2.0-M2 manages 2.21.6). In the same patch release, springdoc moves to swagger-core 2.2.55, which is built against Jackson 2.22.1. In a Gradle build that imports the Spring Boot BOM as a native platform, Gradle resolves the version conflict by taking the highest version. The whole Jackson 2 family then moves from 2.21.5 to 2.22.1 as soon as springdoc is added.
As a result, applications ship a Jackson line that Spring Boot does not manage. Right now that line is also vulnerable: jackson-databind 2.22.1 is affected by CVE-2026-68497 (GHSA-q4xh-88c3-wmh7, HIGH, fixed in 2.22.2 and 2.21.6).
With the io.spring.dependency-management plugin, or with Maven and the Spring Boot parent, the BOM wins instead, and swagger-core 2.2.55 runs on Jackson 2.21.5. That is below the version it declares.
To Reproduce
The same build with id 'io.spring.dependency-management' in place of platform(...) resolves 2.21.5.
Expected behavior
A springdoc release that targets a given Spring Boot line should not move applications off the Jackson line that Spring Boot manages, least of all in a patch release (3.1.0 to 3.1.1). Two possible directions: keep swagger-core on a version built for Jackson 2.21 while Spring Boot 4.1/4.2 manage 2.21.x, or state the required Jackson version in the release notes, so Gradle users know they must pin it.
Versions
Additional context
As a workaround we force every com.fasterxml.jackson artifact to 2.21.7 via resolutionStrategy.eachDependency. All 257 Jackson classes, methods and fields that swagger-core 2.2.55 references exist in 2.21.7, and the generated OpenAPI document is identical to the one produced with 2.22.1.