Update Nimbus, Fixes AB#3328426 #2724
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
AB#3328426
Updating the Nimbus Jose + JWT version to 10.0.2 due to CVE: Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON · CVE-2025-53864 · GitHub Advisory Database
I had to change two instances where an internal dependency of Nimbus was being used for modifiers (I believe said dependency is the one under the CVE); those have been changed to using javax, which is what's being used for most of the related modifiers in the codebase.
Ran the pipeline successfully on my branches: https://identitydivision.visualstudio.com/Engineering/_build/results?buildId=1514283&view=results
AuthApp: currently on 10.2.0.
CP: Notified, and they said they will update the version. CP built successfully on the pipeline.
LTW: Notified, and they moved to 10.0.2.
OneAuth: Notified; their test app built successfully on the pipeline.