Database Cleaner 2.0.0, released 2026-07-28

July 28, 2026 ยท View on GitHub

Code name: Fixed vulnerability CVE-2026-9563 in org.eclipse.parsson:parsson:jar:1.1.7:test

Summary

Breaking Change: Starting with this release, Exasol version 7.1 is no longer supported. We only test against the latest version and the latest LTS version.

This release fixes the following vulnerability:

CVE-2026-9563 (CWE-400) in dependency org.eclipse.parsson:parsson:jar:1.1.7:test

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.

References

Security

  • #26: Fixed vulnerability CVE-2026-9563 in dependency org.eclipse.parsson:parsson:jar:1.1.7:test

Bugfixes

  • #20: Fixed purging database when user owns a schema

Dependency Updates

Runtime Dependency Updates

  • Updated com.exasol:exasol-jdbc:25.2.5 to 26.2.8

Test Dependency Updates

  • Updated com.exasol:exasol-testcontainers:7.2.0 to 8.0.1
  • Updated org.junit.jupiter:junit-jupiter-api:5.13.4 to 5.14.4
  • Updated org.slf4j:slf4j-jdk14:2.0.17 to 2.0.18
  • Removed org.testcontainers:testcontainers-junit-jupiter:2.0.1

Plugin Dependency Updates

  • Updated com.exasol:error-code-crawler-maven-plugin:2.0.5 to 2.1.0
  • Updated com.exasol:project-keeper-maven-plugin:5.4.3 to 5.7.4
  • Removed com.exasol:quality-summarizer-maven-plugin:0.2.1
  • Updated io.github.git-commit-id:git-commit-id-maven-plugin:9.0.2 to 10.0.0
  • Updated org.apache.maven.plugins:maven-compiler-plugin:3.14.1 to 3.15.0
  • Updated org.apache.maven.plugins:maven-enforcer-plugin:3.6.2 to 3.6.3
  • Updated org.apache.maven.plugins:maven-failsafe-plugin:3.5.4 to 3.5.6
  • Updated org.apache.maven.plugins:maven-resources-plugin:3.3.1 to 3.5.0
  • Updated org.apache.maven.plugins:maven-site-plugin:3.21.0 to 3.22.0
  • Updated org.apache.maven.plugins:maven-source-plugin:3.2.1 to 3.4.0
  • Updated org.apache.maven.plugins:maven-surefire-plugin:3.5.4 to 3.5.6
  • Added org.codehaus.mojo:build-helper-maven-plugin:3.6.1
  • Updated org.codehaus.mojo:versions-maven-plugin:2.19.1 to 2.21.0
  • Updated org.jacoco:jacoco-maven-plugin:0.8.14 to 0.8.15
  • Updated org.sonarsource.scanner.maven:sonar-maven-plugin:5.2.0.4988 to 5.7.0.6970
  • Updated org.sonatype.central:central-publishing-maven-plugin:0.9.0 to 0.11.0
  • Added org.spdx:spdx-maven-plugin:1.0.4