diff --git a/.trivyignore b/.trivyignore
index cc7f674..3511344 100644
--- a/.trivyignore
+++ b/.trivyignore
@@ -15,14 +15,6 @@ GHSA-72hv-8253-57qq exp:2026-09-01
# Availability only (C:N/I:N/A:H). Tracking via UID2-7035; revisit on vert.x 5 migration.
CVE-2026-42577 exp:2026-09-11
-# jackson-databind data-binding vulnerability - no upstream fix released yet (fix targets: 2.18.8, 2.21.4, 3.1.4)
-# jackson-databind is pulled in transitively via uid2-shared; the version fix is tracked in
-# uid2-shared (https://github.com/IABTechLab/uid2-shared/pull/631) and will flow here on the
-# next uid2-shared release. Suppressing in the interim.
-# See: UID2-7364
-CVE-2026-54512 exp:2026-07-25
-CVE-2026-54513 exp:2026-07-25
-
# CVE-2026-2100 — p11-kit NULL dereference via C_DeriveKey in the Alpine base image.
# uid2-core is a pure Java service; the JVM uses JSSE for TLS and the bundled Java cacerts keystore for trust — it does
# not load the native p11-kit PKCS#11 module loader and never calls C_DeriveKey, so the
diff --git a/pom.xml b/pom.xml
index 5dd9cc2..dcd86a2 100644
--- a/pom.xml
+++ b/pom.xml
@@ -25,7 +25,8 @@
io.vertx.core.Launcher
11.6.0
- 4.1.135.Final
+ 4.1.136.Final
+ 2.21.4
${project.version}
@@ -50,6 +51,15 @@
+
+
+ com.fasterxml.jackson
+ jackson-bom
+ ${jackson.version}
+ pom
+ import
+
io.netty
netty-bom