More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2316421 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
I don't see any relation of picocli to the affected json-lib. Can you explain why do you think that picocli can be affected by this CVE?
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
I think this issue does not affect picocli. If you disagree please reopen this bug and elaborate what is the relation of picocli to the vulneralble json-lib.