diff --git a/NEXT_CHANGELOG.md b/NEXT_CHANGELOG.md
index fcecbbce3..dcc3e4e54 100644
--- a/NEXT_CHANGELOG.md
+++ b/NEXT_CHANGELOG.md
@@ -6,6 +6,7 @@
### Updated
- `DatabaseMetaData.getColumns(...)` with a `null` catalog now issues a single `SHOW COLUMNS IN ALL CATALOGS` statement (consistent with `getSchemas`/`getTables`) instead of enumerating every catalog and issuing a per-catalog `SHOW COLUMNS`. Older DBR versions that do not support the syntax transparently fall back to the previous enumerate-and-fan-out behavior.
+- Updated bundled Jackson, lz4-java, Netty, and Apache HttpComponents Client and Core dependencies to patched versions to address security findings.
### Fixed
- Invalid or incomplete Databricks JDBC URLs now fail with a descriptive `DatabricksSQLException`
diff --git a/pom.xml b/pom.xml
index 600f6da7d..e2731bf6b 100644
--- a/pom.xml
+++ b/pom.xml
@@ -71,18 +71,18 @@
2.14.0
0.118.0
4.5.14
- 5.5.2
- 5.3.6
+ 5.6.3
+ 5.4.3
0.23.0
2.0.13
- 2.18.8
+ 2.18.9
2.13.2
33.0.0-jre
3.0.1
2.9.2
- 1.10.1
+ 1.11.1
1.3.5
- 4.2.13.Final
+ 4.2.15.Final
1.71.0
1.20.0
1.7.0