Fasterxml

Jackson-core

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 23.09.2026 02:06:10
  • Zuletzt bearbeitet 24.09.2026 20:43:32

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parse...

  • EPSS 0.63%
  • Veröffentlicht 22.09.2026 14:53:20
  • Zuletzt bearbeitet 22.09.2026 20:00:03

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2....

  • EPSS 0.37%
  • Veröffentlicht 04.08.2026 14:39:14
  • Zuletzt bearbeitet 08.09.2026 19:29:32

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validateIntegerLeng...

  • EPSS 0.31%
  • Veröffentlicht 04.08.2026 14:23:27
  • Zuletzt bearbeitet 08.09.2026 19:29:32

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API ...

Medienbericht
  • EPSS 0.55%
  • Veröffentlicht 06.03.2026 07:14:25
  • Zuletzt bearbeitet 15.07.2026 02:19:22

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataIn...