CVE-2026-59889
- EPSS 0.35%
- Veröffentlicht 14.07.2026 19:57:48
- Zuletzt bearbeitet 16.07.2026 16:19:15
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @J...
CVE-2026-59888
- EPSS 0.25%
- Veröffentlicht 14.07.2026 16:44:20
- Zuletzt bearbeitet 15.07.2026 20:18:23
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOProperties...
CVE-2026-54512
- EPSS 0.78%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 21:01:36
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guardin...
CVE-2026-54517
- EPSS 0.3%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:51:09
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied...
CVE-2026-54516
- EPSS 0.28%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:52:12
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the...
CVE-2026-54515
- EPSS 0.35%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 29.06.2026 13:38:59
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions ...
CVE-2026-54514
- EPSS 0.22%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:55:09
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, p...
CVE-2026-54513
- EPSS 0.71%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 14.08.2026 13:19:03
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type b...
CVE-2026-50193
- EPSS 0.46%
- Veröffentlicht 23.06.2026 21:17:01
- Zuletzt bearbeitet 27.06.2026 21:05:59
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service rea...
CVE-2026-54518
- EPSS 0.26%
- Veröffentlicht 23.06.2026 21:02:07
- Zuletzt bearbeitet 27.06.2026 20:49:30
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator pa...