CVE-2026-91777
- EPSS 0.45%
- Veröffentlicht 23.09.2026 02:21:48
- Zuletzt bearbeitet 24.09.2026 20:43:32
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulato...
CVE-2026-91776
- EPSS 0.45%
- Veröffentlicht 23.09.2026 02:17:50
- Zuletzt bearbeitet 24.09.2026 20:43:32
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, def...
CVE-2026-68497
- EPSS 0.58%
- Veröffentlicht 11.09.2026 15:49:30
- Zuletzt bearbeitet 18.09.2026 19:34:36
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers....
CVE-2026-83557
- EPSS 0.59%
- Veröffentlicht 01.09.2026 14:57:01
- Zuletzt bearbeitet 08.09.2026 19:29:32
DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base types", and...
CVE-2026-19032
- EPSS 0.46%
- Veröffentlicht 01.09.2026 03:18:42
- Zuletzt bearbeitet 08.09.2026 19:29:32
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and th...
CVE-2026-77310
- EPSS 0.19%
- Veröffentlicht 24.08.2026 19:24:59
- Zuletzt bearbeitet 09.09.2026 21:06:39
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromS...
CVE-2026-59889
- EPSS 0.35%
- Veröffentlicht 14.07.2026 19:57:48
- Zuletzt bearbeitet 16.07.2026 16:19:15
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @J...
CVE-2026-59888
- EPSS 0.25%
- Veröffentlicht 14.07.2026 16:44:20
- Zuletzt bearbeitet 15.07.2026 20:18:23
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOProperties...
CVE-2026-54517
- EPSS 0.3%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:51:09
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied...
CVE-2026-54512
- EPSS 0.78%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 21:01:36
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guardin...