Fasterxml

Jackson-databind

87 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.71%
  • Veröffentlicht 23.06.2026 21:17:02
  • Zuletzt bearbeitet 14.09.2026 13:18:40

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type b...

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 21:17:02
  • Zuletzt bearbeitet 27.06.2026 20:55:09

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, p...

  • EPSS 0.35%
  • Veröffentlicht 23.06.2026 21:17:02
  • Zuletzt bearbeitet 29.06.2026 13:38:59

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions ...

  • EPSS 0.28%
  • Veröffentlicht 23.06.2026 21:17:02
  • Zuletzt bearbeitet 27.06.2026 20:52:12

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 23.06.2026 21:17:01
  • Zuletzt bearbeitet 27.06.2026 21:05:59

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service rea...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 21:02:07
  • Zuletzt bearbeitet 27.06.2026 20:49:30

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator pa...

Medienbericht
  • EPSS 0.67%
  • Veröffentlicht 25.06.2025 17:02:57
  • Zuletzt bearbeitet 15.04.2026 00:35:42

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing ...

  • EPSS 0.35%
  • Veröffentlicht 14.06.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:58

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the...

Medienbericht Exploit
  • EPSS 1.12%
  • Veröffentlicht 18.03.2023 22:15:11
  • Zuletzt bearbeitet 26.02.2025 19:15:12

jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.

Exploit
  • EPSS 3.33%
  • Veröffentlicht 26.12.2022 20:15:10
  • Zuletzt bearbeitet 19.08.2025 16:37:03

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jt...