CVE-2026-54513
- EPSS 0.71%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 14.09.2026 13:18:40
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type b...
CVE-2026-54514
- EPSS 0.22%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:55:09
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, p...
CVE-2026-54515
- EPSS 0.35%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 29.06.2026 13:38:59
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions ...
CVE-2026-54516
- EPSS 0.28%
- Veröffentlicht 23.06.2026 21:17:02
- Zuletzt bearbeitet 27.06.2026 20:52:12
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the...
CVE-2026-50193
- EPSS 0.46%
- Veröffentlicht 23.06.2026 21:17:01
- Zuletzt bearbeitet 27.06.2026 21:05:59
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service rea...
CVE-2026-54518
- EPSS 0.26%
- Veröffentlicht 23.06.2026 21:02:07
- Zuletzt bearbeitet 27.06.2026 20:49:30
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator pa...
CVE-2025-52999
- EPSS 0.67%
- Veröffentlicht 25.06.2025 17:02:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing ...
CVE-2023-35116
- EPSS 0.35%
- Veröffentlicht 14.06.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:58
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the...
CVE-2021-46877
- EPSS 1.12%
- Veröffentlicht 18.03.2023 22:15:11
- Zuletzt bearbeitet 26.02.2025 19:15:12
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
CVE-2020-10650
- EPSS 3.33%
- Veröffentlicht 26.12.2022 20:15:10
- Zuletzt bearbeitet 19.08.2025 16:37:03
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jt...