Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2026-68496
- EPSS 0.67%
- Veröffentlicht 01.10.2026 17:36:57
- Zuletzt bearbeitet 02.10.2026 18:44:11
The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName()...
7.5
CVE-2026-68495
- EPSS 0.67%
- Veröffentlicht 01.10.2026 17:36:22
- Zuletzt bearbeitet 02.10.2026 18:44:11
The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() deco...
7.5
CVE-2020-28491
- EPSS 3.07%
- Veröffentlicht 18.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:22:53
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
1