CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-68496 HIGH

jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-68495 HIGH

jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-91777 HIGH

jackson-databind: quadratic forward-reference completion in Collection and Map deserializers

CVSS 7.5 EPSS 0.45% Sep 23, 2026
CVE-2026-91776 HIGH

jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID

CVSS 7.5 EPSS 0.45% Sep 23, 2026
CVE-2026-89425 HIGH

jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth

CVSS 7.5 EPSS 0.49% Sep 23, 2026
CVE-2026-89407 HIGH

jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoS

CVSS 7.5 EPSS 0.63% Sep 22, 2026
CVE-2026-68497 HIGH

jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service

CVSS 7.5 EPSS 0.58% Sep 11, 2026
CVE-2026-83557 MEDIUM

jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types

CVSS 5.6 EPSS 0.71% Sep 1, 2026
CVE-2026-19032 MEDIUM

jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path

CVSS 5.3 EPSS 0.53% Sep 1, 2026
CVE-2026-77310 MEDIUM

jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)

CVSS 5.3 EPSS 0.31% Aug 24, 2026
CVE-2026-68494 HIGH

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq)

CVSS 8.7 EPSS 0.62% Aug 4, 2026
CVE-2026-18401 MEDIUM

jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service

CVSS 6.9 EPSS 0.54% Aug 4, 2026
CVE-2026-59889 MEDIUM

jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization

CVSS 6.5 EPSS 0.39% Jul 14, 2026
CVE-2026-59888 MEDIUM

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

CVSS 6.5 EPSS 0.42% Jul 14, 2026
CVE-2026-54518 MEDIUM

jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind

CVSS 6.5 EPSS 0.35% Jun 23, 2026
CVE-2026-50193 MEDIUM

jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()

CVSS 6.3 EPSS 0.62% Jun 23, 2026
CVE-2026-54512 HIGH

jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation

CVSS 8.1 EPSS 1.00% Jun 23, 2026
CVE-2026-54513 HIGH

jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

CVSS 8.1 EPSS 1.23% Jun 23, 2026
CVE-2026-54514 MEDIUM

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

CVSS 5.3 EPSS 0.37% Jun 23, 2026
CVE-2026-54515 MEDIUM

jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties

CVSS 5.3 EPSS 0.44% Jun 23, 2026
CVE-2026-54516 MEDIUM

jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields

CVSS 5.3 EPSS 0.45% Jun 23, 2026
CVE-2026-54517 MEDIUM

jackson-databind: @JsonView bypass for setterless creator properties

CVSS 5.3 EPSS 0.38% Jun 23, 2026
CVE-2026-29062 HIGH

jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion

CVSS 8.7 EPSS 0.76% Mar 6, 2026
CVE-2025-52999 HIGH

jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data

CVSS 8.7 EPSS 0.77% Jun 25, 2025
CVE-2025-49128 MEDIUM

Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation

CVSS 4.0 EPSS 0.39% Jun 6, 2025

Showing 1 to 25 CVEs · page 1 (more available)