CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service
jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service
jackson-databind: quadratic forward-reference completion in Collection and Map deserializers
jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth
jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoS
jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service
jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types
jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq)
jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields
jackson-databind: @JsonView bypass for setterless creator properties
jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data
Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
Showing 1 to 25 CVEs · page 1 (more available)