Fasterxml / Jackson-Core
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-89425 | jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-89407 | jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoS | HIGH | 7.5 | Sep 22, 2026 |
| CVE-2026-68494 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq) | HIGH | 8.7 | Aug 4, 2026 |
| CVE-2026-18401 | jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service | MEDIUM | 6.9 | Aug 4, 2026 |
| CVE-2026-29062 | jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion | HIGH | 8.7 | Mar 6, 2026 |
| CVE-2025-52999 | jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data | HIGH | 8.7 | Jun 25, 2025 |
| CVE-2025-49128 | Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation | MEDIUM | 4.0 | Jun 6, 2025 |
Showing 1 to 7 of 7 CVEs