Fasterxml / Jackson-Databind
85 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-91777 | jackson-databind: quadratic forward-reference completion in Collection and Map deserializers | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-91776 | jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID | HIGH | 7.5 | Sep 23, 2026 |
| CVE-2026-68497 | jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service | HIGH | 7.5 | Sep 11, 2026 |
| CVE-2026-83557 | jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types | MEDIUM | 5.6 | Sep 1, 2026 |
| CVE-2026-19032 | jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path | MEDIUM | 5.3 | Sep 1, 2026 |
| CVE-2026-59889 | jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization | MEDIUM | 6.5 | Jul 14, 2026 |
| CVE-2026-59888 | jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy | MEDIUM | 6.5 | Jul 14, 2026 |
| CVE-2026-54518 | jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind | MEDIUM | 6.5 | Jun 23, 2026 |
| CVE-2026-50193 | jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString() | MEDIUM | 6.3 | Jun 23, 2026 |
| CVE-2026-54512 | jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation | HIGH | 8.1 | Jun 23, 2026 |
| CVE-2026-54513 | jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) | HIGH | 8.1 | Jun 23, 2026 |
| CVE-2026-54514 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2026-54515 | jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2026-54516 | jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2026-54517 | jackson-databind: @JsonView bypass for setterless creator properties | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2023-35116 | jackson-databind: denial of service via cylic dependencies | MEDIUM | 4.7 | Jun 14, 2023 |
| CVE-2021-46877 | jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode | HIGH | 7.5 | Mar 18, 2023 |
| CVE-2020-10650 | A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or… | HIGH | 8.1 | Dec 26, 2022 |
| CVE-2022-42004 | jackson-databind: use of deeply nested arrays | HIGH | 8.2 | Oct 2, 2022 |
| CVE-2022-42003 | jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS | HIGH | 7.5 | Oct 2, 2022 |
| CVE-2020-36518 | jackson-databind: denial of service via a large depth of nested objects | HIGH | 7.5 | Mar 11, 2022 |
| CVE-2021-20190 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing | HIGH | 8.1 | Jan 19, 2021 |
| CVE-2020-36179 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
Showing 1 to 25 of 85 CVEs