VYPR

Maven package

com.fasterxml.jackson.core/jackson-databind

pkg:maven/com.fasterxml.jackson.core/jackson-databind

Vulnerabilities (76)

  • CVE-2026-54518MedJun 23, 2026
    affected >= 2.21.0, < 2.21.4fixed 2.21.4

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults pr

  • CVE-2026-54517MedJun 23, 2026
    affected >= 2.21.0, < 2.21.4fixed 2.21.4

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; t

  • CVE-2026-54516MedJun 23, 2026
    affected >= 2.21.0, < 2.21.4fixed 2.21.4

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the

  • CVE-2026-54515MedJun 23, 2026
    affected >= 3.1.0, < 3.1.4fixed 3.1.4

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameIn

  • CVE-2026-54514MedJun 23, 2026
    affected >= 2.0.0, < 2.18.8fixed 2.18.8

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS

  • CVE-2026-54513HigJun 23, 2026
    affected >= 2.10.0, < 2.18.8fixed 2.18.8

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),

  • CVE-2026-54512HigJun 23, 2026
    affected >= 2.10.0, < 2.18.8fixed 2.18.8

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization.

  • CVE-2026-50193HigJun 23, 2026
    affected >= 2.10.0, < 2.14.0fixed 2.14.0

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of lev

  • CVE-2021-46877HigMar 18, 2023
    affected >= 2.10.0, < 2.12.6fixed 2.12.6

    jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.

  • CVE-2020-10650HigDec 26, 2022
    affected < 2.9.10.4fixed 2.9.10.4

    A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and

  • CVE-2022-42003HigOct 2, 2022
    affected >= 2.4.0-rc1, < 2.12.7.1fixed 2.12.7.1

    In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

  • CVE-2020-36518HigMar 11, 2022
    affected >= 2.13.0, < 2.13.2.1fixed 2.13.2.1

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

  • CVE-2021-20190HigJan 19, 2021
    affected >= 2.7.0, < 2.9.10.7fixed 2.9.10.7

    A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-36183HigJan 7, 2021
    affected >= 2.7.00, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

  • CVE-2020-36182HigJan 7, 2021
    affected >= 2.7.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

  • CVE-2020-36180HigJan 7, 2021
    affected >= 2.7.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

  • CVE-2020-36179HigJan 7, 2021
    affected >= 2.7.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

  • CVE-2020-36189HigJan 6, 2021
    affected >= 2.7.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

  • CVE-2020-36188HigJan 6, 2021
    affected >= 2.7.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

  • CVE-2020-36187HigJan 6, 2021
    affected >= 2.0.0, < 2.9.10.8fixed 2.9.10.8

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

Page 1 of 4