VYPR

Maven package

tools.jackson.core/jackson-core

pkg:maven/tools.jackson.core/jackson-core

Vulnerabilities (3)

  • CVE-2026-89425HigSep 23, 2026
    affected >= 3.0.0, < 3.1.7fixed 3.1.7

    UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including U

  • CVE-2026-89407HigSep 22, 2026
    affected >= 3.0.0, < 3.1.7fixed 3.1.7

    NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adj

  • CVE-2026-29062HigMar 6, 2026
    affected >= 3.0.0, < 3.1.0fixed 3.1.0

    jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNe