VYPR

rpm package

almalinux/pki-servlet-engine

pkg:rpm/almalinux/pki-servlet-engine

Vulnerabilities (3)

  • CVE-2026-54513HigJun 23, 2026
    affected < 1:9.0.62-1.module_el8.10.0+3791+e0637953fixed 1:9.0.62-1.module_el8.10.0+3791+e0637953

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),

  • CVE-2025-52999HigJun 25, 2025
    affected < 1:9.0.62-1.module_el8.10.0+3791+e0637953fixed 1:9.0.62-1.module_el8.10.0+3791+e0637953

    jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the de

  • CVE-2020-36518HigMar 11, 2022
    affected < 1:9.0.62-1.module_el8.10.0+3791+e0637953fixed 1:9.0.62-1.module_el8.10.0+3791+e0637953

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.