VYPR

rpm package

opensuse/jackson-core&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/jackson-core&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-68494HigAug 4, 2026
    affected < 2.18.9-2.1fixed 2.18.9-2.1

    The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validateIntegerLength() into a new _setIntLength(

  • CVE-2026-18401MedAug 4, 2026
    affected < 2.18.9-2.1fixed 2.18.9-2.1

    The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of a