com.fasterxml.jackson.core:jackson-core
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.fasterxml.jackson.core:jackson-corepage 1 of 1
- CVE-2025-49128MEDIUMCVSS 4.0EG 4.0fixed in 2.13.02025-06-06
vulnerable: 2.0.0 ... 2.9.9 (124 versions)
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDes…
- CVE-2025-52999HIGHCVSS 8.7EG 8.7fixed in 2.15.02025-06-25
vulnerable: 2.0.0 ... 2.9.9 (143 versions)
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end u…
- CVE-2026-18401MEDIUMCVSS 6.9EG 6.9fixed in 2.21.1 or 2.18.6, by version range2026-08-04
vulnerable: 2.15.0 ... 2.18.5 (22 versions)
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async …
- CVE-2026-68494HIGHCVSS 8.7EG 8.7fixed in 2.18.8 or 2.21.4, by version range2026-08-04
vulnerable: 2.19.0 ... 2.21.3 (13 versions)
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validate…
- CVE-2026-89407HIGHCVSS 7.5EG 7.5fixed in 2.18.11, 2.21.7 or 2.22.3, by version range2026-09-22
vulnerable: 2.22.0, 2.22.1, 2.22.2
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, …
- CVE-2026-89425HIGHCVSS 7.5EG 7.5fixed in 2.21.7, 2.22.3 or 2.18.11, by version range2026-09-23
vulnerable: 2.10.0 ... 2.9.9 (97 versions)
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three si…
Check whether com.fasterxml.jackson.core:jackson-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.fasterxml.jackson.core:jackson-core CVEs against the assets you own.
Book a Demo →