com.fasterxml.jackson.core:jackson-databind
Maven85 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.fasterxml.jackson.core:jackson-databindpage 2 of 2
- CVE-2020-36180HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-07
vulnerable: 2.0.0 ... 2.6.7.4 (63 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
- CVE-2020-36181HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-06
vulnerable: 2.0.0 ... 2.6.7.4 (63 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
- CVE-2020-36182HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-07
vulnerable: 2.0.0 ... 2.6.7.4 (63 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
- CVE-2020-36183HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-07
vulnerable: 2.0.0 ... 2.6.7.4 (63 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
- CVE-2020-36184HIGHCVSS 8.1EG 8.1fixed in 2.9.10.82021-01-06
vulnerable: 2.0.0 ... 2.9.9.3 (131 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
- CVE-2020-36185HIGHCVSS 8.1EG 8.1fixed in 2.9.10.82021-01-06
vulnerable: 2.0.0 ... 2.9.9.3 (131 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
- CVE-2020-36186HIGHCVSS 8.1EG 8.1fixed in 2.9.10.82021-01-06
vulnerable: 2.0.0 ... 2.9.9.3 (131 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
- CVE-2020-36187HIGHCVSS 8.1EG 8.1fixed in 2.9.10.82021-01-06
vulnerable: 2.0.0 ... 2.9.9.3 (131 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
- CVE-2020-36188HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-06
vulnerable: 2.0.0 ... 2.6.7.4 (63 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
- CVE-2020-36189HIGHCVSS 8.1EG 8.1fixed in 2.9.10.8 or 2.6.7.5, by version range2021-01-06
vulnerable: 2.0.0 ... 2.6.7.4 (66 versions)
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
- CVE-2020-36518HIGHCVSS 7.5EG 7.5fixed in 2.13.2.1 or 2.12.6.1, by version range2022-03-11
vulnerable: 2.0.0 ... 2.9.9.3 (160 versions)
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
- CVE-2020-8840CRITICALCVSS 9.8EG 9.8fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5 or 2.9.10.3, by version range2020-02-10
vulnerable: 2.9.0 ... 2.9.9.3 (20 versions)
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
- CVE-2020-9546CRITICALCVSS 9.8EG 9.8fixed in 2.9.10.42020-03-02
vulnerable: 2.9.0 ... 2.9.9.3 (21 versions)
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
- CVE-2020-9547CRITICALCVSS 9.8EG 9.8fixed in 2.9.10.4, 2.8.11.6 or 2.7.9.7, by version range2020-03-02
vulnerable: 2.0.0 ... 2.7.9.6 (84 versions)
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
- CVE-2020-9548CRITICALCVSS 9.8EG 9.8fixed in 2.9.10.4, 2.8.11.6 or 2.7.9.7, by version range2020-03-02
vulnerable: 2.0.0 ... 2.7.9.6 (84 versions)
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
- CVE-2021-20190HIGHCVSS 8.1EG 8.1fixed in 2.9.10.7 or 2.6.7.5, by version range2021-01-19
vulnerable: 2.0.0 ... 2.6.7.4 (66 versions)
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system avai…
- CVE-2021-46877HIGHCVSS 7.5EG 7.5fixed in 2.12.6 or 2.13.1, by version range2023-03-18
vulnerable: 2.13.0
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
- CVE-2022-42003HIGHCVSS 7.5EG 7.5fixed in 2.12.7.1 or 2.13.4.2, by version range2022-10-02
vulnerable: 2.13.0 ... 2.13.4.1 (8 versions)
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feat…
- CVE-2022-42004HIGHCVSS 7.5EG 7.5fixed in 2.12.7.1 or 2.13.4, by version range2022-10-02
vulnerable: 2.13.0 ... 2.13.3 (6 versions)
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain custom…
- CVE-2026-19032MEDIUMCVSS 5.3EG 5.3fixed in 2.18.10, 2.21.6 or 2.22.2, by version range2026-09-01
vulnerable: 2.22.0, 2.22.1
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(va…
- CVE-2026-50193HIGHCVSS 7.5EG 7.5fixed in 2.14.02026-06-23
vulnerable: 2.10.0 ... 2.14.0-rc3 (44 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the …
- CVE-2026-54512HIGHCVSS 8.1EG 8.1fixed in 2.18.8, 3.1.4 or 2.21.4, by version range2026-06-23
vulnerable: 2.19.0 ... 2.21.3 (13 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechan…
- CVE-2026-54513HIGHCVSS 8.1EG 8.1fixed in 2.18.8, 2.21.4 or 3.1.4, by version range2026-06-23
vulnerable: 2.19.0 ... 2.21.3 (13 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any a…
- CVE-2026-54514MEDIUMCVSS 5.3EG 5.3fixed in 2.18.8, 2.21.4 or 3.1.4, by version range2026-06-23
vulnerable: 2.19.0 ... 2.21.3 (13 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddr…
- CVE-2026-54515MEDIUMCVSS 5.3EG 5.3fixed in 3.1.4, 2.18.9, 2.21.5 or 2.22.1, by version range2026-06-23
vulnerable: 2.22.0
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties …
- CVE-2026-54516MEDIUMCVSS 5.3EG 5.3fixed in 2.21.4 or 3.1.4, by version range2026-06-23
vulnerable: 2.21.0, 2.21.1, 2.21.2, 2.21.3
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renam…
- CVE-2026-54517MEDIUMCVSS 5.3EG 5.3fixed in 2.21.4 or 3.1.4, by version range2026-06-23
vulnerable: 2.21.0, 2.21.1, 2.21.2, 2.21.3
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter …
- CVE-2026-54518MEDIUMCVSS 6.5EG 6.5fixed in 2.21.42026-06-23
vulnerable: 2.21.0, 2.21.1, 2.21.2, 2.21.3
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into…
- CVE-2026-59888MEDIUMCVSS 6.5EG 6.5fixed in 2.18.8 or 2.21.4, by version range2026-07-14
vulnerable: 2.19.0 ... 2.21.3 (13 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJ…
- CVE-2026-59889MEDIUMCVSS 6.5EG 6.5fixed in 2.21.5, 2.18.9 or 2.22.1, by version range2026-07-14
vulnerable: 2.22.0
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JS…
- CVE-2026-68497HIGHCVSS 7.5EG 7.5fixed in 2.18.10, 2.21.6 or 2.22.2, by version range2026-09-11
vulnerable: 2.22.0, 2.22.1
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDes…
- CVE-2026-77310MEDIUMCVSS 5.3EG 5.3fixed in 2.18.9, 2.21.5 or 2.22.1, by version range2026-08-24
vulnerable: 2.22.0
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress bran…
- CVE-2026-83557MEDIUMCVSS 5.6EG 5.6fixed in 2.18.10, 2.21.6 or 2.22.2, by version range2026-09-01
vulnerable: 2.22.0, 2.22.1
DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base …
- CVE-2026-91776HIGHCVSS 7.5EG 7.5fixed in 2.18.11, 2.21.7 or 2.22.3, by version range2026-09-23
vulnerable: 2.22.0, 2.22.1, 2.22.2
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = I…
- CVE-2026-91777HIGHCVSS 7.5EG 7.5fixed in 2.21.7, 2.18.11 or 2.22.3, by version range2026-09-23
vulnerable: 2.22.0, 2.22.1, 2.22.2
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferrin…
Check whether com.fasterxml.jackson.core:jackson-databind is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.fasterxml.jackson.core:jackson-databind CVEs against the assets you own.
Book a Demo →