tools.jackson.core:jackson-core
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting tools.jackson.core:jackson-corepage 1 of 1
- CVE-2026-18401MEDIUMCVSS 6.9EG 6.9fixed in 3.1.02026-08-04
vulnerable: 3.0.0 ... 3.1.0-rc1 (6 versions)
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async …
- CVE-2026-29062HIGHCVSS 7.5EG 7.5fixed in 3.1.02026-03-06
vulnerable: 3.0.0 ... 3.1.0-rc1 (6 versions)
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a jav…
- CVE-2026-68494HIGHCVSS 8.7EG 8.7fixed in 3.1.42026-08-04
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validate…
- CVE-2026-89407HIGHCVSS 7.5EG 7.5fixed in 3.1.7 or 3.2.2, by version range2026-09-22
vulnerable: 3.2.0, 3.2.1
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, …
- CVE-2026-89425HIGHCVSS 7.5EG 7.5fixed in 3.1.7 or 3.2.3, by version range2026-09-23
vulnerable: 3.2.0, 3.2.1, 3.2.2
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three si…
Check whether tools.jackson.core:jackson-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for tools.jackson.core:jackson-core CVEs against the assets you own.
Book a Demo →