tools.jackson.core:jackson-core
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting tools.jackson.core:jackson-corepage 1 of 1
- CVE-2026-18401MEDIUMCVSS 6.9EG 6.9✓ Fixed in 3.1.02026-08-04
vulnerable: 3.0.0 ... 3.1.0-rc1 (6 versions)
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async …
- CVE-2026-29062HIGHCVSS 7.5EG 7.5✓ Fixed in 3.1.02026-03-06
vulnerable: 3.0.0 ... 3.1.0-rc1 (6 versions)
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a jav…
Check whether tools.jackson.core:jackson-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for tools.jackson.core:jackson-core CVEs against the assets you own.
Start Free Scan →