tools.jackson.core:jackson-databind
Maven15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting tools.jackson.core:jackson-databindpage 1 of 1
- CVE-2026-19032MEDIUMCVSS 5.3EG 5.3fixed in 3.1.6 or 3.2.2, by version range2026-09-01
vulnerable: 3.2.0, 3.2.1
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(va…
- CVE-2026-54512HIGHCVSS 8.1EG 8.1fixed in 3.1.42026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechan…
- CVE-2026-54513HIGHCVSS 8.1EG 8.1fixed in 3.1.42026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any a…
- CVE-2026-54514MEDIUMCVSS 5.3EG 5.3fixed in 2.21.4 or 3.1.4, by version range2026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddr…
- CVE-2026-54515MEDIUMCVSS 5.3EG 5.3fixed in 3.1.42026-06-23
vulnerable: 3.1.0, 3.1.1, 3.1.2, 3.1.3
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties …
- CVE-2026-54516MEDIUMCVSS 5.3EG 5.3fixed in 3.1.42026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renam…
- CVE-2026-54517MEDIUMCVSS 5.3EG 5.3fixed in 3.1.42026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter …
- CVE-2026-54518MEDIUMCVSS 6.5EG 6.5fixed in 3.1.42026-06-23
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into…
- CVE-2026-59888MEDIUMCVSS 6.5EG 6.5fixed in 3.1.42026-07-14
vulnerable: 3.0.0 ... 3.1.3 (10 versions)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJ…
- CVE-2026-59889MEDIUMCVSS 6.5EG 6.5fixed in 3.1.5 or 3.2.1, by version range2026-07-14
vulnerable: 3.2.0
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JS…
- CVE-2026-68497HIGHCVSS 7.5EG 7.5fixed in 3.2.2 or 3.1.6, by version range2026-09-11
vulnerable: 3.0.0 ... 3.1.5 (12 versions)
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDes…
- CVE-2026-77310MEDIUMCVSS 5.3EG 5.3fixed in 3.1.5 or 3.2.1, by version range2026-08-24
vulnerable: 3.2.0
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress bran…
- CVE-2026-83557MEDIUMCVSS 5.6EG 5.6fixed in 3.1.6 or 3.2.2, by version range2026-09-01
vulnerable: 3.2.0, 3.2.1
DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base …
- CVE-2026-91776HIGHCVSS 7.5EG 7.5fixed in 3.1.7 or 3.2.3, by version range2026-09-23
vulnerable: 3.2.0, 3.2.1, 3.2.2
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = I…
- CVE-2026-91777HIGHCVSS 7.5EG 7.5fixed in 3.1.7 or 3.2.3, by version range2026-09-23
vulnerable: 3.2.0, 3.2.1, 3.2.2
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferrin…
Check whether tools.jackson.core:jackson-databind is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for tools.jackson.core:jackson-databind CVEs against the assets you own.
Book a Demo →