Where
-Infinity
0

fasterxml jackson-databindjackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson …

Risk 33
Severity
7
First published (updated )

fasterxml jackson-databindjackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson …

Risk 33
Severity
7
First published (updated )

fasterxml jackson-databindjackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind

Risk 40
Severity
6.5
First published (updated )

maven/com.fasterxml.jackson.core/jackson-databindjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()

Risk 43
Severity
6.3
First published (updated )

maven/com.fasterxml.jackson.core:jackson-databindjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation

Risk 75
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/com.fasterxml.jackson.core:jackson-databindjackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

Risk 75
Severity
8.1
First published (updated )

maven/com.fasterxml.jackson.core:jackson-databindjackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

Risk 27
Severity
5.3
First published (updated )

fasterxml jackson-databindjackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties

Risk 27
Severity
5.3
First published (updated )

maven/com.fasterxml.jackson.core:jackson-databindjackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields

Risk 27
Severity
5.3
First published (updated )

maven/com.fasterxml.jackson.core:jackson-databindjackson-databind: @JsonView bypass for setterless creator properties

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fasterxml jackson-corejackson-core contains core low-level incremental ("streaming") parser and generator abstractions use…

Risk 33
Severity
7
First published (updated )

fasterxml jackson-corejackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )

fasterxml jackson-databindAn issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service o…

Risk 29
Severity
4.7
First published (updated )

fasterxml jackson-databindA flaw was found in Jackson Databind. This issue may allow a malicious user to cause a denial of ser…

Risk 45
Severity
7.5
First published (updated )

redhat/candlepinIn FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur …

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/eap7-jackson-databindIn FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a ch…

Risk 46
Severity
7.5
First published (updated )

fasterxml jackson-databindThe com.fasterxml.jackson.core:jackson-databind library before version 2.9.10.4 is vulnerable to an …

Risk 79
Severity
8.1
First published (updated )

maven/com.fasterxml.jackson.core:jackson-databindSSRF

Risk 63
Severity
8.3
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 80
Severity
8.8
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 80
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 77
Severity
8.1
First published (updated )

Oracle Primavera GatewayFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 80
Severity
8.8
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 80
Severity
8.8
First published (updated )

Oracle Banking PlatformFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 78
Severity
8.1
First published (updated )

Oracle Primavera GatewayA flaw was found in jackson-databind. FasterXML mishandles the interaction between serialization gad…

Risk 78
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 78
Severity
8.1
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 77
Severity
8.1
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 77
Severity
8.1
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 80
Severity
8.8
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

Risk 77
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203