在 java-json-tools 的 jackson-coreutils 2.0 中发现了一个漏洞。该问题影响的是组件“URL 验证”中文件 里的 函数。对函数的特定操纵会导致服务器端请求伪造(SSRF)。攻击者可远程发起该攻击。利用方式(exploit)已经公开,且可能被利用。项目方已较早通过问题报告得知该问题,但尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| java-json-tools | jackson-coreutils | 2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| java-json-tools | jackson-coreutils | 2.0 |
cpe:2.3:a:java-json-tools:jackson-coreutils:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86318 | 5.3 MEDIUM | java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-b |
| CVE-2026-86319 | 5.3 MEDIUM | java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consump |
No comments yet