在 java-json-tools 的 jackson-coreutils 2.0 中发现了漏洞。该漏洞影响的是位于 文件中 函数。执行特定操作会导致资源过度消耗(即资源消耗型 DoS 攻击)。此漏洞可被远程触发。该漏洞的利用方式已被公开,可能被用于实际攻击。项目组已通过 issue 报告提前获知该问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| java-json-tools | jackson-coreutils | 2.0 |
cpe:2.3:a:java-json-tools:jackson-coreutils:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86512 | 6.3 MEDIUM | java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply acc |
| CVE-2026-86513 | 5.3 MEDIUM | java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensF |
No comments yet