在 的 (版本 1.13 及更早版本)中,发现了一个漏洞。该漏洞影响 文件中 和 函数所在的“Copy Move Operations”组件。该漏洞由不当的访问控制机制导致,且可被远程利用。目前该漏洞的利用方式已公开披露,且已被实际利用。该项目方已早先通过问题报告获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| java-json-tools | json-patch | 1.0 |
cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86511 | 5.3 MEDIUM | java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource cons |
| CVE-2026-86513 | 5.3 MEDIUM | java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensF |
No comments yet