Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FasterXML — Vulnerabilities & Security Advisories 28

Browse all 28 CVE security advisories affecting FasterXML. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FasterXML develops the Jackson JSON processing library, widely used for data binding and parsing in Java applications. Historically, vulnerabilities have primarily centered on remote code execution (RCE) and cross-site scripting (XSS) due to insecure deserialization and input validation flaws. The library's extensive adoption makes it a high-value target. Notable security characteristics include its modular architecture, though complex configurations can introduce risks. While no major public incidents have been widely documented, the 6 CVEs on record highlight persistent concerns around memory corruption and improper handling of untrusted input, necessitating careful implementation and regular updates.

CVE ID Title CVSS Severity Published
CVE-2026-68496 jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service — jackson-dataformats-binary CWE-770 7.5 High 2026-10-01
CVE-2026-68495 jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service — jackson-dataformats-binary CWE-770 7.5 High 2026-10-01
CVE-2026-91777 jackson-databind: quadratic forward-reference completion in Collection and Map deserializers — jackson-databind CWE-400 7.5 High 2026-09-23
CVE-2026-91776 jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID — jackson-databind CWE-400 7.5 High 2026-09-23
CVE-2026-89425 jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth — jackson-core CWE-770 7.5 High 2026-09-23
CVE-2026-89407 jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoS — jackson-core CWE-1333 7.5 High 2026-09-22
CVE-2026-68497 jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service — jackson-databind CWE-400 7.5 High 2026-09-11
CVE-2026-83557 jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types — jackson-databind CWE-502 5.6 Medium 2026-09-01
CVE-2026-19032 jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path — jackson-databind CWE-470 5.3 Medium 2026-09-01
CVE-2026-77310 jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514) — com.fasterxml.jackson.core:jackson-databind CWE-918 5.3 Medium 2026-08-24
CVE-2026-68494 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq) — jackson-core CWE-770 8.7 High 2026-08-04
CVE-2026-18401 jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service — jackson-core CWE-770 6.9 Medium 2026-08-04
CVE-2026-59889 jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization — jackson-databind CWE-863 6.5 Medium 2026-07-14
CVE-2026-59888 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy — jackson-databind CWE-915 6.5 Medium 2026-07-14
CVE-2026-54518 jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind — jackson-databind CWE-863 6.5 Medium 2026-06-23
CVE-2026-50193 jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString() — jackson-databind CWE-400 - - 2026-06-23
CVE-2026-54512 jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation — jackson-databind CWE-184 8.1 High 2026-06-23
CVE-2026-54513 jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) — jackson-databind CWE-184 8.1 High 2026-06-23
CVE-2026-54514 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) — jackson-databind CWE-918 5.3 Medium 2026-06-23
CVE-2026-54515 jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties — jackson-databind CWE-915 5.3 Medium 2026-06-23
CVE-2026-54516 jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields — jackson-databind CWE-915 5.3 Medium 2026-06-23
CVE-2026-54517 jackson-databind: @JsonView bypass for setterless creator properties — jackson-databind CWE-863 5.3 Medium 2026-06-23
CVE-2026-29062 jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion — jackson-core CWE-770 7.5 - 2026-03-06
CVE-2025-52999 jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data — jackson-core CWE-121 6.5 - 2025-06-25
CVE-2025-49128 Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation — jackson-core CWE-209 4.0 Medium 2025-06-06
CVE-2023-3894 DOS in jackson-dataformats-text — jackson-dataformats-text CWE-20 5.8 Medium 2023-08-08
CVE-2017-15095 FasterXML Jackson-databind 代码问题漏洞 — jackson-databind CWE-184 9.8 - 2018-02-06
CVE-2017-7525 FasterXML Jackson 代码问题漏洞 — jackson-databind CWE-184 9.8 - 2018-02-06

This page lists every published CVE security advisory associated with FasterXML. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.