fasterxml
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting fasterxml.
- CVE-2026-59889jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization6.5
- CVE-2026-59888jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy6.5
- CVE-2026-54518jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind6.5
- CVE-2026-50193jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()7.5
- CVE-2026-54512jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation8.1
- CVE-2026-54513jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)8.1
- CVE-2026-54514jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)5.3
- CVE-2026-54515jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties5.3
- CVE-2026-54516jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields5.3
- CVE-2026-54517jackson-databind: @JsonView bypass for setterless creator properties5.3
- CVE-2026-29062jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion7.5
- CVE-2025-52999jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data5.3
- CVE-2025-49128Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation4.0
- CVE-2023-3894DOS in jackson-dataformats-text5.8
- CVE-2023-35116jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that ...4.7