Fasterxml Jackson-Databind vulnerabilities
82 known vulnerabilities affecting fasterxml/jackson-databind.
Total CVEs
82
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL26HIGH44MEDIUM12
Vulnerabilities
Page 5 of 5
CVE-2026-54515P4MEDIUMCVSS 5.3≥ 2.8.0, < 2.18.9≥ 2.19.0, < 2.21.5+5 more2026-06-23
CVE-2026-54515 [MEDIUM] CWE-915 CVE-2026-54515: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has
nvd
CVE-2023-35116P4MEDIUMCVSS 4.7fixed in 2.16.02023-06-14
CVE-2023-35116 [MEDIUM] CWE-770 CVE-2023-35116: jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified i
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an ex
nvd
← Previous5 / 5