Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▼ 73 respecto a la semana anterior
Críticas / altas1416▲ 183 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.5)——Fasterxml Jackson-dataformats-binaryAI1/10/20261/10/2026
The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained…
RecibidaAlta (7.5)——Fasterxml Jackson Dataformats BinaryAI1/10/20261/10/2026
The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and…
ModificadaAlta (7.5)3.1%—Fasterxml Jackson-dataformats-binaryQuarkusOracle Weblogic Server18/2/202117/6/2026
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.