« Back to list

Fasterxml

Fasterxml Jackson-core: vulnerabilities and CVEs

Fasterxml Jackson-core has 6 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-89425High (7.5)0.49%—Sep 23, 2026
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound.…
CVE-2026-89407High (7.5)0.63%—Sep 22, 2026
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and…
CVE-2026-68494High (8.7)0.62%—Aug 4, 2026
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier…
CVE-2026-18401Medium (6.9)0.54%—Aug 4, 2026
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application…
CVE-2026-29062High (8.7)0.76%—Mar 6, 2026
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used…
CVE-2025-49128Medium (4)0.39%—Jun 6, 2025
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1499.004 Application or System Exploitation3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Fasterxml