Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson-dataformats-binaryAI | 1/10/2026 | 2/10/2026 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained… | |
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson Dataformats BinaryAI | 1/10/2026 | 2/10/2026 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and… | |
| Pendiente de análisis | Crítica (9.4) | 0.35% | — | Google Cloud BigqueryAIGoogle DataformAIGoogle Colab EnterpriseAI | 13/7/2026 | 13/7/2026 | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository… | |
| Aplazada | Crítica (10) | 0.68% | — | Google Cloud DataformAINPMAI | 25/8/2025 | 17/6/2026 | A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file. | |
| Modificada | Alta (7.5) | 0.91% | — | Fasterxml Jackson-dataformats-text | 8/8/2023 | 17/6/2026 | Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. | |
| Modificada | Alta (7.5) | 3.1% | — | Fasterxml Jackson-dataformats-binaryQuarkusOracle Weblogic Server | 18/2/2021 | 17/6/2026 | This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception. | |
| Modificada | Alta (8.6) | 2.4% | — | Fasterxml Jackson-dataformat-xml | 14/4/2017 | 17/6/2026 | XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. | |
| Modificada | Crítica (9.8) | 2.8% | — | Fedoraproject FedoraFasterxml Jackson-dataformat-xml | 10/6/2016 | 17/6/2026 | XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors. |