Fasterxml

    Dashboard / Vendors

    Products: 9
    Vulnerabilities: 94
    Known Exploited: 0
    27
    Critical Level Threats
    49
    High Level Threats
    17
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-68497

    jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service

    Last Modified: Sep 11, 2026
    Published: Sep 11, 2026

    CVE-2026-83557

    jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types

    Last Modified: Sep 01, 2026
    Published: Sep 01, 2026

    CVE-2026-19032

    jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path

    Last Modified: Sep 01, 2026
    Published: Sep 01, 2026

    CVE-2026-77310

    jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)

    Last Modified: Aug 25, 2026
    Published: Aug 24, 2026

    CVE-2026-68494

    jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq)

    Last Modified: Aug 05, 2026
    Published: Aug 04, 2026
    Items Per Page
    Fasterxml Vulnerabilities & Security CVEs | CVE-DB