CVE-2026-86513
Dashboard / Vulnerabilities / CVE-2026-86513
CVE-2026-86513
Summary: java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources
Details: A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References: https://github.com/java-json-tools/jackson-coreutils/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86513.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86513, https://vuldb.com/cve/CVE-2026-86513, https://vuldb.com/submit/908445, https://vuldb.com/vuln/399667, https://github.com/java-json-tools/jackson-coreutils/issues/66, https://vuldb.com/vuln/399667/cti
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
