FasterXML jackson-core
4 known vulnerabilities in FasterXML jackson-core, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-89425 CVSS 7.5 high UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending…
- CVE-2026-89407 CVSS 7.5 high NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions…
- CVE-2026-68494 CVSS 8.7 high The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the…
- CVE-2026-18401 CVSS 6.9 medium The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in…