Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jackson Databind MEDIUM 6.5
CVE-2026-54518

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.…

Fix: 2.21.4 / 3.1.4+
Fix from $1,600 2026-06-23
Jackson Databind HIGH 8.1
CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4,…

Fix: 2.18.8 / 2.21.4+
Fix from $1,950 2026-06-23
Jackson Databind HIGH 8.1
CVE-2026-54512

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4,…

Fix: 2.18.8 / 2.21.4+
Fix from $1,950 2026-06-23
Jackson Databind MEDIUM 5.3
CVE-2026-54514

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, …

Fix: 2.18.8 / 2.21.4+
Fix from $1,600 2026-06-23
Jackson Databind MEDIUM 5.3
CVE-2026-54515

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, …

Fix: 2.18.9 / 2.21.5+
Fix from $1,600 2026-06-23
Jackson Databind MEDIUM 5.3
CVE-2026-54516

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.…

Fix: 2.21.4 / 3.1.4+
Fix from $1,600 2026-06-23
Jackson Databind MEDIUM 5.3
CVE-2026-54517

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.…

Fix: 2.21.4 / 3.1.4+
Fix from $1,600 2026-06-23
Jackson Databind HIGH 7.5
CVE-2026-50193

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a poten…

Fix: 2.14.0+
Fix from $1,950 2026-06-23
Jackson Core HIGH 7.5
CVE-2026-29062

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 t…

Fix: 3.1.0+
Fix from $1,950 2026-03-06
Jackson Dataformats Text HIGH 7.5
CVE-2023-3894

Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppli…

Fix: 2.15.0+
Fix from $1,950 2023-08-08
Jackson Databind HIGH 7.5
CVE-2021-46877

jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usag…

Fix: 2.12.6+
Fix from $1,950 2023-03-18
Jackson Dataformats Binary HIGH 7.5
CVE-2020-28491

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchec…

Fix: 2.0.2 / 2.11.4+
Fix from $1,950 2021-02-18
Jackson Databind CRITICAL 9.8
CVE-2019-14893

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…

Fix: 2.8.11.5 / 2.9.10+
Fix from $2,300 2020-03-02
Jackson Dataformat Xml HIGH 8.6
CVE-2016-7051

XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct…

Fix: 2.7.8+
Fix from $1,950 2017-04-14