Known Vulnerabilities for Jackson by Fasterxml
Listed below are 10 of the newest known vulnerabilities associated with "Jackson" by "Fasterxml".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91777 json | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pen... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-91776 json | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attack... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-89425 json | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-89407 json | NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-86513 json | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePoi... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-86511 json | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-86321 json | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-83557 json | DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-77310 json | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to ... | Not Provided | 2026-08-24 | 2026-08-25 |
| CVE-2026-68497 json | jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by pas... | Not Provided | 2026-09-11 | 2026-09-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fasterxml | Jackson | 3.0.0 | |||
| Application | Fasterxml | Jackson | 2.9.9 | |||
| Application | Fasterxml | Jackson | 2.9.8 | |||
| Application | Fasterxml | Jackson | 2.9.7 | |||
| Application | Fasterxml | Jackson | 2.9.6 | |||
| Application | Fasterxml | Jackson | 2.9.5 | |||
| Application | Fasterxml | Jackson | 2.9.4 | |||
| Application | Fasterxml | Jackson | 2.9.3 | |||
| Application | Fasterxml | Jackson | 2.9.2 | |||
| Application | Fasterxml | Jackson | 2.9.1 | |||
| Application | Fasterxml | Jackson | 2.9.0 | |||
| Application | Fasterxml | Jackson | 2.8.9 | |||
| Application | Fasterxml | Jackson | 2.8.8 | |||
| Application | Fasterxml | Jackson | 2.8.7 | |||
| Application | Fasterxml | Jackson | 2.8.6 | |||
| Application | Fasterxml | Jackson | 2.8.5 | |||
| Application | Fasterxml | Jackson | 2.8.4 | |||
| Application | Fasterxml | Jackson | 2.8.3 | |||
| Application | Fasterxml | Jackson | 2.8.2 | |||
| Application | Fasterxml | Jackson | 2.8.11 |