Known vulnerabilities in jackson-databind 2.9.7

Vendor: FasterXML
Version: 2.9.7
Software CPE: cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
Total vulnerabilities: 58
Public exploits: 13
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting jackson-databind version 2.9.7 jackson-databind 2.9.7 is affected by 58 vulnerabilities: 41 high, 15 medium, 2 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU151565 - Resource exhaustion
CVE-2026-91776
CWE-400 Medium
No
No
2.8.11, 2.21.7, 2.22.3, 3.1.7, 3.2.3 22.09.2026 SB2026092225
#VU144596 - Server-Side Request Forgery (SSRF)
CVE-2026-77310
CWE-918 Medium
No
No
2.18.9, 2.21.1, 2.21.5, 3.1.5, 3.2.1 24.08.2026 SB2026072278
SB2026090312
SB2026091103
#VU144593 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-19032
CWE-470 Medium
No
No
2.18.10, 2.21.6, 2.22.2, 3.1.6, 3.2.2 24.08.2026 SB2026082435
#VU139157 - Server-Side Request Forgery (SSRF)
CVE-2026-54514
CWE-918 Medium
No
No
2.18.8, 2.21.4, 3.1.4 22.07.2026 SB2026072278
SB2026072288
SB2026072340
and 12 more
#VU139156 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54515
CWE-915 Medium
No
No
2.18.9, 2.21.5, 2.22.1, 3.1.4 22.07.2026 SB2026072278
SB2026072282
SB2026072288
and 14 more
#VU49967 - Deserialization of Untrusted Data
CVE-2021-20190
CWE-502 High
No
No
2.9.10.7 19.01.2021 SB2021012514
SB2021042826
SB2021050708
and 17 more
#VU49368 - Deserialization of Untrusted Data
CVE-2020-36179
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 18 more
#VU49369 - Deserialization of Untrusted Data
CVE-2020-36180
CWE-502 High
Public exploit available
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49370 - Deserialization of Untrusted Data
CVE-2020-36182
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49371 - Deserialization of Untrusted Data
CVE-2020-36183
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 15 more
#VU49367 - Deserialization of Untrusted Data
CVE-2020-36188
CWE-502 High
Public exploit available
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49372 - Deserialization of Untrusted Data
CVE-2020-36181
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49373 - Deserialization of Untrusted Data
CVE-2020-36184
CWE-502 High
Public exploit available
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49374 - Deserialization of Untrusted Data
CVE-2020-36185
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49375 - Deserialization of Untrusted Data
CVE-2020-36186
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49376 - Deserialization of Untrusted Data
CVE-2020-36187
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49377 - Deserialization of Untrusted Data
CVE-2020-36189
CWE-502 High
No
No
2.9.10.8 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49378 - Deserialization of Untrusted Data
CVE-2020-35728
CWE-502 High
Public exploit available
No
2.9.10.8 27.12.2020 SB2021011105
SB2021042826
SB2021050708
and 15 more
#VU49379 - Deserialization of Untrusted Data
CVE-2020-35490
CWE-502 High
No
No
2.9.10.8 17.12.2020 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49380 - Deserialization of Untrusted Data
CVE-2020-35491
CWE-502 High
No
No
2.9.10.8 17.12.2020 SB2021011105
SB2021042826
SB2021050708
and 15 more


Showing elements 1 - 20 out of 58