Known vulnerabilities in jackson-core
Vendor:
FasterXML
Software:
jackson-core
Software CPE:
cpe:2.3:a:fasterxml:jackson-core:*:*:*:*:*:*:*:*
Website:
https://github.com/FasterXML
Total vulnerabilities:
7
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
3.2.1
3.1.5
2.22.1
2.18.9
2.21.5
3.2.0
2.22.0
3.1.4
2.21.4
2.18.8
3.1.3
2.21.3
2.18.7
3.1.2
3.1.1
2.21.2
3.1.0
2.21.1
2.18.6
3.0.4
2.20.2
2.21.0
3.0.3
3.0.2
2.20.1
2.19.4
2.19.3
2.18.5
3.0.1
3.0.0
2.20.0
2.19.2
2.19.1
2.18.4.1
2.18.4
2.19.0
2.18.3
2.18.2
2.17.3
2.18.1
2.18.0
2.17.2
2.17.1
2.17.0
2.16.2
2.15.4
2.16.1
2.16.0
2.15.3
2.15.2
2.15.1
2.14.3
2.15.0
2.14.2
2.13.5
2.14.1
2.14.0
2.13.4
2.12.7
2.13.3
2.13.2
2.13.1
2.12.6
2.13.0
2.12.5
2.12.4
1.9
1.8
1.7
1.6
1.5
1.4.6
1.4.0
1.3
1.2.0
1.1.2
1.1.0
1.0.0
0.9.7
2.12.3
2.12.2
2.12.1
2.12.0
2.11.4
2.11.3
2.11.2
2.11.1
2.11.0
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.10
2.9.9
2.9.8
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.9.0
2.8.11
2.8.10
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.7.9
2.7.8
2.7.7
2.7.6
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1.1
2.4.1
2.4.0
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.4
2.2.3
2.2.2
2.2.1
2.1.5
2.1.4
2.1.3
2.1.2
2.0.6
2.0.5
2.0.4
2.0.2
2.0.1
2.0.0
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137339 - Allocation of Resources Without Limits or Throttling |
CWE-770 | Medium | 2.18.8, 2.21.4, 2.22.1, 3.1.4, 3.2.1 | 12.07.2026 |
SB2026071204 |
||
| #VU124821 - Improper input validation |
CWE-20 | Medium | 3.1.1 | 02.04.2026 |
SB2026040233 |
||
| #VU123491 - Memory corruption CVE-2026-29062 |
CWE-119 | Medium | 3.1.0 | 04.03.2026 |
SB2026030413 SB2026060232 SB2026060234 and 3 more |
||
| #VU123309 - Resource exhaustion CVE-2026-18401 |
CWE-400 | Medium | 2.18.6, 2.21.1 | 27.02.2026 |
SB2026022701 |
||
| #VU116606 - Information Exposure Through an Error Message CVE-2025-49128 |
CWE-209 | Low | 2.13.0 | 06.10.2025 |
SB2025100621 SB2025100622 SB20251022103 and 7 more |
||
| #VU112106 - Memory corruption CVE-2025-52999 |
CWE-119 | Medium | 2.15.0 | 02.07.2025 |
SB2025070257 SB2025070261 SB2025070262 and 43 more |
||
| #VU59148 - Deserialization of Untrusted Data CVE-2021-46877 |
CWE-502 | Medium | 2.12.6, 2.13.1 | 03.01.2022 |
SB2022010326 SB2022010327 SB2022062734 and 37 more |