Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

jackson-databind — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in jackson-databind, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common weakness enumerations associated with the vendor Fasterxml and the open-source library jackson-databind, focusing on vulnerability classifications. It collects a wide array of security flaws, including deserialization issues, injection flaws, and information disclosure vulnerabilities, covering entries reported from the initial public disclosure of the library up to the present day. By navigating this resource, users can systematically track vendor advisories to understand how Fasterxml has addressed specific security incidents over time. Furthermore, the page allows security professionals and developers to analyze trends within specific weakness classes, such as CWE-502, to grasp the broader implications of these defect types on application security. Users can also look up the detailed vulnerability history of jackson-databind, reviewing the chronology of reported issues to assess the stability and security posture of the software across different versions. This structured overview facilitates a deeper understanding of the attack surfaces inherent in JSON processing libraries, enabling more informed decisions regarding dependency management and risk mitigation. The data is curated to highlight patterns in defect introduction and remediation, offering insights into the lifecycle of security flaws in widely used Java utilities. This approach helps teams prioritize patches and updates by providing context on the severity and prevalence of each identified issue.

Vendor: FasterXML

CVE IDTitleCVSSSeverityPublished
CVE-2026-59889 jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization CWE-863 6.5 Medium2026-07-14
CVE-2026-59888 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy CWE-915 6.5 Medium2026-07-14
CVE-2026-54518 jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind CWE-863 6.5 Medium2026-06-23
CVE-2026-50193 jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString() CWE-400--2026-06-23
CVE-2026-54512 jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation CWE-184 8.1 High2026-06-23
CVE-2026-54513 jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) CWE-184 8.1 High2026-06-23
CVE-2026-54514 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) CWE-918 5.3 Medium2026-06-23
CVE-2026-54515 jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties CWE-915 5.3 Medium2026-06-23
CVE-2026-54516 jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields CWE-915 5.3 Medium2026-06-23
CVE-2026-54517 jackson-databind: @JsonView bypass for setterless creator properties CWE-863 5.3 Medium2026-06-23
CVE-2021-20190 FasterXML jackson-databind 代码问题漏洞 CWE-502 8.1 -2021-01-19
CVE-2020-25649 Fasterxml Jackson 代码问题漏洞 CWE-611 7.5 -2020-12-03
CVE-2019-14893 FasterXML jackson-databind 代码问题漏洞 CWE-502 8.1 -2020-03-02
CVE-2019-14892 FasterXML jackson-databind 代码问题漏洞 CWE-502 9.8 -2020-03-02
CVE-2017-15095 FasterXML Jackson-databind 代码问题漏洞 CWE-184 9.8 -2018-02-06
CVE-2017-7525 FasterXML Jackson 代码问题漏洞 CWE-184 9.8 -2018-02-06

All 16 known CVE vulnerabilities affecting jackson-databind with full Chinese analysis, references, and POCs where available.