Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: fasterxml Clear
ID Title
CVE-2026-54512 Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54512)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54512). Successful exploitation can lead to full system takeover. Exploitable via ``PolymorphicTypeValidator``. Mitigation: upgrade to `2.21.4` or later.
CVE-2026-50193 Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-50193)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-50193). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonNode``. Mitigation: upgrade to `2.14.0` or later.
CVE-2026-54518 Authorization Flaw in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54518)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54518). Risk of unauthorized operations or information disclosure. Exploitable via ``d633bc0``. Mitigation: upgrade to `2.21.4` or later.
CVE-2026-54513 Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54513)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54513). Successful exploitation can lead to full system takeover. Exploitable via ``EvilType``. Mitigation: upgrade to `3.1.4` or later.
CVE-2026-54514 SSRF (Server-Side Request Forgery) in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54514)
SSRF in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54514). Risk of unauthorized operations or information disclosure. Exploitable via ``JDKFromStringDeserializer``. Mitigation: upgrade to `3.1.4` or later.
CVE-2026-54515 Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54515)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54515). Risk of unauthorized operations or information disclosure. Exploitable via ``contextual``. Mitigation: upgrade to `2.18.9` or later.
CVE-2026-54516 Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54516)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54516). Risk of unauthorized operations or information disclosure. Exploitable via ``MapperFeature.INFER_PROPERTY_MUTATORS``. Mitigation: upgrade to `3.1.4` or later.
CVE-2026-54517 Authorization Flaw in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54517)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54517). Risk of unauthorized operations or information disclosure. Exploitable via ``true``. Mitigation: upgrade to `3.1.4` or later.
CVE-2026-29062 Vulnerability in dos (CVE-2026-29062)
vulnerability in dos (CVE-2026-29062). Risk of unauthorized operations or information disclosure.
CVE-2021-20190 Unsafe Deserialization in fasterxml (CVE-2021-20190)
vulnerability in fasterxml (CVE-2021-20190). Successful exploitation can lead to full system takeover.
CVE-2020-36183 Unsafe Deserialization in apache (CVE-2020-36183)
vulnerability in apache (CVE-2020-36183). Successful exploitation can lead to full system takeover.
CVE-2020-36182 Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
CVE-2020-36180 Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
CVE-2020-36179 Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
CVE-2020-36189 Unsafe Deserialization in fasterxml (CVE-2020-36189)
vulnerability in fasterxml (CVE-2020-36189). Successful exploitation can lead to full system takeover.
CVE-2020-36188 Unsafe Deserialization in fasterxml (CVE-2020-36188)
vulnerability in fasterxml (CVE-2020-36188). Successful exploitation can lead to full system takeover.
CVE-2020-36187 Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
CVE-2020-36186 Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
CVE-2020-36185 Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
CVE-2020-36184 Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
CVE-2020-36181 Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
CVE-2020-35728 Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
CVE-2020-35490 Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
CVE-2020-35491 Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
CVE-2020-25649 XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
CVE-2020-24750 Unsafe Deserialization in fasterxml (CVE-2020-24750)
vulnerability in fasterxml (CVE-2020-24750). Successful exploitation can lead to full system takeover.
CVE-2020-24616 Unsafe Deserialization in fasterxml (CVE-2020-24616)
vulnerability in fasterxml (CVE-2020-24616). Successful exploitation can lead to full system takeover.
CVE-2020-14195 Unsafe Deserialization in fasterxml (CVE-2020-14195)
vulnerability in fasterxml (CVE-2020-14195). Successful exploitation can lead to full system takeover.
CVE-2020-14060 Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
CVE-2020-14061 Unsafe Deserialization in fasterxml (CVE-2020-14061)
vulnerability in fasterxml (CVE-2020-14061). Successful exploitation can lead to full system takeover.
CVE-2020-14062 Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
CVE-2020-11619 Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-9548 Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
CVE-2020-9546 Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
CVE-2016-7051 XXE (XML External Entity) in ssrf (CVE-2016-7051)
vulnerability in ssrf (CVE-2016-7051). Data can be tampered with by attackers.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →