Количество 13
Количество 13
GHSA-h46c-h94j-95f3
jackson-core can throw a StackoverflowError when processing deeply nested data
CVE-2025-52999
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.
CVE-2025-52999
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.
CVE-2025-52999
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.
CVE-2025-52999
jackson-core contains core low-level incremental ("streaming") parser ...
ELSA-2025-14126
ELSA-2025-14126: pki-deps:10.6 security update (IMPORTANT)
ELSA-2025-12280
ELSA-2025-12280: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (IMPORTANT)
BDU:2025-11087
Уязвимость библиотеки jackson-core проекта FasterXML, позволяющая нарушителю оказать воздействие на доступность защищаемой информации
ROS-20251006-16
Множественные уязвимости jackson-databind
ROS-20251006-15
Множественные уязвимости jackson-core
ROS-20251006-14
Множественные уязвимости jackson-annotations
ROS-20251006-13
Множественные уязвимости jackson-bom
ROS-20251006-12
Множественные уязвимости jackson-parent
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested data | 0% Низкий | 5 месяцев назад | ||
CVE-2025-52999 jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. | 0% Низкий | 5 месяцев назад | ||
CVE-2025-52999 jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2025-52999 jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. | 0% Низкий | 5 месяцев назад | ||
CVE-2025-52999 jackson-core contains core low-level incremental ("streaming") parser ... | 0% Низкий | 5 месяцев назад | ||
ELSA-2025-14126 ELSA-2025-14126: pki-deps:10.6 security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2025-12280 ELSA-2025-12280: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (IMPORTANT) | 3 месяца назад | |||
BDU:2025-11087 Уязвимость библиотеки jackson-core проекта FasterXML, позволяющая нарушителю оказать воздействие на доступность защищаемой информации | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
ROS-20251006-16 Множественные уязвимости jackson-databind | CVSS3: 5.3 | около 1 месяца назад | ||
ROS-20251006-15 Множественные уязвимости jackson-core | CVSS3: 5.3 | около 1 месяца назад | ||
ROS-20251006-14 Множественные уязвимости jackson-annotations | CVSS3: 5.3 | около 1 месяца назад | ||
ROS-20251006-13 Множественные уязвимости jackson-bom | CVSS3: 5.3 | около 1 месяца назад | ||
ROS-20251006-12 Множественные уязвимости jackson-parent | CVSS3: 5.3 | около 1 месяца назад |
Уязвимостей на страницу