Vulnerabilidades em FasterXML

18 resultados
Análise Vexday

FasterXML apresenta 16 vulnerabilidades no histórico, com 10 publicadas nos últimos 90 dias, indicando padrão recente de descobertas; nenhuma está sob exploração ativa (KEV) e não há críticas CVSS, reduzindo a urgência imediata. A fraqueza dominante é CWE-184 (acesso incorreto a acesso controlado), sugerindo falhas de autenticação e autorização nos componentes da empresa.

CVE-2017-7525A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticaEPSS 37.7%CVE-2017-15095A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated userEPSS 8.4%CVE-2026-54512HIGHjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEPSS 0.8%CVE-2023-3894MEDIUMDOS in jackson-dataformats-textEPSS 0.7%CVE-2026-54513HIGHjackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)EPSS 0.7%CVE-2025-52999HIGHjackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested dataEPSS 0.6%CVE-2026-29062HIGHjackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource ExhaustionEPSS 0.6%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.5%CVE-2026-68494HIGHjackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq)EPSS 0.4%CVE-2026-59889MEDIUMjackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserializationEPSS 0.3%CVE-2026-54515MEDIUMjackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesEPSS 0.3%CVE-2025-49128MEDIUMJackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocationEPSS 0.3%CVE-2026-18401MEDIUMjackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of serviceEPSS 0.3%CVE-2026-54517MEDIUMjackson-databind: @JsonView bypass for setterless creator propertiesEPSS 0.3%CVE-2026-54516MEDIUMjackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fieldsEPSS 0.3%CVE-2026-54518MEDIUMjackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databindEPSS 0.3%CVE-2026-59888MEDIUMjackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyEPSS 0.2%CVE-2026-54514MEDIUMjackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)EPSS 0.2%