{"api_version":"v1","generated_at":"2026-10-08T11:00:00+00:00","product":{"cve_count":17,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-fasterxml-jackson-databind-a87ad6a92391","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"jackson-databind","next_cursor":null,"observations":[{"affected":"jackson-databind: 2.5.0 \u2264 2.18.10, 2.19.0 \u2264 2.21.6, 2.22.0 \u2264 2.22.2, 3.0.0 \u2264 3.1.6, 3.2.0 \u2264 3.2.2","affected_versions_present":true,"cve_id":"CVE-2026-91777","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91777","fixed":"Upgrade to com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7 or 2.22.3, or to tools.jackson.core:jackson-databind 3.1.7 or 3.2.3. Lines 2.5.x through 2.17.x, 2.19.x, 2.20.x and 3.0.x received no fix on their own branch and are no longer maintained upstream.","last_modified":"2026-09-23T14:05:17.919Z","patch_url":"https://github.com/FasterXML/jackson-databind/issues/6204","primary_source":"","published":"2026-09-23T02:21:48.323Z"},{"affected":"jackson-databind: 2.0.0 \u2264 2.18.10, 2.19.0 \u2264 2.21.6, 2.22.0 \u2264 2.22.2, 3.0.0 \u2264 3.1.6, 3.2.0 \u2264 3.2.2","affected_versions_present":true,"cve_id":"CVE-2026-91776","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91776","fixed":"Upgrade to com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7 or 2.22.3, or to tools.jackson.core:jackson-databind 3.1.7 or 3.2.3. Lines 2.0.x through 2.17.x, 2.19.x, 2.20.x and 3.0.x received no fix on their own branch and are no longer maintained upstream.","last_modified":"2026-09-23T14:03:16.129Z","patch_url":"https://github.com/FasterXML/jackson-databind/issues/6203","primary_source":"","published":"2026-09-23T02:17:50.480Z"},{"affected":"jackson-databind: 2.0.0 < 2.18.10, 2.19.0 < 2.21.6, 2.22.0 < 2.22.2, 3.0.0 < 3.1.6, 3.2.0 < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2026-68497","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68497","fixed":"Upgrade to jackson-databind 2.18.10, 2.21.6, 2.22.2 (com.fasterxml.jackson.core) or 3.1.6, 3.2.2 (tools.jackson.core). The fix applies the same validate-length-then-parse idiom already used by NumberDeserializers, calling StreamReadConstraints length validation on the raw string before delegating to DatatypeFactory. The guard deliberately does not extend to javax.xml.namespace.QName, whose local parts may legitimately be long.","last_modified":"2026-09-11T16:32:46.146Z","patch_url":"https://github.com/FasterXML/jackson-databind/pull/6127","primary_source":"","published":"2026-09-11T15:49:30.366Z"},{"affected":"2.11.0 < 2.18.10; 2.19.0 < 2.21.6; 2.22.0 < 2.22.2; 3.0.0 < 3.1.6; 3.2.0 < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2026-83557","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-83557","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-01T17:46:40.145Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-83557","primary_source":"","published":"2026-09-01T14:57:01.340Z"},{"affected":"2.8.0 < 2.18.10; 2.19.0 < 2.21.6; 2.22.0 < 2.22.2; 3.0.0 < 3.1.6; 3.2.0 < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2026-19032","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-19032","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-01T13:13:09.928Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-19032","primary_source":"","published":"2026-09-01T03:18:42.280Z"},{"affected":">= 2.18.0, < 2.18.9; >= 2.21.0, < 2.21.5; >= 2.22.0, < 2.22.1; >= 3.0.0, < 3.1.5; >= 3.2.0, < 3.2.1","affected_versions_present":true,"cve_id":"CVE-2026-59889","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59889","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-07-16T14:50:17.517Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-59889","primary_source":"","published":"2026-07-14T19:57:48.473Z"},{"affected":">= 2.15.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-59888","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59888","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:68699","last_modified":"2026-07-14T17:52:03.675Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-59888","primary_source":"","published":"2026-07-14T16:44:20.091Z"},{"affected":">= 2.21.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54518","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54518","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-24T15:32:44.157Z","patch_url":"https://github.com/FasterXML/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341","primary_source":"","published":"2026-06-23T21:02:07.539Z"},{"affected":">= 2.10.0, < 2.14.0","affected_versions_present":true,"cve_id":"CVE-2026-50193","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50193","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-06-24T18:52:47.982Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-50193","primary_source":"","published":"2026-06-23T21:00:20.444Z"},{"affected":">= 2.10.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54512","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54512","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-06-24T15:22:43.268Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-54512","primary_source":"","published":"2026-06-23T20:56:36.646Z"},{"affected":"jackson-databind: >= 2.10.0, < 2.18.8, >= 2.19.0, < 2.21.4, >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54513","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54513","fixed":"RHSA-2026:48095: Red Hat Certificate System 10.8 for RHEL 8","last_modified":"2026-09-14T12:04:31.647Z","patch_url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","primary_source":"","published":"2026-06-23T20:53:52.543Z"},{"affected":">= 2.0.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54514","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54514","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-25T12:59:39.055Z","patch_url":"https://github.com/FasterXML/jackson-databind/pull/5951","primary_source":"","published":"2026-06-23T20:51:50.612Z"},{"affected":">= 2.8.0, < 2.18.9; >= 2.19.0, < 2.21.5; >= 3.1.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54515","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54515","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-06-24T12:22:56.445Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-54515","primary_source":"","published":"2026-06-23T20:50:25.715Z"},{"affected":">= 2.21.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54516","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54516","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-24T13:00:17.780Z","patch_url":"https://github.com/FasterXML/jackson-databind/pull/5967","primary_source":"","published":"2026-06-23T20:48:52.730Z"},{"affected":">= 2.21.0, < 2.21.4; >= 3.0.0, < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-54517","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54517","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-24T19:13:32.607Z","patch_url":"https://github.com/FasterXML/jackson-databind/pull/5969","primary_source":"","published":"2026-06-23T20:47:22.977Z"},{"affected":"before 2.6.7.1; before 2.7.9.1; before 2.8.9","affected_versions_present":true,"cve_id":"CVE-2017-7525","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-7525","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T02:21:29.302Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2018-02-06T15:00:00.000Z"},{"affected":"before 2.8.10; before 2.9.1","affected_versions_present":true,"cve_id":"CVE-2017-15095","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-15095","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T22:57:07.488Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2018-02-06T15:00:00.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"FasterXML"}}
