{"schema_version":1,"title":"FasterXML Jackson-Databind vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in FasterXML Jackson-Databind: 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68497, was published on 11 September 2026.","url":"https://junglewise.ai/threats/technologies/jackson-databind","json_url":"https://junglewise.ai/threats/technologies/jackson-databind.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/jackson-databind","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":7,"last_365_days":15},"latest":[{"cve":"CVE-2026-68497","cvss":7.5,"epss":0.0058,"slug":"cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype","title":"FasterXML jackson-databind quadratic parse in XML datatype deserialization","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:39.61+00:00","url":"https://junglewise.ai/threats/cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype"},{"cve":"CVE-2026-83557","cvss":5.6,"epss":0.0071,"slug":"cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type","title":"FasterXML Jackson Databind unsafe polymorphic type deserialization","severity":"medium","exploited":false,"published_at":"2026-09-01T15:17:37.987+00:00","url":"https://junglewise.ai/threats/cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type"},{"cve":"CVE-2026-19032","cvss":5.3,"epss":0.0053,"slug":"cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme","title":"FasterXML jackson-databind Path deserialization URI scheme injection","severity":"medium","exploited":false,"published_at":"2026-09-01T04:18:00.433+00:00","url":"https://junglewise.ai/threats/cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme"},{"cve":"CVE-2026-77310","cvss":5.3,"epss":0.0031,"slug":"cve-2026-77310-fasterxml-jackson-databind-dns-resolution-ssrf-in-inetaddress","title":"FasterXML jackson-databind DNS resolution SSRF in InetAddress deserialization","severity":"medium","exploited":false,"published_at":"2026-08-24T20:17:20.977+00:00","url":"https://junglewise.ai/threats/cve-2026-77310-fasterxml-jackson-databind-dns-resolution-ssrf-in-inetaddress"},{"cvss":6.5,"slug":"fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85","title":"FasterXML jackson-databind JsonView bypass in creator properties","severity":"medium","exploited":false,"published_at":"2026-07-21T19:40:12+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85"},{"cve":"CVE-2026-59889","cvss":6.5,"epss":0.0039,"slug":"cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped","title":"FasterXML jackson-databind authorization bypass in @JsonUnwrapped properties","severity":"medium","exploited":false,"published_at":"2026-07-14T21:17:06.16+00:00","url":"https://junglewise.ai/threats/cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped"},{"cve":"CVE-2026-59888","cvss":6.5,"epss":0.0042,"slug":"cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records","title":"FasterXML jackson-databind @JsonIgnore bypass in Java Records","severity":"medium","exploited":false,"published_at":"2026-07-14T17:17:15.137+00:00","url":"https://junglewise.ai/threats/cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records"},{"cve":"CVE-2026-54518","cvss":6.5,"epss":0.0035,"slug":"cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in","title":"FasterXML jackson-databind authorization bypass in UnwrappedPropertyHandler","severity":"medium","exploited":false,"published_at":"2026-06-23T22:16:32.073+00:00","url":"https://junglewise.ai/threats/cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in"},{"cve":"CVE-2026-54517","cvss":5.3,"epss":0.0038,"slug":"cve-2026-54517-fasterxml-jackson-databind-jsonview-bypass-in-beandeserializer","title":"FasterXML jackson-databind @JsonView bypass in BeanDeserializer","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.853+00:00","url":"https://junglewise.ai/threats/cve-2026-54517-fasterxml-jackson-databind-jsonview-bypass-in-beandeserializer"},{"cve":"CVE-2026-54516","cvss":5.3,"epss":0.0045,"slug":"cve-2026-54516-fasterxml-jackson-databind-jsonignore-bypass-via-renamed","title":"FasterXML jackson-databind @JsonIgnore bypass via renamed properties","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.723+00:00","url":"https://junglewise.ai/threats/cve-2026-54516-fasterxml-jackson-databind-jsonignore-bypass-via-renamed"},{"cve":"CVE-2026-54515","cvss":5.3,"epss":0.0044,"slug":"cve-2026-54515-fasterxml-jackson-databind-property-exclusion-bypass-in","title":"FasterXML jackson-databind property exclusion bypass in BeanDeserializerBase","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.597+00:00","url":"https://junglewise.ai/threats/cve-2026-54515-fasterxml-jackson-databind-property-exclusion-bypass-in"},{"cve":"CVE-2026-54514","cvss":5.3,"epss":0.0037,"slug":"cve-2026-54514-fasterxml-jackson-databind-ssrf-via-eager-dns-resolution-in","title":"FasterXML jackson-databind SSRF via eager DNS resolution in InetSocketAddress","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.467+00:00","url":"https://junglewise.ai/threats/cve-2026-54514-fasterxml-jackson-databind-ssrf-via-eager-dns-resolution-in"},{"cve":"CVE-2026-54513","cvss":8.1,"epss":0.0123,"slug":"cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in","title":"FasterXML jackson-databind validation bypass in BasicPolymorphicTypeValidator","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.333+00:00","url":"https://junglewise.ai/threats/cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in"},{"cve":"CVE-2026-54512","cvss":8.1,"epss":0.01,"slug":"cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via","title":"FasterXML jackson-databind PolymorphicTypeValidator bypass via generic types","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via"},{"cve":"CVE-2026-50193","cvss":3.1,"epss":0.0062,"slug":"cve-2026-50193-fasterxml-jackson-databind-denial-of-service-via-deeply-nested","title":"FasterXML jackson-databind denial of service via deeply nested JSON","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:01.117+00:00","url":"https://junglewise.ai/threats/cve-2026-50193-fasterxml-jackson-databind-denial-of-service-via-deeply-nested"},{"cve":"CVE-2022-42004","cvss":7.5,"epss":0.0278,"slug":"cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in","title":"FasterXML jackson-databind resource exhaustion in BeanDeserializer","severity":"high","exploited":false,"published_at":"2022-10-03T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"FasterXML Jackson-Core","slug":"jackson-core","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/jackson-core"}],"technology":{"hub":true,"name":"FasterXML Jackson-Databind","slug":"jackson-databind","vendor":{"name":"FasterXML","slug":"fasterxml","url":"https://junglewise.ai/threats/vendors/fasterxml"},"aliases":[],"category":"library","homepage":"https://github.com/FasterXML/jackson-databind","repo_url":"https://github.com/FasterXML/jackson-databind","description":"A data-binding package for Jackson that allows for converting between JSON and Java objects.","url":"https://junglewise.ai/threats/technologies/jackson-databind"},"most_severe":[{"cve":"CVE-2026-54513","cvss":8.1,"epss":0.0123,"slug":"cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in","title":"FasterXML jackson-databind validation bypass in BasicPolymorphicTypeValidator","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.333+00:00","url":"https://junglewise.ai/threats/cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in"},{"cve":"CVE-2026-54512","cvss":8.1,"epss":0.01,"slug":"cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via","title":"FasterXML jackson-databind PolymorphicTypeValidator bypass via generic types","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via"},{"cve":"CVE-2022-42004","cvss":7.5,"epss":0.0278,"slug":"cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in","title":"FasterXML jackson-databind resource exhaustion in BeanDeserializer","severity":"high","exploited":false,"published_at":"2022-10-03T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in"},{"cve":"CVE-2026-68497","cvss":7.5,"epss":0.0058,"slug":"cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype","title":"FasterXML jackson-databind quadratic parse in XML datatype deserialization","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:39.61+00:00","url":"https://junglewise.ai/threats/cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype"},{"cve":"CVE-2026-59888","cvss":6.5,"epss":0.0042,"slug":"cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records","title":"FasterXML jackson-databind @JsonIgnore bypass in Java Records","severity":"medium","exploited":false,"published_at":"2026-07-14T17:17:15.137+00:00","url":"https://junglewise.ai/threats/cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records"},{"cve":"CVE-2026-59889","cvss":6.5,"epss":0.0039,"slug":"cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped","title":"FasterXML jackson-databind authorization bypass in @JsonUnwrapped properties","severity":"medium","exploited":false,"published_at":"2026-07-14T21:17:06.16+00:00","url":"https://junglewise.ai/threats/cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped"},{"cve":"CVE-2026-54518","cvss":6.5,"epss":0.0035,"slug":"cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in","title":"FasterXML jackson-databind authorization bypass in UnwrappedPropertyHandler","severity":"medium","exploited":false,"published_at":"2026-06-23T22:16:32.073+00:00","url":"https://junglewise.ai/threats/cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in"},{"cvss":6.5,"slug":"fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85","title":"FasterXML jackson-databind JsonView bypass in creator properties","severity":"medium","exploited":false,"published_at":"2026-07-21T19:40:12+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85"},{"cve":"CVE-2026-83557","cvss":5.6,"epss":0.0071,"slug":"cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type","title":"FasterXML Jackson Databind unsafe polymorphic type deserialization","severity":"medium","exploited":false,"published_at":"2026-09-01T15:17:37.987+00:00","url":"https://junglewise.ai/threats/cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type"},{"cve":"CVE-2026-19032","cvss":5.3,"epss":0.0053,"slug":"cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme","title":"FasterXML jackson-databind Path deserialization URI scheme injection","severity":"medium","exploited":false,"published_at":"2026-09-01T04:18:00.433+00:00","url":"https://junglewise.ai/threats/cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme"}],"generated_at":"2026-09-26T14:07:00.158513+00:00"}