{"schema_version":1,"title":"FasterXML vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in FasterXML: 2 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-89425, was published on 23 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/fasterxml","json_url":"https://junglewise.ai/threats/vendors/fasterxml.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/fasterxml","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":8,"all_time":23,"critical":0,"exploited":0,"last_7_days":2,"last_30_days":5,"last_90_days":12,"last_365_days":22},"latest":[{"cve":"CVE-2026-89425","cvss":7.5,"epss":0.0049,"slug":"cve-2026-89425-utf8datainputjsonparser-reportinvalidtoken-in-fasterxml-jackson","title":"FasterXML jackson-core denial of service in UTF8DataInputJsonParser","severity":"high","exploited":false,"published_at":"2026-09-23T03:17:04.357+00:00","url":"https://junglewise.ai/threats/cve-2026-89425-utf8datainputjsonparser-reportinvalidtoken-in-fasterxml-jackson"},{"cve":"CVE-2026-89407","cvss":7.5,"epss":0.0063,"slug":"cve-2026-89407-numberinput-lookslikevalidnumber-in-fasterxml-jackson-core-pre","title":"FasterXML jackson-core regular expression denial of service in NumberInput","severity":"high","exploited":false,"published_at":"2026-09-22T15:17:21.053+00:00","url":"https://junglewise.ai/threats/cve-2026-89407-numberinput-lookslikevalidnumber-in-fasterxml-jackson-core-pre"},{"cve":"CVE-2026-68497","cvss":7.5,"epss":0.0058,"slug":"cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype","title":"FasterXML jackson-databind quadratic parse in XML datatype deserialization","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:39.61+00:00","url":"https://junglewise.ai/threats/cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype"},{"cve":"CVE-2026-83557","cvss":5.6,"epss":0.0071,"slug":"cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type","title":"FasterXML Jackson Databind unsafe polymorphic type deserialization","severity":"medium","exploited":false,"published_at":"2026-09-01T15:17:37.987+00:00","url":"https://junglewise.ai/threats/cve-2026-83557-fasterxml-jackson-databind-unsafe-polymorphic-type"},{"cve":"CVE-2026-19032","cvss":5.3,"epss":0.0053,"slug":"cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme","title":"FasterXML jackson-databind Path deserialization URI scheme injection","severity":"medium","exploited":false,"published_at":"2026-09-01T04:18:00.433+00:00","url":"https://junglewise.ai/threats/cve-2026-19032-fasterxml-jackson-databind-path-deserialization-uri-scheme"},{"cve":"CVE-2026-77310","cvss":5.3,"epss":0.0031,"slug":"cve-2026-77310-fasterxml-jackson-databind-dns-resolution-ssrf-in-inetaddress","title":"FasterXML jackson-databind DNS resolution SSRF in InetAddress deserialization","severity":"medium","exploited":false,"published_at":"2026-08-24T20:17:20.977+00:00","url":"https://junglewise.ai/threats/cve-2026-77310-fasterxml-jackson-databind-dns-resolution-ssrf-in-inetaddress"},{"cvss":8.7,"slug":"fasterxml-jackson-core-number-length-constraint-bypass-in-async-parser-78aa3f75","title":"FasterXML jackson-core number length constraint bypass in async parser","severity":"medium","exploited":false,"published_at":"2026-08-04T15:32:23+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-number-length-constraint-bypass-in-async-parser-78aa3f75"},{"cve":"CVE-2026-68494","cvss":7.5,"epss":0.0062,"slug":"cve-2026-68494-fasterxml-jackson-core-incomplete-number-length-validation-bypass","title":"FasterXML jackson-core incomplete number length validation bypass","severity":"info","exploited":false,"published_at":"2026-08-04T15:16:41.443+00:00","url":"https://junglewise.ai/threats/cve-2026-68494-fasterxml-jackson-core-incomplete-number-length-validation-bypass"},{"cvss":8.7,"slug":"fasterxml-jackson-core-memory-exhaustion-in-async-parser-via-chunked-aac0fe2a","title":"FasterXML jackson-core memory exhaustion in async parser via chunked digits","severity":"high","exploited":false,"published_at":"2026-07-21T21:58:53+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-memory-exhaustion-in-async-parser-via-chunked-aac0fe2a"},{"cvss":6.5,"slug":"fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85","title":"FasterXML jackson-databind JsonView bypass in creator properties","severity":"medium","exploited":false,"published_at":"2026-07-21T19:40:12+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-databind-jsonview-bypass-in-creator-properties-c3386b85"},{"cve":"CVE-2026-59889","cvss":6.5,"epss":0.0039,"slug":"cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped","title":"FasterXML jackson-databind authorization bypass in @JsonUnwrapped properties","severity":"medium","exploited":false,"published_at":"2026-07-14T21:17:06.16+00:00","url":"https://junglewise.ai/threats/cve-2026-59889-fasterxml-jackson-databind-authorization-bypass-in-jsonunwrapped"},{"cve":"CVE-2026-59888","cvss":6.5,"epss":0.0042,"slug":"cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records","title":"FasterXML jackson-databind @JsonIgnore bypass in Java Records","severity":"medium","exploited":false,"published_at":"2026-07-14T17:17:15.137+00:00","url":"https://junglewise.ai/threats/cve-2026-59888-fasterxml-jackson-databind-jsonignore-bypass-in-java-records"},{"cve":"CVE-2026-54518","cvss":6.5,"epss":0.0035,"slug":"cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in","title":"FasterXML jackson-databind authorization bypass in UnwrappedPropertyHandler","severity":"medium","exploited":false,"published_at":"2026-06-23T22:16:32.073+00:00","url":"https://junglewise.ai/threats/cve-2026-54518-fasterxml-jackson-databind-authorization-bypass-in"},{"cve":"CVE-2026-54517","cvss":5.3,"epss":0.0038,"slug":"cve-2026-54517-fasterxml-jackson-databind-jsonview-bypass-in-beandeserializer","title":"FasterXML jackson-databind @JsonView bypass in BeanDeserializer","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.853+00:00","url":"https://junglewise.ai/threats/cve-2026-54517-fasterxml-jackson-databind-jsonview-bypass-in-beandeserializer"},{"cve":"CVE-2026-54516","cvss":5.3,"epss":0.0045,"slug":"cve-2026-54516-fasterxml-jackson-databind-jsonignore-bypass-via-renamed","title":"FasterXML jackson-databind @JsonIgnore bypass via renamed properties","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.723+00:00","url":"https://junglewise.ai/threats/cve-2026-54516-fasterxml-jackson-databind-jsonignore-bypass-via-renamed"},{"cve":"CVE-2026-54515","cvss":5.3,"epss":0.0044,"slug":"cve-2026-54515-fasterxml-jackson-databind-property-exclusion-bypass-in","title":"FasterXML jackson-databind property exclusion bypass in BeanDeserializerBase","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.597+00:00","url":"https://junglewise.ai/threats/cve-2026-54515-fasterxml-jackson-databind-property-exclusion-bypass-in"},{"cve":"CVE-2026-54514","cvss":5.3,"epss":0.0037,"slug":"cve-2026-54514-fasterxml-jackson-databind-ssrf-via-eager-dns-resolution-in","title":"FasterXML jackson-databind SSRF via eager DNS resolution in InetSocketAddress","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:02.467+00:00","url":"https://junglewise.ai/threats/cve-2026-54514-fasterxml-jackson-databind-ssrf-via-eager-dns-resolution-in"},{"cve":"CVE-2026-54513","cvss":8.1,"epss":0.0123,"slug":"cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in","title":"FasterXML jackson-databind validation bypass in BasicPolymorphicTypeValidator","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.333+00:00","url":"https://junglewise.ai/threats/cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in"},{"cve":"CVE-2026-54512","cvss":8.1,"epss":0.01,"slug":"cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via","title":"FasterXML jackson-databind PolymorphicTypeValidator bypass via generic types","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via"},{"cve":"CVE-2026-50193","cvss":3.1,"epss":0.0062,"slug":"cve-2026-50193-fasterxml-jackson-databind-denial-of-service-via-deeply-nested","title":"FasterXML jackson-databind denial of service via deeply nested JSON","severity":"medium","exploited":false,"published_at":"2026-06-23T21:17:01.117+00:00","url":"https://junglewise.ai/threats/cve-2026-50193-fasterxml-jackson-databind-denial-of-service-via-deeply-nested"},{"cve":"CVE-2026-29062","cvss":7.5,"epss":0.0076,"slug":"cve-2026-29062-fasterxml-jackson-core-dos-via-nesting-depth-limit-bypass","title":"FasterXML jackson-core DoS via nesting depth limit bypass","severity":"high","exploited":false,"published_at":"2026-03-06T08:16:26.603+00:00","url":"https://junglewise.ai/threats/cve-2026-29062-fasterxml-jackson-core-dos-via-nesting-depth-limit-bypass"},{"cvss":6.9,"slug":"fasterxml-jackson-core-dos-via-number-length-limit-bypass-in-async-904e648b","title":"FasterXML jackson-core DoS via number length limit bypass in async parser","severity":"medium","exploited":false,"published_at":"2026-02-28T02:01:05+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-dos-via-number-length-limit-bypass-in-async-904e648b"},{"cve":"CVE-2022-42004","cvss":7.5,"epss":0.0278,"slug":"cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in","title":"FasterXML jackson-databind resource exhaustion in BeanDeserializer","severity":"high","exploited":false,"published_at":"2022-10-03T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in"}],"vendor":{"hub":true,"name":"FasterXML","slug":"fasterxml","homepage":"https://github.com/FasterXML","description":"FasterXML is an organization that maintains open-source data processing libraries, including the Jackson JSON processor.","url":"https://junglewise.ai/threats/vendors/fasterxml"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cvss":8.7,"slug":"fasterxml-jackson-core-memory-exhaustion-in-async-parser-via-chunked-aac0fe2a","title":"FasterXML jackson-core memory exhaustion in async parser via chunked digits","severity":"high","exploited":false,"published_at":"2026-07-21T21:58:53+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-memory-exhaustion-in-async-parser-via-chunked-aac0fe2a"},{"cve":"CVE-2026-54513","cvss":8.1,"epss":0.0123,"slug":"cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in","title":"FasterXML jackson-databind validation bypass in BasicPolymorphicTypeValidator","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.333+00:00","url":"https://junglewise.ai/threats/cve-2026-54513-fasterxml-jackson-databind-validation-bypass-in"},{"cve":"CVE-2026-54512","cvss":8.1,"epss":0.01,"slug":"cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via","title":"FasterXML jackson-databind PolymorphicTypeValidator bypass via generic types","severity":"high","exploited":false,"published_at":"2026-06-23T21:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-54512-fasterxml-jackson-databind-polymorphictypevalidator-bypass-via"},{"cve":"CVE-2022-42004","cvss":7.5,"epss":0.0278,"slug":"cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in","title":"FasterXML jackson-databind resource exhaustion in BeanDeserializer","severity":"high","exploited":false,"published_at":"2022-10-03T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-42004-fasterxml-jackson-databind-resource-exhaustion-in"},{"cve":"CVE-2026-29062","cvss":7.5,"epss":0.0076,"slug":"cve-2026-29062-fasterxml-jackson-core-dos-via-nesting-depth-limit-bypass","title":"FasterXML jackson-core DoS via nesting depth limit bypass","severity":"high","exploited":false,"published_at":"2026-03-06T08:16:26.603+00:00","url":"https://junglewise.ai/threats/cve-2026-29062-fasterxml-jackson-core-dos-via-nesting-depth-limit-bypass"},{"cve":"CVE-2026-89407","cvss":7.5,"epss":0.0063,"slug":"cve-2026-89407-numberinput-lookslikevalidnumber-in-fasterxml-jackson-core-pre","title":"FasterXML jackson-core regular expression denial of service in NumberInput","severity":"high","exploited":false,"published_at":"2026-09-22T15:17:21.053+00:00","url":"https://junglewise.ai/threats/cve-2026-89407-numberinput-lookslikevalidnumber-in-fasterxml-jackson-core-pre"},{"cve":"CVE-2026-68497","cvss":7.5,"epss":0.0058,"slug":"cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype","title":"FasterXML jackson-databind quadratic parse in XML datatype deserialization","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:39.61+00:00","url":"https://junglewise.ai/threats/cve-2026-68497-fasterxml-jackson-databind-quadratic-parse-in-xml-datatype"},{"cve":"CVE-2026-89425","cvss":7.5,"epss":0.0049,"slug":"cve-2026-89425-utf8datainputjsonparser-reportinvalidtoken-in-fasterxml-jackson","title":"FasterXML jackson-core denial of service in UTF8DataInputJsonParser","severity":"high","exploited":false,"published_at":"2026-09-23T03:17:04.357+00:00","url":"https://junglewise.ai/threats/cve-2026-89425-utf8datainputjsonparser-reportinvalidtoken-in-fasterxml-jackson"},{"cvss":8.7,"slug":"fasterxml-jackson-core-number-length-constraint-bypass-in-async-parser-78aa3f75","title":"FasterXML jackson-core number length constraint bypass in async parser","severity":"medium","exploited":false,"published_at":"2026-08-04T15:32:23+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-number-length-constraint-bypass-in-async-parser-78aa3f75"},{"cvss":6.9,"slug":"fasterxml-jackson-core-dos-via-number-length-limit-bypass-in-async-904e648b","title":"FasterXML jackson-core DoS via number length limit bypass in async parser","severity":"medium","exploited":false,"published_at":"2026-02-28T02:01:05+00:00","url":"https://junglewise.ai/threats/fasterxml-jackson-core-dos-via-number-length-limit-bypass-in-async-904e648b"}],"generated_at":"2026-09-26T14:07:00.158513+00:00","technologies":[{"name":"FasterXML Jackson-Databind","slug":"jackson-databind","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/jackson-databind"},{"name":"FasterXML Jackson-Core","slug":"jackson-core","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/jackson-core"}]}