Dependency scanning
Check whether com.fasterxml.jackson.core:jackson-databind is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-54513
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-59889
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
CVE-2026-59888
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
CVE-2026-54515
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
CVE-2026-54517
jackson-databind has @JsonView bypass for setterless creator properties
CVE-2026-50193
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
GHSA-mhm7-754m-9p8w
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
CVE-2026-54518
jackson-databind has a @JsonView bypass for unwrapped creator parameters
CVE-2026-54512
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
CVE-2026-54514
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
CVE-2026-54516
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
CVE-2021-46877
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
CVE-2022-42003
Uncontrolled Resource Consumption in Jackson-databind
CVE-2022-42004
Uncontrolled Resource Consumption in FasterXML jackson-databind
CVE-2020-36518
Deeply nested json in jackson-databind
CVE-2019-14540
Polymorphic Typing issue in FasterXML jackson-databind
CVE-2019-14893
Polymorphic deserialization of malicious object in jackson-databind
CVE-2020-25649
XML External Entity (XXE) Injection in Jackson Databind
CVE-2020-10672
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-14195
Deserialization of untrusted data in Jackson Databind
CVE-2020-14062
Deserialization of untrusted data in Jackson Databind
CVE-2018-14721
Server-Side Request Forgery (SSRF) in jackson-databind
CVE-2020-11111
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11620
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11112
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-14060
Deserialization of untrusted data in Jackson Databind
CVE-2018-12023
Deserialization of Untrusted Data
CVE-2020-11113
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2018-19361
Deserialization of Untrusted Data in jackson-databind
CVE-2020-14061
Deserialization of untrusted data in Jackson Databind
CVE-2018-19360
Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
CVE-2020-9546
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2018-14720
XML External Entity Reference (XXE) in jackson-databind
CVE-2020-10968
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11619
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-10969
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-10650
jackson-databind vulnerable to unsafe deserialization
CVE-2020-36183
Unsafe Deserialization in jackson-databind
CVE-2021-20190
Deserialization of untrusted data in jackson-databind
GHSA-wrr7-33fx-rcvj
Deserialization of Untrusted Data in jackson-databind
CVE-2020-10673
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-35491
Serialization gadgets exploit in jackson-databind
CVE-2019-16943
jackson-databind polymorphic typing issue
CVE-2020-9547
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2019-17531
jackson-databind polymorphic typing issue
CVE-2018-14718
Arbitrary Code Execution in jackson-databind
CVE-2020-8840
Deserialization of Untrusted Data in jackson-databind
CVE-2019-17267
Improper Input Validation in jackson-databind
CVE-2018-14719
Arbitrary Code Execution in jackson-databind
CVE-2019-16335
Polymorphic Typing issue in FasterXML jackson-databind
CVE-2019-14379
Deserialization of untrusted data in FasterXML jackson-databind
CVE-2018-7489
FasterXML jackson-databind allows unauthenticated remote code execution
CVE-2019-12814
Deserialization of untrusted data in FasterXML jackson-databind
CVE-2019-12086
Information exposure in FasterXML jackson-databind
CVE-2018-19362
com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data
CVE-2017-15095
jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution
CVE-2019-12384
Deserialization of Untrusted Data in FasterXML jackson-databind
CVE-2019-20330
Deserialization of Untrusted Data in jackson-databind
CVE-2019-16942
Polymorphic Typing in FasterXML jackson-databind
CVE-2020-9548
jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-35490
Serialization gadgets exploit in jackson-databind
CVE-2019-14439
Deserialization of untrusted data in FasterXML jackson-databind
CVE-2018-11307
Deserialization of Untrusted Data in jackson-databind
CVE-2017-7525
jackson-databind is vulnerable to a deserialization flaw
CVE-2018-12022
jackson-databind Deserialization of Untrusted Data vulnerability
CVE-2018-5968
Deserialization of Untrusted Data in jackson-databind
CVE-2017-17485
jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass
CVE-2020-35728
Serialization gadget exploit in jackson-databind
CVE-2020-36182
Unsafe Deserialization in jackson-databind
CVE-2020-36179
Unsafe Deserialization in jackson-databind
CVE-2019-14892
Polymorphic deserialization of malicious object in jackson-databind
CVE-2020-36188
Unsafe Deserialization in jackson-databind
CVE-2020-36180
Unsafe Deserialization in jackson-databind
CVE-2020-36185
Unsafe Deserialization in jackson-databind
CVE-2020-36187
Unsafe Deserialization in jackson-databind
CVE-2020-24616
Code Injection in jackson-databind
CVE-2020-36181
Unsafe Deserialization in jackson-databind
CVE-2020-36189
Unsafe Deserialization in jackson-databind
CVE-2020-36186
Unsafe Deserialization in jackson-databind
CVE-2020-36184
Unsafe Deserialization in jackson-databind
CVE-2020-24750
Unsafe Deserialization in jackson-databind
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes