9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether tools.jackson.core:jackson-databind is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2026-54513
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
MEDIUM 6.5
CVE-2026-59889
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM 6.5
CVE-2026-59888
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
MEDIUM 5.3
CVE-2026-54515
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
MEDIUM 5.3
CVE-2026-54517
jackson-databind has @JsonView bypass for setterless creator properties
MEDIUM 6.5
CVE-2026-54518
jackson-databind has a @JsonView bypass for unwrapped creator parameters
HIGH 8.1
CVE-2026-54512
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
MEDIUM 5.3
CVE-2026-54514
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
MEDIUM 5.3
CVE-2026-54516
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes