These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-68497 is a high-severity vulnerability in the jackson-databind library, which can be exploited by an unauthenticated attacker to cause a denial-of-service (DoS) attack. The vulnerability is caused by the library's failure to properly validate the length of XML schema lexical grammar components, allowing an attacker to submit a malicious JSON string that can force the library to perform excessive CPU work.
CVE-2026-77310 is a vulnerability in the jackson-databind library that allows for DNS-based server-side request forgery and internal-host enumeration. The issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. Defenders should assess exposure and prioritize patching or mitigation to prevent potential DNS-based attacks and internal-host enumeration. The vulnerability is caused by the java.net [truncated]
CVE-2026-68494 is an incomplete fix for a previous vulnerability (CVE-2026-18401) in the Jackson Core library, which could allow an attacker to bypass the length constraint on numbers in JSON data. This could lead to a denial-of-service (DoS) attack by exhausting the JVM heap. The vulnerability affects versions 2.15.0 through 2.18.7 and 2.19.0 through 2.21.3 of jackson-core. The fix for this issue is incl [truncated]
CVE-2026-18401 is a denial-of-service vulnerability in the non-blocking JSON parser in jackson-core. An attacker can submit a JSON document with an arbitrarily long number to cause excessive memory allocation and potential CPU exhaustion. The async parser API does not enforce the maxNumberLength constraint, unlike the synchronous parser. Defenders of applications using the async parser API should assess e [truncated]
PatchSiren analyzed CVE-2026-59889, a vulnerability in jackson-databind's UnwrappedPropertyHandler. This issue allows attackers to write properties under a less-privileged active view. The vulnerability affects jackson-databind versions between 2.18.0 and 2.18.8, 2.21.4 and earlier, 2.22.0, 3.1.4 and earlier, and 3.2.0. Developers and security teams should prioritize patching to mitigate this vulnerability.
CVE-2026-29062 is a high-severity vulnerability in Jackson-Core, a popular Java library for processing JSON data. The vulnerability allows for a Denial of Service (DoS) attack due to a bypass of the maxNestingDepth constraint in the UTF8DataInputJsonParser and ReaderBasedJsonParser. This can be exploited by supplying a JSON document with excessive nesting, leading to a StackOverflowError. The issue has be [truncated]