PatchSiren

java-json-tools CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM java-json-tools CVE published 2026-09-07

CVE-2026-86321

A vulnerability was found in java-json-tools jackson-coreutils 2.0, affecting the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java, which is responsible for URL validation. This issue allows for server-side request forgery and can be exploited remotely. The exploit has been made public, and although the project was informed early through an issue report, there h [truncated]

MEDIUM java-json-tools CVE published 2026-09-07

CVE-2026-86319

A vulnerability was found in the java-json-tools json-patch library up to version 1.13. The vulnerability affects the JsonPatch.apply function in the JsonPatch.java file, which is part of the Patch Operation Handler component. This vulnerability can lead to resource consumption and can be exploited remotely. The exploit has been publicly disclosed, and although the project was informed early through an is [truncated]

MEDIUM java-json-tools CVE published 2026-09-07

CVE-2026-86318

A flaw in java-json-tools json-patch up to 1.13 can lead to a stack-based buffer overflow when executing a manipulation via JsonMergePatch.fromJson in JsonMergePatchDeserializer.java. The attack may be performed remotely. The exploit has been published and may be used. However, the project was informed early but has not responded yet. The vulnerability affects systems using java-json-tools json-patch, par [truncated]