Security update for jackson-annotations, jackson-core, jackson-databind
Description
This security update addresses multiple vulnerabilities in the jackson-annotations, jackson-core, and jackson-databind libraries. The issues include bypasses of number length constraints in asynchronous parsers, unsafe deserialization of java.nio.file.Path URIs, unbounded cache growth, denial of service via unbounded string builder growth, and unsafe polymorphic deserialization allowing arbitrary Comparable types. The update to version 2.18.11 includes fixes that enforce length limits, restrict URI schemes, optimize parsing functions, and prevent unbounded resource consumption.
Affected software
pkg:maven/com.fasterxml.jackson.core/jackson-annotationspkg:maven/com.fasterxml.jackson.core/jackson-corepkg:maven/com.fasterxml.jackson.core/jackson-databindRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for jackson-annotations, jackson-core, and jackson-databind fixes several vulnerabilities: CVE-2026-18401 and CVE-2026-68494 address number length constraint bypasses in asynchronous parsers that could lead to processing time issues; CVE-2026-19032 restricts URI schemes in java.nio.file.Path deserialization to prevent unsafe resolution of attacker-supplied URIs; CVE-2026-68497 mitigates the ability for unauthenticated attackers to submit large requests; CVE-2026-68498 enforces maxNameLength incrementally to prevent bypass; CVE-2026-83557 adds java.lang.Comparable to unsafe polymorphic base types to prevent arbitrary deserialization; CVE-2026-89425 limits unbounded StringBuilder growth during malformed token processing to prevent denial of service; CVE-2026-91776 prevents unbounded cache growth from attacker-supplied type IDs; and CVE-2026-91777 optimizes forward-reference completion to avoid quadratic CPU usage. These fixes are included in version 2.18.11 of the respective libraries.
Potential Impact
The vulnerabilities could allow attackers to bypass input length constraints, causing excessive processing time or denial of service conditions. Unsafe deserialization of attacker-controlled data could lead to arbitrary code execution or resource exhaustion. Unbounded cache growth and inefficient processing could degrade application performance or cause crashes. The ability to submit large requests without authentication increases the risk of denial of service attacks.
Mitigation Recommendations
A fixed version 2.18.11 of jackson-annotations, jackson-core, and jackson-databind is available and should be applied to remediate these vulnerabilities. Users should upgrade to this version to ensure all listed issues are addressed. No additional mitigation steps are indicated beyond applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:22034-1
- Cve Count
- 10
- Additional Cves
- ["CVE-2026-19032","CVE-2026-68494","CVE-2026-68497","CVE-2026-68498","CVE-2026-83557","CVE-2026-89407","CVE-2026-89425","CVE-2026-91776","CVE-2026-91777"]
- State
- PUBLISHED
Threat ID: 6ac80fb02cdf04f65639a73d
Added to database: 10/08/2026, 21:48:32 UTC
Last enriched: 10/08/2026, 22:09:10 UTC
Last updated: 10/08/2026, 23:28:09 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.