Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/com.fasterxml.jackson.core/jackson-core

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constraint (default: 500) defined in StreamReadConstraints. A similar issue was found in ReaderBasedJsonParser. This allows a user to supply a JSON document with excessive nesting, which can cause a StackOverflowError when the structure is processed, leading to a Denial of Service (DoS). This issue has been patched in version 3.1.0.

Join the discussion

A stack-based buffer overflow vulnerability exists in FasterXML jackson-core versions prior to 2.15.0. This occurs when parsing input files with deeply nested data, potentially causing a StackOverflowError. Version 2.15.0 introduces a configurable depth limit (default 1000) to prevent this issue by throwing a StreamConstraintsException when exceeded.jackson-databind also benefits from this fix as it relies on jackson-core for JSON parsing.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:maven/com.fasterxml.jackson.core/jackson-core
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses