Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54518: CWE-863: Incorrect Authorization in FasterXML jackson-databindCVE-2026-54518
0

A medium severity authorization vulnerability exists in FasterXML jackson-databind versions prior to 2.21.4 and 3.1.4. The flaw allows attacker-controlled JSON to populate constructor parameters annotated with both @JsonView and @JsonUnwrapped, bypassing intended view-based access controls. This occurs because the unwrapped-creator replay path does not enforce visibility checks on creator properties. The issue is fixed in versions 2.21.4 and 3.1.4.

Join the discussion
CVE-2026-54517: CWE-863: Incorrect Authorization in FasterXML jackson-databindCVE-2026-54517
0

A medium severity authorization vulnerability (CWE-863) exists in FasterXML jackson-databind versions from 2.21.0 up to but not including 2.21.4 and 3.1.4. The issue involves incorrect application of the @JsonView filter during deserialization, allowing attacker-controlled JSON to populate setterless Collection/Map properties annotated with restricted views, bypassing intended view-based access controls. This flaw is fixed in versions 2.21.4 and 3.1.4.

Join the discussion
CVE-2026-54516: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54516
0

A vulnerability in FasterXML jackson-databind versions from 2.21.0 until 2.21.4 and 3.1.4 allows an attacker to bypass @JsonIgnore on a setter by renaming a property with @JsonProperty on the getter. This leads to direct modification of a private backing field during deserialization. The issue is fixed in version 3.1.4.

Join the discussion
CVE-2026-54515: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54515
0

A vulnerability in FasterXML jackson-databind versions from 2.8.0 until fixed versions allows ignored properties to become writable again due to improper handling of property exclusions combined with case-insensitivity processing. This issue is identified as CWE-915 and affects the BeanDeserializerBase.createContextual() method. The vulnerability has a medium severity with a CVSS score of 5.3 and is fixed in versions 2.18.9, 2.21.5, and 3.1.4.

Join the discussion
CVE-2026-54514: CWE-918: Server-Side Request Forgery (SSRF) in FasterXML jackson-databindCVE-2026-54514
0

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind due to eager DNS resolution during deserialization of InetSocketAddress fields. Versions from 2.0.0 up to but not including 2.18.8, 2.21.4, and 3.1.4 are affected. The issue arises because the deserializer performs DNS resolution immediately, allowing an attacker to trigger DNS queries before application-level validation. This vulnerability is fixed in versions 2.18.8, 2.21.4, and 3.1.4 by deferring DNS resolution until an explicit connection attempt.

Join the discussion
CVE-2026-54513: CWE-184: Incomplete List of Disallowed Inputs in FasterXML jackson-databindCVE-2026-54513
0

A vulnerability in FasterXML jackson-databind affects versions from 2.10.0 up to but not including 2.18.8, 2.21.4, and 3.1.4. The issue arises because the BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() method allowlists array types based only on whether the class is an array, without validating the component type against the allowlist. This allows deserialization of arrays of disallowed types, bypassing intended security checks. The vulnerability is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

Join the discussion
CVE-2026-54512: CWE-184: Incomplete List of Disallowed Inputs in FasterXML jackson-databindCVE-2026-54512
0

A vulnerability in jackson-databind's polymorphic deserialization allows bypassing the configured PolymorphicTypeValidator (PTV) allow-list when generic type parameters are used. This occurs because only the raw container class name is validated, not the nested generic type arguments. An attacker controlling the type ID can specify a denied class as a generic parameter within an allowed container, leading to unsafe deserialization and potential remote code execution. This issue affects versions from 2.10.0 up to but not including 2.18.8, 2.21.4, and 3.1.4, where it is fixed.

Join the discussion
CVE-2026-50193: CWE-400: Uncontrolled Resource Consumption in FasterXML jackson-databindCVE-2026-50193
0

A denial-of-service vulnerability exists in FasterXML jackson-databind versions from 2.13.0 up to but not including 2.14.0. The issue occurs when processing deeply nested JSON structures (thousands of levels) using ObjectMapper.readTree() and then serializing the JsonNode back to a string. This can lead to uncontrolled resource consumption, potentially impacting service availability. The vulnerability is fixed in version 2.14.0.

Join the discussion

Showing 1 to 8 of 8 results

Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses