📦

jackson-databind

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 62 Code Available
Total RCEs 64 Remote Access
Total CVEs 110 Total Indexed
Avg. EPSS 8.67% Exploit Prob.
Latest CVE CVE-2026-54518 Jun 23

Security Vulnerability Index

Page 2 / 11
8.1 CVSS

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

EPSS: 3.33%
7.5 CVSS

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

EPSS: 2.71%
7.5 CVSS

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

EPSS: 2.71%
7.5 CVSS
CVE-2020-36518
RCE Exploit Found

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

EPSS: 4.86%
8.1 CVSS
CVE-2021-20190
RCE Exploit Found

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS: 7.48%
8.1 CVSS
CVE-2020-36183
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

EPSS: 4.89%
8.1 CVSS
CVE-2020-36182
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

EPSS: 5.02%
8.1 CVSS
CVE-2020-36180
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

EPSS: 5.04%
8.1 CVSS
CVE-2020-36179
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

EPSS: 20.93%
8.1 CVSS
CVE-2020-36189
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

EPSS: 4.91%