📦

jackson-databind

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 62 Code Available
Total RCEs 64 Remote Access
Total CVEs 110 Total Indexed
Avg. EPSS 8.67% Exploit Prob.
Latest CVE CVE-2026-54518 Jun 23

Security Vulnerability Index

Page 5 / 11
8.8 CVSS
CVE-2020-11111
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

EPSS: 3.49%
8.8 CVSS
CVE-2020-10969
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

EPSS: 3.47%
8.8 CVSS
CVE-2020-10968
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

EPSS: 3.54%
8.8 CVSS
CVE-2020-10673
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

EPSS: 8.03%
8.8 CVSS

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

EPSS: 2.98%
9.8 CVSS
CVE-2019-14893
RCE Exploit Found

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.

EPSS: 4.09%
9.8 CVSS
CVE-2019-14892
RCE Exploit Found

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

EPSS: 5.62%
9.8 CVSS
CVE-2020-9548
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

EPSS: 18.34%
9.8 CVSS
CVE-2020-9547
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

EPSS: 18.67%
9.8 CVSS
CVE-2020-9546
Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

EPSS: 4.61%