📦

jackson-databind

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 62 Code Available
Total RCEs 64 Remote Access
Total CVEs 110 Total Indexed
Avg. EPSS 8.67% Exploit Prob.
Latest CVE CVE-2026-54518 Jun 23

Security Vulnerability Index

Page 6 / 11
9.8 CVSS
CVE-2020-8840
RCE Exploit Found

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

EPSS: 26.59%
9.8 CVSS
CVE-2019-20330
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

EPSS: 8.64%
9.8 CVSS
CVE-2019-17531
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

EPSS: 5.37%
9.8 CVSS
CVE-2019-17267
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

EPSS: 4.63%
9.8 CVSS
CVE-2019-16943
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

EPSS: 4.90%
9.8 CVSS
CVE-2019-16942
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

EPSS: 5.73%
9.8 CVSS
CVE-2019-16335
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

EPSS: 4.96%
9.8 CVSS
CVE-2019-14540
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

EPSS: 10.76%
7.5 CVSS
CVE-2019-14439
RCE Exploit Found

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

EPSS: 10.85%
9.8 CVSS
CVE-2019-14379
RCE Exploit Found

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

EPSS: 8.11%