PT-2026-99157 · Suse+1 · Jackson-Annotations+4
CVE-2026-68498
·
Publicado
2026-09-24
·
Atualizado
2026-09-29
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-base fixes the following issues:
- CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
- CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
- CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639).
- CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser (bsc#1282640).
- CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
- CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
- CVE-2026-89425:
UTF8DataInputJsonParser. reportInvalidToken()lacksmaxErrorTokenLengthlimit, which allows for unboundedStringBuildergrowth and can lead to a DoS when malformed tokens are processed (bsc#1282505).
Changes for jackson-annotations:
- Update to 2.18.11
Changes for jackson-bom:
- Update to 2.18.11
Changes for jackson-core:
- Update to 2.18.11
- #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
- #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
- #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
- #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)
Changes for jackson-databind:
- Update to 2.18.11
- #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
- #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
- #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
- #6099: Resolve classes without initialization in TypeFactory.findClass()
- #6116: Reject non-ASCII digits in InetAddress literal validation
- #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
- #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
- #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
- #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys
Changes for jackson-dataformat-xml:
- Update to 2.18.11
- Fix build to avoid past-JDK-8 bytecode generation
- #891: Enforce StreamReadConstraints.maxNestingDepth in FromXmlParser
Changes for jackson-dataformats-binary:
- Update to 2.18.11
- #783: (protobuf) Support StreamReadConstraints.maxDocumentLength in ProtobufParser
- #785: (avro) Support StreamReadConstraints.maxDocumentLength and maxTokenCount in Avro parser
- #803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion parser (partial fix for #358)
- #805: (ion) Support StreamReadConstraints.maxDocumentLength in Ion parser (partial fix for #358)
- #725: (cbor) Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639, CVE-2026-68495)
- #726: (smile) Ensure maxNameLength limit enforced for Smile parser (bsc#1282640, CVE-2026-68496)
- #727: (cbor) CBORParser.nextFieldName(SerializableString) confuses 5-bit length marker 23 with 24 ('1-byte length suffix follows')
- #728: (cbor) CBORParser.nextFieldName(SerializableString) consumes Object entry slot twice on fast-path miss, truncating definite-length Objects
- #733: (cbor) Long
Strings not added to 'stringref' reference table, breaking following references - #735: (cbor) 'stringref' property-name paths pass 5-bit length marker instead of actual length to shouldReferenceString()
- #736: (cbor) Long Object property names added to 'stringref' reference table twice
Changes for jackson-modules-base:
- Update to 2.18.11
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jackson-Annotations
Jackson-Core
Jackson-Databind
Jackson-Dataformat-Xml
Jackson-Dataformats-Binary