Fasterxml maintains a narrow but strategically positioned portfolio of Java serialization and data-format libraries, most notably Jackson, that are embedded across a vast range of enterprise applications, web frameworks, and microservices infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and concentrate in a durable pattern of deserialization flaws, resource-exhaustion conditions, and XML entity-reference issues that arise from the parsing and object-instantiation demands of a universal data-binding library. Jackson's deep presence in the Java ecosystem—particularly in Spring Boot, Kafka, and similar foundation layers—means that a single flaw in the core databind module can propagate to thousands of downstream products, amplifying the practical impact beyond the vendor's own product count. Defenders should treat Fasterxml disclosures as high-priority for any Java-based infrastructure and maintain a forward-facing inventory of Jackson versions in use, especially across REST APIs and message-processing pipelines; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fasterxml over time
Signals from CVEs in this vendor scope (86 CVEs).
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17485CRITICAL FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization fl | Jan 10, 2018 | 9.8 | 58 | NO | NO |
CVE-2020-9547CRITICAL FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransacti | Mar 2, 2020 | 9.8 | 52 | NO | YES |
CVE-2020-9548CRITICAL FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-co | Mar 2, 2020 | 9.8 | 51 | NO | YES |
CVE-2017-7525CRITICAL A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by se | Feb 6, 2018 | 9.8 | 50 | NO | NO |
CVE-2020-8840CRITICAL FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. | Feb 10, 2020 | 9.8 | 45 | NO | NO |
CVE-2019-12384MEDIUM FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserializat | Jun 24, 2019 | 5.9 | 45 | NO | NO |
CVE-2018-7489CRITICAL FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7 | Feb 26, 2018 | 9.8 | 43 | NO | NO |
CVE-2026-54513HIGH jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTyp | Jun 23, 2026 | 8.1 | 40 | NO | NO |
CVE-2026-54512HIGH jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's | Jun 23, 2026 | 8.1 | 39 | NO | NO |
CVE-2020-36179HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte | Jan 7, 2021 | 8.1 | 36 | NO | NO |
Signals from CVEs in this vendor scope (86 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fasterxml.
Media articles that mention a CVE ID that affects a product developed by Fasterxml — matched by CVE ID, not by vendor name.