Jackson Databind

Vendor:

First CVE: Jan 10, 2018 · Active for 8 years

78
Total CVEs
More Total CVEs than 99% of tracked products
11.1
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jackson Databind over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2018
8 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

CVE Severity & Scoring

Jackson Databind78 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (1.3%)
Network77 (98.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (59.0%)
High32 (41.0%)
Unknown0 (0.0%)
User Interaction
None69 (88.5%)
Unknown0 (0.0%)
Required9 (11.5%)
Privileges Required
Low1 (1.3%)
High0 (0.0%)
None77 (98.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (78 CVEs).

78 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization fl
Jan 10, 20189.858NONO
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransacti
Mar 2, 20209.852NOYES
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-co
Mar 2, 20209.851NOYES
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by se
Feb 6, 20189.850NONO
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
Feb 10, 20209.845NONO
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserializat
Jun 24, 20195.945NONO
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7
Feb 26, 20189.843NONO
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTyp
Jun 23, 20268.140NONO
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's
Jun 23, 20268.139NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte
Jan 7, 20218.136NONO

Exploit Exposure

Signals from CVEs in this product scope (78 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (78 CVEs).

Media Mentions

Signals from CVEs in this product scope (78 CVEs).

Top CNAs Publishing CVEs For Jackson Databind

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.049.812.6%00
2.8.029.99.0%00
2.7.029.99.0%00
2.22.015.30.4%00
2.13.017.51.1%00
2.10.018.13.3%00