[Git][security-tracker-team/security-tracker][master] Add two jackson-core issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 21:24:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b64da344 by Salvatore Bonaccorso at 2026-08-04T22:24:24+02:00
Add two jackson-core issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -68,7 +68,10 @@ CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in t
 	- sssd <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509760
 CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401  ...)
-	TODO: check
+	- jackson-core <not-affected> (Incomplete fix for CVE-2026-18401 not applied)
+	NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9
+	NOTE: https://github.com/FasterXML/jackson-core/pull/1611
+	NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641 (jackson-core-2.18.8)
 CVE-2026-67618 (marimo before 0.23.15 contains a configuration injection vulnerability ...)
 	NOT-FOR-US: marimo
 CVE-2026-67243 (freo2 provided by refirio contains an unrestricted upload of file with ...)
@@ -237,7 +240,11 @@ CVE-2026-18753 (The product firmware contains an embedded, static RSA private ke
 CVE-2026-18650 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows  ...)
 	TODO: check
 CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core does not e ...)
-	TODO: check
+	- jackson-core <unfixed>
+	NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq
+	NOTE: https://github.com/FasterXML/jackson-core/pull/1555
+	NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf (jackson-core-2.18.6)
+	NOTE: When fixing this issue make sure to make it complete to not open up CVE-2026-68494.
 CVE-2026-17070 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows  ...)
 	TODO: check
 CVE-2026-15721 (Cleartext storage of sensitive information vulnerability in Bilin Soft ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b64da34460f77ce0f3cda85a8489ecb6b1e86373

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b64da34460f77ce0f3cda85a8489ecb6b1e86373
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/dacf82a4/attachment.htm>


More information about the debian-security-tracker-commits mailing list