[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-18401
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 7 05:07:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3e49c316 by Salvatore Bonaccorso at 2026-08-07T06:06:40+02:00
Update status for CVE-2026-18401
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2040,7 +2040,7 @@ CVE-2026-18753 (The product firmware contains an embedded, static RSA private ke
CVE-2026-18650 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows ...)
NOT-FOR-US: Liman MYS
CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core does not e ...)
- - jackson-core <unfixed>
+ - jackson-core <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq
NOTE: https://github.com/FasterXML/jackson-core/pull/1555
NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf (jackson-core-2.18.6)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e49c3162d5eba0cbdfae3c3691418f875617c40
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e49c3162d5eba0cbdfae3c3691418f875617c40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/bdf07659/attachment.htm>
More information about the debian-security-tracker-commits
mailing list