[Git][security-tracker-team/security-tracker][master] new jackson-databind issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 4 12:13:04 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
31c75ed1 by Moritz Muehlenhoff at 2026-09-04T13:12:41+02:00
new jackson-databind issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3301,7 +3301,12 @@ CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads
CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is vulnerable to St ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path resolves an att ...)
- TODO: check
+ - jackson-databind <unfixed>
+ NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf
+ NOTE: https://github.com/FasterXML/jackson-databind/pull/6129
+ NOTE: https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551 (jackson-databind-2.18.10)
+ NOTE: https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d (jackson-databind-3.1.6)
+ NOTE: https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166 (jackson-databind-3.2.2)
CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to generic SQL ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an attacker to pro ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c75ed14f58f5b89cf13448c1d99228467f04b1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c75ed14f58f5b89cf13448c1d99228467f04b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/534f6e10/attachment.htm>
More information about the debian-security-tracker-commits
mailing list