[Git][security-tracker-team/security-tracker][master] new jackson-databind issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 12:13:04 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
31c75ed1 by Moritz Muehlenhoff at 2026-09-04T13:12:41+02:00
new jackson-databind issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3301,7 +3301,12 @@ CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads
 CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is vulnerable to St ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path resolves an att ...)
-	TODO: check
+	- jackson-databind <unfixed>
+	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf
+	NOTE: https://github.com/FasterXML/jackson-databind/pull/6129
+	NOTE: https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551 (jackson-databind-2.18.10)
+	NOTE: https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d (jackson-databind-3.1.6)
+	NOTE: https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166 (jackson-databind-3.2.2)
 CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to generic SQL ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an attacker to pro ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c75ed14f58f5b89cf13448c1d99228467f04b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c75ed14f58f5b89cf13448c1d99228467f04b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/534f6e10/attachment.htm>


More information about the debian-security-tracker-commits mailing list