[Git][security-tracker-team/security-tracker][master] Add CVE-2026-68497/jackson-databind

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 10:15:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1cecff4f by Salvatore Bonaccorso at 2026-09-12T11:15:29+02:00
Add CVE-2026-68497/jackson-databind

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2017,7 +2017,10 @@ CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable to
 CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered remote  ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Duration  ...)
-	TODO: check
+	- jackson-databind <unfixed>
+	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
+	NOTE: https://github.com/FasterXML/jackson-databind/pull/6127
+	NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd (jackson-databind-2.18.10)
 CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
 	- apache-opennlp <not-affected> (Vulnerable code not present)
 	NOTE: https://lists.apache.org/thread/gnobdsj640c60xl76q8g9o73c7jsybjm



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cecff4fcc3de538fb97323bb772bab1c4e1f296

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cecff4fcc3de538fb97323bb772bab1c4e1f296
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/01eae2ba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list