[Git][security-tracker-team/security-tracker][master] Add CVE-2026-89407/jackson-core
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 23 04:57:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
855b26c0 by Salvatore Bonaccorso at 2026-09-23T05:57:22+02:00
Add CVE-2026-89407/jackson-core
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -381,7 +381,12 @@ CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erla
CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
NOT-FOR-US: ZenHive mpp
CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
- TODO: check
+ - jackson-core <unfixed>
+ NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89
+ NOTE: https://github.com/FasterXML/jackson-core/issues/1649
+ NOTE: https://github.com/FasterXML/jackson-core/pull/1650
+ NOTE: https://github.com/FasterXML/jackson-core/pull/1701 (2.18 backport)
+ NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff (jackson-core-3.2.3, jackson-core-3.1.7, jackson-core-2.22.3, jackson-core-2.21.7, jackson-core-2.18.11)
CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
NOT-FOR-US: Adobe
CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/855b26c0f201a5c0a3abb04b3ef8cfb499672fb0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/855b26c0f201a5c0a3abb04b3ef8cfb499672fb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/a1fa4f4f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list