[Git][security-tracker-team/security-tracker][master] Add CVE-2026-89407/jackson-core

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 04:57:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
855b26c0 by Salvatore Bonaccorso at 2026-09-23T05:57:22+02:00
Add CVE-2026-89407/jackson-core

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -381,7 +381,12 @@ CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erla
 CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
 	NOT-FOR-US: ZenHive mpp
 CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
-	TODO: check
+	- jackson-core <unfixed>
+	NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89
+	NOTE: https://github.com/FasterXML/jackson-core/issues/1649
+	NOTE: https://github.com/FasterXML/jackson-core/pull/1650
+	NOTE: https://github.com/FasterXML/jackson-core/pull/1701 (2.18 backport)
+	NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff (jackson-core-3.2.3, jackson-core-3.1.7, jackson-core-2.22.3, jackson-core-2.21.7, jackson-core-2.18.11)
 CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
 	NOT-FOR-US: Adobe
 CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/855b26c0f201a5c0a3abb04b3ef8cfb499672fb0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/855b26c0f201a5c0a3abb04b3ef8cfb499672fb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/a1fa4f4f/attachment.htm>


More information about the debian-security-tracker-commits mailing list