Bug#1108367: marked as pending in jackson-core
Emmanuel Arias
noreply at salsa.debian.org
Mon Oct 6 15:54:29 BST 2025
Control: tag -1 pending
Hello,
Bug #1108367 in jackson-core reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:
https://salsa.debian.org/java-team/jackson-core/-/commit/1578f93a08e5ba2e567120f09fcc61515bce9c8c
------------------------------------------------------------------------
CVE-2025-52999: A limite was added to avoid a StackoverflowError if the parsed JSON is very deeply nested. The StackoverflowError issue happens in jackson-databind but this change in jackson-core stops it from happening unless you increase the StreamReadConstraints.maxNestingDepth() to a high number (Closes: #1108367).
------------------------------------------------------------------------
(this message was generated automatically)
--
Greetings
https://bugs.debian.org/1108367
More information about the pkg-java-maintainers
mailing list