Bug#1108367: marked as pending in jackson-core

Emmanuel Arias noreply at salsa.debian.org
Mon Oct 6 15:54:29 BST 2025


Control: tag -1 pending

Hello,

Bug #1108367 in jackson-core reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/java-team/jackson-core/-/commit/1578f93a08e5ba2e567120f09fcc61515bce9c8c

------------------------------------------------------------------------
CVE-2025-52999: A limite was added to avoid a StackoverflowError if the parsed JSON is very deeply nested. The StackoverflowError issue happens in jackson-databind but this change in jackson-core stops it from happening unless you increase the StreamReadConstraints.maxNestingDepth() to a high number (Closes: #1108367).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1108367



More information about the pkg-java-maintainers mailing list