{"grype_matches":[{"artifact":{"id":"f0e36dd27cd5f201","cpes":["cpe:2.3:a:jonathan-hedley:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:jonathan_hedley:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jsoup:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.23.1:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.23.1","type":"java-archive","version":"1.23.1","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jsoup-1.23.1.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"0c0350bb325da274f0508349109516a7855d01ab","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jsoup-1.23.1.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jsoup-1.23.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-65r4-943x-97jj","versionConstraint":"<1.23.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.23.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-65r4-943x-97jj","fix":{"state":"fixed","versions":["1.23.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.23.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"risk":0.40950000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-75140","https://github.com/jhy/jsoup/pull/2556","https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder","https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-65r4-943x-97jj","description":"jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations"},"relatedVulnerabilities":[{"id":"CVE-2026-75140","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"urls":["https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://github.com/jhy/jsoup/pull/2556","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75140","description":"jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application."}]},{"artifact":{"id":"f2a3d0ffa28d9ec9","cpes":["cpe:2.3:a:jonathan-hedley:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:jonathan_hedley:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jsoup:jsoup:1.23.1:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.23.1:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.23.1","type":"java-archive","version":"1.23.1","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/usr/share/opensearch/plugins/opensearch-skills/jsoup-1.23.1.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"0c0350bb325da274f0508349109516a7855d01ab","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-skills/jsoup-1.23.1.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-skills/jsoup-1.23.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-65r4-943x-97jj","versionConstraint":"<1.23.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.23.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-65r4-943x-97jj","fix":{"state":"fixed","versions":["1.23.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.23.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"risk":0.40950000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-75140","https://github.com/jhy/jsoup/pull/2556","https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder","https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-65r4-943x-97jj","description":"jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations"},"relatedVulnerabilities":[{"id":"CVE-2026-75140","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"urls":["https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://github.com/jhy/jsoup/pull/2556","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75140","description":"jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application."}]},{"artifact":{"id":"cc846903f520ab78","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"ab3429ceb5205bc1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"6f74a6589692dd2d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"bcfc770dcbfb1841","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"b65c7dd7aae43763","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"6ecc75b982888f3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"b7535ad8e55c41a1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"f2d1184070918264","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"418f077f4955c9fb","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"601c7f4f4caa9386","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"232cf9b88e24a035","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"4aa71a1b8216c2c3","cpes":["cpe:2.3:a:org.jline.builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:builtins:3.21.0:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.21.0","type":"java-archive","version":"3.21.0","language":"java","licenses":["https://opensource.org/licenses/BSD-3-Clause"],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":[{"value":"e90bfa5dc84615baa864f073000f80cdeb849720","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r2xf-8xr9-62gw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.21.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r2xf-8xr9-62gw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"risk":0.372,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r2xf-8xr9-62gw","description":"JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping"},"relatedVulnerabilities":[{"id":"CVE-2026-77422","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77422","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"b7535ad8e55c41a1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"601c7f4f4caa9386","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"418f077f4955c9fb","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"f2d1184070918264","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"b65c7dd7aae43763","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"6ecc75b982888f3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"cc846903f520ab78","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"bcfc770dcbfb1841","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"6f74a6589692dd2d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"ab3429ceb5205bc1","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"232cf9b88e24a035","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"13a748ea3e329fa220076e021b45c8391b32420c","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-core-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"542778a1c3e661aa","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/lib/jackson-core-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"33448a192d5b662438c859a57daf0f3e8ad9da4b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/lib/jackson-core-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/lib/jackson-core-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"ea056f2f4239bd23","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"74e8dd5e6473dad3","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"6683eae89513af8d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"01461c48db5e42cb","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"6c70dc7fb6524e6c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"8b62f1500fce0b7d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"48e5c4d4dc46a9c8","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"d1f95bc3327a346d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"9c991ccdc1b26834","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"a69af2d6d0667db8","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"09201a122e0d63a0","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"ea056f2f4239bd23","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/modules/ingest-geoip/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"8b62f1500fce0b7d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"09201a122e0d63a0","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"74e8dd5e6473dad3","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"6683eae89513af8d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"01461c48db5e42cb","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"6c70dc7fb6524e6c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"48e5c4d4dc46a9c8","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-observability/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"d1f95bc3327a346d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"9c991ccdc1b26834","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"921bd2092b0c539b2876de7063d55c72edcd05d3","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-2.22.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"a69af2d6d0667db8","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/opensaml-3.9.0.0-all.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"89ac86e6b6a53fa4","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"2d55b696fe3b6c6d","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"9d200714764c3a6a","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"f929ca98ed956504","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"13e0df457e7c52ec","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"211b9b98d1c3740f","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"281c6918d363d68a","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"eb3f7a1e2a9f6625","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"cd040d1fa47317fd","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"5686c363c7fab7c8","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"32946541adb45b73","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"211b9b98d1c3740f","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"281c6918d363d68a","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"89ac86e6b6a53fa4","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ubi/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"5686c363c7fab7c8","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"9d200714764c3a6a","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-alerting/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"cd040d1fa47317fd","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-neural-search/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"eb3f7a1e2a9f6625","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-notifications-core/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"32946541adb45b73","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-flow-framework/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"2d55b696fe3b6c6d","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-sql/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"f929ca98ed956504","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"13e0df457e7c52ec","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.2","type":"java-archive","version":"3.2.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7415dfebcdfed0af627a087ed175e7ab08bb12e6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-search-relevance/jackson-databind-3.2.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"b859babb95935dae","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:curl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:curl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/amzn/curl-minimal@8.21.0-5.amzn2023.0.1?arch=x86_64&distro=amzn-2023&upstream=curl-8.21.0-5.amzn2023.0.1.src.rpm","type":"rpm","version":"8.21.0-5.amzn2023.0.1","language":"","licenses":["curl"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"8.21.0-5.amzn2023.0.1"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.21.0-5.amzn2023.0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3128","versionConstraint":"< 8.21.0-5.amzn2023.0.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"curl-minimal","version":"0:8.21.0-5.amzn2023.0.1"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"8.21.0-5.amzn2023.0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3128","versionConstraint":"< 8.21.0-5.amzn2023.0.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"curl","version":"8.21.0-5.amzn2023.0.1"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3128","fix":{"state":"fixed","versions":["8.21.0-5.amzn2023.0.2"],"available":[{"date":"2026-09-29","kind":"advisory","version":"8.21.0-5.amzn2023.0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3128.html","description":"When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. (CVE-2026-80230)"},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"c1c572a37e2087f1","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:libcurl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:libcurl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:8.21.0-5.amzn2023.0.1:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/amzn/libcurl-minimal@8.21.0-5.amzn2023.0.1?arch=x86_64&distro=amzn-2023&upstream=curl-8.21.0-5.amzn2023.0.1.src.rpm","type":"rpm","version":"8.21.0-5.amzn2023.0.1","language":"","licenses":["curl"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"8.21.0-5.amzn2023.0.1"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.21.0-5.amzn2023.0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3128","versionConstraint":"< 8.21.0-5.amzn2023.0.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"libcurl-minimal","version":"0:8.21.0-5.amzn2023.0.1"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"8.21.0-5.amzn2023.0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3128","versionConstraint":"< 8.21.0-5.amzn2023.0.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"curl","version":"8.21.0-5.amzn2023.0.1"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3128","fix":{"state":"fixed","versions":["8.21.0-5.amzn2023.0.2"],"available":[{"date":"2026-09-29","kind":"advisory","version":"8.21.0-5.amzn2023.0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3128.html","description":"When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. (CVE-2026-80230)"},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"4aa71a1b8216c2c3","cpes":["cpe:2.3:a:org.jline.builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:builtins:builtins:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:builtins:3.21.0:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.21.0","type":"java-archive","version":"3.21.0","language":"java","licenses":["https://opensource.org/licenses/BSD-3-Clause"],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":[{"value":"e90bfa5dc84615baa864f073000f80cdeb849720","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ph9c-7hw9-vhhw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.21.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ph9c-7hw9-vhhw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"risk":0.24955,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ph9c-7hw9-vhhw","description":"JLine: ReDoS in Nano Editor Regex Search Mode"},"relatedVulnerabilities":[{"id":"CVE-2026-77421","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77421","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"664354e05a5a63a4","cpes":["cpe:2.3:a:amazonlinux:libxml2:2.10.4-1.amzn2023.0.20:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2:2.10.4-1.amzn2023.0.20:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/amzn/libxml2@2.10.4-1.amzn2023.0.20?arch=x86_64&distro=amzn-2023&upstream=libxml2-2.10.4-1.amzn2023.0.20.src.rpm","type":"rpm","version":"2.10.4-1.amzn2023.0.20","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.10.4-1.amzn2023.0.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3122","versionConstraint":"< 2.10.4-1.amzn2023.0.21 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"libxml2","version":"0:2.10.4-1.amzn2023.0.20"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3122","fix":{"state":"fixed","versions":["2.10.4-1.amzn2023.0.21"],"available":[{"date":"2026-09-29","kind":"advisory","version":"2.10.4-1.amzn2023.0.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841},{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398},{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383},{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291},{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231},{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256},{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.218,"urls":[],"severity":"Medium","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3122.html","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings. (CVE-2026-74860)In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. (CVE-2026-86137)In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. (CVE-2026-86138)In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. (CVE-2026-86140)In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. (CVE-2026-86142)In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. (CVE-2026-86143)In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). (CVE-2026-86144)"},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},{"id":"CVE-2026-86137","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"urls":["https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86137","description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."},{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."},{"id":"CVE-2026-86140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."},{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."},{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."},{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"dd5bb59826e63cc9","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.2:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.2","type":"java-archive","version":"1.11.2","language":"java","licenses":["Apache License, Version 2.0;link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"3fe7cb28a7102752d77c3aa4e309ea76efe85def","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"2fe3707a2ac3050b","cpes":["cpe:2.3:a:amazonlinux:python3-rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:python3_rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3-rpm:python3-rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3-rpm:python3_rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3-rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3_rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*"],"name":"python3-rpm","purl":"pkg:rpm/amzn/python3-rpm@4.16.1.3-29.amzn2023.0.7?arch=x86_64&distro=amzn-2023&upstream=rpm-4.16.1.3-29.amzn2023.0.7.src.rpm","type":"rpm","version":"4.16.1.3-29.amzn2023.0.7","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"python3-rpm","version":"0:4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3125","fix":{"state":"fixed","versions":["4.16.1.3-29.amzn2023.0.8"],"available":[{"date":"2026-09-29","kind":"advisory","version":"4.16.1.3-29.amzn2023.0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857},{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"risk":0.14775000000000002,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3125.html","description":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball. (CVE-2026-78367)A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. (CVE-2026-84233)"},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},{"id":"CVE-2026-84233","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"urls":["https://access.redhat.com/errata/RHSA-2026:66637","https://access.redhat.com/security/cve/CVE-2026-84233","https://bugzilla.redhat.com/show_bug.cgi?id=2478409"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84233","description":"A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability."}]},{"artifact":{"id":"c400e983acf9633b","cpes":["cpe:2.3:a:amazonlinux:rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/amzn/rpm@4.16.1.3-29.amzn2023.0.7?arch=x86_64&distro=amzn-2023&upstream=rpm-4.16.1.3-29.amzn2023.0.7.src.rpm","type":"rpm","version":"4.16.1.3-29.amzn2023.0.7","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm","version":"0:4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3125","fix":{"state":"fixed","versions":["4.16.1.3-29.amzn2023.0.8"],"available":[{"date":"2026-09-29","kind":"advisory","version":"4.16.1.3-29.amzn2023.0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857},{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"risk":0.14775000000000002,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3125.html","description":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball. (CVE-2026-78367)A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. (CVE-2026-84233)"},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},{"id":"CVE-2026-84233","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"urls":["https://access.redhat.com/errata/RHSA-2026:66637","https://access.redhat.com/security/cve/CVE-2026-84233","https://bugzilla.redhat.com/show_bug.cgi?id=2478409"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84233","description":"A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability."}]},{"artifact":{"id":"1f12922cf118c2e5","cpes":["cpe:2.3:a:rpm-build-libs:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build-libs:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-build-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_build_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*"],"name":"rpm-build-libs","purl":"pkg:rpm/amzn/rpm-build-libs@4.16.1.3-29.amzn2023.0.7?arch=x86_64&distro=amzn-2023&upstream=rpm-4.16.1.3-29.amzn2023.0.7.src.rpm","type":"rpm","version":"4.16.1.3-29.amzn2023.0.7","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm-build-libs","version":"0:4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3125","fix":{"state":"fixed","versions":["4.16.1.3-29.amzn2023.0.8"],"available":[{"date":"2026-09-29","kind":"advisory","version":"4.16.1.3-29.amzn2023.0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857},{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"risk":0.14775000000000002,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3125.html","description":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball. (CVE-2026-78367)A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. (CVE-2026-84233)"},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},{"id":"CVE-2026-84233","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"urls":["https://access.redhat.com/errata/RHSA-2026:66637","https://access.redhat.com/security/cve/CVE-2026-84233","https://bugzilla.redhat.com/show_bug.cgi?id=2478409"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84233","description":"A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability."}]},{"artifact":{"id":"d18dbcf8914e3542","cpes":["cpe:2.3:a:amazonlinux:rpm-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:rpm_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/amzn/rpm-libs@4.16.1.3-29.amzn2023.0.7?arch=x86_64&distro=amzn-2023&upstream=rpm-4.16.1.3-29.amzn2023.0.7.src.rpm","type":"rpm","version":"4.16.1.3-29.amzn2023.0.7","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm-libs","version":"0:4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3125","fix":{"state":"fixed","versions":["4.16.1.3-29.amzn2023.0.8"],"available":[{"date":"2026-09-29","kind":"advisory","version":"4.16.1.3-29.amzn2023.0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857},{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"risk":0.14775000000000002,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3125.html","description":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball. (CVE-2026-78367)A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. (CVE-2026-84233)"},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},{"id":"CVE-2026-84233","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"urls":["https://access.redhat.com/errata/RHSA-2026:66637","https://access.redhat.com/security/cve/CVE-2026-84233","https://bugzilla.redhat.com/show_bug.cgi?id=2478409"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84233","description":"A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability."}]},{"artifact":{"id":"06a3ecdfe2ac244b","cpes":["cpe:2.3:a:rpm-sign-libs:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-sign-libs:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_sign_libs:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_sign_libs:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-sign:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm-sign:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_sign:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm_sign:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-sign-libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_sign_libs:4.16.1.3-29.amzn2023.0.7:*:*:*:*:*:*:*"],"name":"rpm-sign-libs","purl":"pkg:rpm/amzn/rpm-sign-libs@4.16.1.3-29.amzn2023.0.7?arch=x86_64&distro=amzn-2023&upstream=rpm-4.16.1.3-29.amzn2023.0.7.src.rpm","type":"rpm","version":"4.16.1.3-29.amzn2023.0.7","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm-sign-libs","version":"0:4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"4.16.1.3-29.amzn2023.0.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3125","versionConstraint":"< 4.16.1.3-29.amzn2023.0.8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"rpm","version":"4.16.1.3-29.amzn2023.0.7"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3125","fix":{"state":"fixed","versions":["4.16.1.3-29.amzn2023.0.8"],"available":[{"date":"2026-09-29","kind":"advisory","version":"4.16.1.3-29.amzn2023.0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857},{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"risk":0.14775000000000002,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3125.html","description":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball. (CVE-2026-78367)A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. (CVE-2026-84233)"},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},{"id":"CVE-2026-84233","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84233","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84233","date":"2026-10-08","epss":0.00194,"percentile":0.08303}],"urls":["https://access.redhat.com/errata/RHSA-2026:66637","https://access.redhat.com/security/cve/CVE-2026-84233","https://bugzilla.redhat.com/show_bug.cgi?id=2478409"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84233","description":"A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability."}]},{"artifact":{"id":"dd5bb59826e63cc9","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.2:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.2","type":"java-archive","version":"1.11.2","language":"java","licenses":["Apache License, Version 2.0;link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"3fe7cb28a7102752d77c3aa4e309ea76efe85def","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"e4b33c1eb66a7e2a","cpes":["cpe:2.3:a:amazonlinux:pcre2:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/amzn/pcre2@10.40-1.amzn2023.0.3?arch=x86_64&distro=amzn-2023&upstream=pcre2-10.40-1.amzn2023.0.3.src.rpm","type":"rpm","version":"10.40-1.amzn2023.0.3","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.40-1.amzn2023.0.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3119","versionConstraint":"< 10.40-1.amzn2023.0.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"pcre2","version":"0:10.40-1.amzn2023.0.3"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3119","fix":{"state":"fixed","versions":["10.40-1.amzn2023.0.4"],"available":[{"date":"2026-09-29","kind":"advisory","version":"10.40-1.amzn2023.0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09450000000000001,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3119.html","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. (CVE-2026-89161)"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"1d8e822edb17a6bf","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:pcre2-syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:amazonlinux:pcre2_syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-1.amzn2023.0.3:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/amzn/pcre2-syntax@10.40-1.amzn2023.0.3?arch=noarch&distro=amzn-2023&upstream=pcre2-10.40-1.amzn2023.0.3.src.rpm","type":"rpm","version":"10.40-1.amzn2023.0.3","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:05d410e3ff09627a4127610540d1abe3f97279b15b199a9e5c66252e4c4870b8","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-1.amzn2023.0.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.40-1.amzn2023.0.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"ALAS2023-2026-3119","versionConstraint":"< 10.40-1.amzn2023.0.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"pcre2-syntax","version":"0:10.40-1.amzn2023.0.3"},"namespace":"amazon:distro:amazonlinux:2023"}},{"fix":{"suggestedVersion":"10.40-1.amzn2023.0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"ALAS2023-2026-3119","versionConstraint":"< 10.40-1.amzn2023.0.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"amazonlinux","version":"2023"},"package":{"name":"pcre2","version":"10.40-1.amzn2023.0.3"},"namespace":"amazon:distro:amazonlinux:2023"}}],"vulnerability":{"id":"ALAS2023-2026-3119","fix":{"state":"fixed","versions":["10.40-1.amzn2023.0.4"],"available":[{"date":"2026-09-29","kind":"advisory","version":"10.40-1.amzn2023.0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09450000000000001,"urls":[],"severity":"High","namespace":"amazon:distro:amazonlinux:2023","advisories":[],"dataSource":"https://alas.aws.amazon.com/AL2023/ALAS2023-2026-3119.html","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. (CVE-2026-89161)"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"464f008cd78794d6","cpes":["cpe:2.3:a:org.jline.reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline.reader:reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-reader:reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:reader:reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:reader:3.21.0:*:*:*:*:*:*:*"],"name":"jline-reader","purl":"pkg:maven/org.jline/jline-reader@3.21.0","type":"java-archive","version":"3.21.0","language":"java","licenses":["https://opensource.org/licenses/BSD-3-Clause"],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-reader-3.21.0.jar","manifestName":"","pomArtifactID":"jline-reader","archiveDigests":[{"value":"9cd5c76dd2a47e9e0e7ab39821c0f62fa46e8581","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-ml/jline-reader-3.21.0.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-ml/jline-reader-3.21.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5q95-hrpc-m3w3","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-reader","version":"3.21.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5q95-hrpc-m3w3","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"risk":0.06457500000000001,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5q95-hrpc-m3w3","description":"JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable"},"relatedVulnerabilities":[{"id":"CVE-2026-77420","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77420","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"dd5bb59826e63cc9","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.2:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.2","type":"java-archive","version":"1.11.2","language":"java","licenses":["Apache License, Version 2.0;link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"3fe7cb28a7102752d77c3aa4e309ea76efe85def","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","layerID":"sha256:706c3dbb3c2c76f39ab5ee4403eed9dcd6c2e297950ca6c0e100e3472c02a07d","accessPath":"/usr/share/opensearch/plugins/opensearch-security/lz4-java-1.11.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:27:50.526Z","grype_db_version":"2026-10-09T06:32:32.000Z"}