24h | 7d | 30d

Overview

  • FasterXML
  • jackson-core

25 Jun 2025
Published
25 Jun 2025
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.77%

KEV

Description

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • encoding/pem
  • encoding/pem

29 Oct 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.66%

KEV

Description

The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • html/template
  • html/template

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.39%

KEV

Description

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • archive/tar
  • archive/tar

08 Apr 2026
Published
13 Apr 2026
Updated

CVSS
Pending
EPSS
0.18%

KEV

Description

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/http/httputil
  • net/http/httputil

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.41%

KEV

Description

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&a2=x&...&a10000=x&hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • golang.org/x/net
  • golang.org/x/net/http2
  • golang.org/x/net/http2

07 May 2026
Published
18 Sep 2026
Updated

CVSS
Pending
EPSS
0.78%

KEV

Description

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net
  • net

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.62%

KEV

Description

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/http
  • net/http

29 Oct 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.56%

KEV

Description

Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go toolchain
  • cmd/compile
  • cmd/compile

08 Apr 2026
Published
13 Apr 2026
Updated

CVSS
Pending
EPSS
0.66%

KEV

Description

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/mail
  • net/mail

07 May 2026
Published
18 Sep 2026
Updated

CVSS
Pending
EPSS
0.80%

KEV

Description

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 3h ago
Showing 151 to 160 of 185 CVEs