Core Jackson processing abstractions (aka Streaming API), implementation for JSON
94%
Total Score
healthy
Healthy: sustained maintenance, organizational backing, and signed Maven provenance make this a strong dependency choice.
All health scores are okay.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-665392 New jackson-core is vulnerable to Denial of Service (DoS) in versions 2.15.0 - 2.18.7 and 2.19.0 - 2.21.3. | 2.15.0 - 2.18.72.19.0 - 2.21.3 | High |
CVE-2026-89425 New com.fasterxml.jackson.core:jackson-core is vulnerable to Uncontrolled Resource Consumption in versions 2.19.0 - 2.21.6, 2.22.0 - 2.22.2 and 2.8.0 - 2.18.10. | 2.8.0 - 2.18.102.19.0 - 2.21.62.22.0 - 2.22.2 | High |
CVE-2026-89407 New com.fasterxml.jackson.core:jackson-core is vulnerable to Uncontrolled Resource Consumption in versions 2.17.0 - 2.18.10, 2.19.0 - 2.21.6 and 2.22.0 - 2.22.2. | 2.17.0 - 2.18.102.19.0 - 2.21.62.22.0 - 2.22.2 | High |
CVE-2025-52999 com.fasterxml.jackson.core:jackson-core is vulnerable to Stack-based Buffer Overflow in versions 0.0.0 - 2.15.0. | 0.0.0 - 2.15.0 | High |
CVE-2025-49128 com.fasterxml.jackson.core:jackson-core is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.0.0 - 2.13.0. | 2.0.0 - 2.13.0 | Medium |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.