Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Bedework: network utils

org.bedework:bw-util-network:6.2.2-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
bw-base-2.0.0.jarpkg:maven/org.bedework/bw-base@2.0.0 042
bw-util-config-6.1.1-SNAPSHOT.jarpkg:maven/org.bedework/bw-util-config@6.1.1-20260731.034129-4
pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
 043
bw-util-jmx-6.1.1-SNAPSHOT.jarpkg:maven/org.bedework/bw-util-jmx@6.1.1-20260731.034129-4
pkg:maven/org.bedework/bw-util-jmx@6.1.1-SNAPSHOT
 043
bw-util-logging-6.0.0.jarpkg:maven/org.bedework/bw-util-logging@6.0.0 044
bw-util-misc-6.1.1-SNAPSHOT.jarcpe:2.3:a:utils_project:utils:6.1.1:snapshot:*:*:*:*:*:*pkg:maven/org.bedework/bw-util-misc@6.1.1-20260731.033918-6
pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT
 0Low43
bw-util-properties-6.1.1-SNAPSHOT.jarcpe:2.3:a:com-property:com_properties:6.1.1:snapshot:*:*:*:*:*:*pkg:maven/org.bedework/bw-util-properties@6.1.1-20260731.033918-6
pkg:maven/org.bedework/bw-util-properties@6.1.1-SNAPSHOT
 0High43
bw-util-xml-6.1.1-SNAPSHOT.jarpkg:maven/org.bedework/bw-util-xml@6.1.1-20260731.033918-7
pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
 043
commons-beanutils-1.11.0.jarcpe:2.3:a:apache:commons_beanutils:1.11.0:*:*:*:*:*:*:*pkg:maven/commons-beanutils/commons-beanutils@1.11.0 0Highest170
commons-codec-1.17.1.jarpkg:maven/commons-codec/commons-codec@1.17.1 0121
commons-lang3-3.18.0.jarcpe:2.3:a:apache:commons_lang:3.18.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-lang3@3.18.0 0Highest145
commons-logging-1.2.jarpkg:maven/commons-logging/commons-logging@1.2 0117
commons-text-1.14.0.jarcpe:2.3:a:apache:commons_text:1.14.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-text@1.14.0 0Highest73
httpclient-4.5.14.jarcpe:2.3:a:apache:httpclient:4.5.14:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 0Highest32
httpcore-4.4.16.jarcpe:2.3:a:apache:httpcomponents_core:4.4.16:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpcore@4.4.16 0Highest32
jackson-core-2.18.2.jarcpe:2.3:a:fasterxml:jackson-core:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.2 0Highest47
jackson-databind-2.18.2.jarcpe:2.3:a:fasterxml:jackson-core:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2HIGH10Highest41
org.bedework:bw-util-http:6.2.2-SNAPSHOTpkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT 06
org.bedework:bw-util-servlet:6.2.2-SNAPSHOTpkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT 06

Dependencies (vulnerable)

bw-base-2.0.0.jar

Description:

This project provides base classes, types and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-base/2.0.0/bw-base-2.0.0.jar
MD5: 0480624145ad4fc5daeba898b7132099
SHA1: b24b7279e0475bb3c8c84e37af400ad87877c955
SHA256:10d27642e3bf1f2f4f85320293b5041b7e34cba02cc2656f29e79f75cee97cc5
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - jsp support:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-base-2.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

bw-util-config-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-config/6.1.1-SNAPSHOT/bw-util-config-6.1.1-SNAPSHOT.jar
MD5: 61c32d7d4fd7bf21cf1d77894056d81c
SHA1: 7591e566bc1a5af2d053980f7e779cfa0c89e6bd
SHA256:43891c2e6f645e8aad8d57168787d7605ba649702cb5f70fdae2cc3dbefa6a22
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-config-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

bw-util-jmx-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-jmx/6.1.1-SNAPSHOT/bw-util-jmx-6.1.1-SNAPSHOT.jar
MD5: 52c30ff87145d86270ca115cee31ed8a
SHA1: ce0cf95ed0c2e2bea8513c24485c985e7f2c8a6d
SHA256:cd2fa7373a7a97b8daada8e0fa3e946cc2907b21da1027a6d87f65d0793e769f
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-jmx-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

bw-util-logging-6.0.0.jar

Description:

This project provides logging utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-logging/6.0.0/bw-util-logging-6.0.0.jar
MD5: 2c63b9031e2d0852a00e57753320b409
SHA1: a12c15e6670f1298c8c4779d08b24595e921aceb
SHA256:e26bbaf5a5dcad998990fdc647f448b2e2dcac6eb628be6945fe24d53759b745
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-logging-6.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT

Identifiers

bw-util-misc-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-misc/6.1.1-SNAPSHOT/bw-util-misc-6.1.1-SNAPSHOT.jar
MD5: 8aac00a58e98664cf20c6e5b17ff57c4
SHA1: ea4e57f5835a8223d353bf6f1bf1c6d45bd73c62
SHA256:f078af029454c4347887d0289718b98bc9698d52728fa92bb42e16df75bb3f20
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-misc-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jmx@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT

Identifiers

bw-util-properties-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-properties/6.1.1-SNAPSHOT/bw-util-properties-6.1.1-SNAPSHOT.jar
MD5: b3f2fd0c2762ba293db56abbf9f395bd
SHA1: 3982a712ad3282658b2f83a7da8846c429f649cc
SHA256:1033989b15d79d888149fc44296ccc4886c744b6a11175e166c63c45cc3f6956
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-properties-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

bw-util-xml-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-xml/6.1.1-SNAPSHOT/bw-util-xml-6.1.1-SNAPSHOT.jar
MD5: e34452ab38c318cd68a18f81dbe227b7
SHA1: 4be260d343978c2838f13fab1e0e871d46292989
SHA256:72dcd6ce6e84a9cac0f193e164b9e8b3ce890897128c833cd881105ca67c9f50
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-xml-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT

Identifiers

commons-beanutils-1.11.0.jar

Description:

Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-beanutils/commons-beanutils/1.11.0/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256:9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Project/Scope: Bedework: network util - jsp support:compile
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT

Identifiers

commons-codec-1.17.1.jar

Description:

     The Apache Commons Codec component contains encoders and decoders for
     various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-codec/commons-codec/1.17.1/commons-codec-1.17.1.jar
MD5: 7b3438ab4c6d91e0066d410947e43f3e
SHA1: 973638b7149d333563584137ebf13a691bb60579
SHA256:f9f6cb103f2ddc3c99a9d80ada2ae7bf0685111fd6bffccb72033d1da4e6ff23
Referenced In Projects/Scopes:
  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

commons-codec-1.17.1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.apache.httpcomponents/httpclient@4.5.14
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

commons-lang3-3.18.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17 and 21 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.18.0/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256:4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jmx@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT

Identifiers

commons-logging-1.2.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256:daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Projects/Scopes:
  • Bedework: network util - http:compile
  • Bedework: network util - jsp support:compile
  • Bedework: network util - webbdav handling:compile

commons-logging-1.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.apache.httpcomponents/httpclient@4.5.14
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/commons-beanutils/commons-beanutils@1.11.0

Identifiers

commons-text-1.14.0.jar

Description:

Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256:121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

commons-text-1.14.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-jmx@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT

Identifiers

httpclient-4.5.14.jar

Description:

   Apache HttpComponents Client
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jar
MD5: 2cb357c4b763f47e58af6cad47df6ba3
SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98
SHA256:c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Referenced In Projects/Scopes:

  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

httpclient-4.5.14.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

httpcore-4.4.16.jar

Description:

   Apache HttpComponents Core (blocking I/O)
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jar
MD5: 28d2cd9bf8789fd2ec774fb88436ebd1
SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850
SHA256:6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Referenced In Projects/Scopes:

  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

httpcore-4.4.16.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

jackson-core-2.18.2.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.2/jackson-core-2.18.2.jar
MD5: bf935e6eca3a57defa13918661905cb0
SHA1: fb64ccac5c27dca8819418eb4e443a9f496d9ee7
SHA256:d8054ae7c0d1c2d2f55d28e46026ebe5892881f3fab5f439233184381c3b4a1f
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

jackson-core-2.18.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2
  • pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

jackson-databind-2.18.2.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.18.2/jackson-databind-2.18.2.jar
MD5: 1b56887bcd3eaea1ff710eb673e610b0
SHA1: deef8697b92141fb6caf7aa86966cff4eec9b04f
SHA256:4b364e6850dc89172fcf1d4dd26b8ff5488eda44ff4657e22dd265203dd5ab3c
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

jackson-databind-2.18.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

CVE-2026-68497 (OSSINDEX)  

jackson-databind - Allocation of Resources Without Limits or Throttling
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-54512  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-502 Deserialization of Untrusted Data, CWE-184 Incomplete List of Disallowed Inputs

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-54513  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-184 Incomplete List of Disallowed Inputs

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-19032 (OSSINDEX)  

com.fasterxml.jackson.core/jackson-databind - Unrestricted URI schemes in Path deserialization
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-54518 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://guide.sonatype.com/vulnerability/CVE-2026-54518 for details
CWE-863 Incorrect Authorization

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-77310 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.
CWE-918 Server-Side Request Forgery (SSRF)

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-59888 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-59889 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.
CWE-863 Incorrect Authorization

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-54514  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-918 Server-Side Request Forgery (SSRF)

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-54515  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

org.bedework:bw-util-http:6.2.2-SNAPSHOT

Description:

Network (http, DAV,servlet etc) related utilities

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-http/pom.xml

Referenced In Project/Scope: Bedework: network util - webbdav handling
org.bedework:bw-util-http:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT

Identifiers

org.bedework:bw-util-servlet:6.2.2-SNAPSHOT

Description:

Network (http, DAV,servlet etc) related utilities

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-servlet/pom.xml

Referenced In Project/Scope: Bedework: network util - servlet filters
org.bedework:bw-util-servlet:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.