Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Bedework: network utils

org.bedework:bw-util-network:6.2.2-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
bw-base-2.0.0.jarpkg:maven/org.bedework/bw-base@2.0.0 042
bw-util-config-6.1.0.jarpkg:maven/org.bedework/bw-util-config@6.1.0 044
bw-util-jmx-6.1.0.jarpkg:maven/org.bedework/bw-util-jmx@6.1.0 044
bw-util-logging-6.0.0.jarpkg:maven/org.bedework/bw-util-logging@6.0.0 044
bw-util-misc-6.1.1-SNAPSHOT.jarcpe:2.3:a:utils_project:utils:6.1.1:snapshot:*:*:*:*:*:*pkg:maven/org.bedework/bw-util-misc@6.1.1-20260527.022346-2
pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT
 0Low43
bw-util-properties-6.1.1-SNAPSHOT.jarcpe:2.3:a:com-property:com_properties:6.1.1:snapshot:*:*:*:*:*:*pkg:maven/org.bedework/bw-util-properties@6.1.1-20260527.022346-2
pkg:maven/org.bedework/bw-util-properties@6.1.1-SNAPSHOT
 0High43
bw-util-xml-6.1.1-SNAPSHOT.jarpkg:maven/org.bedework/bw-util-xml@6.1.1-20260527.022346-3
pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
 043
commons-beanutils-1.11.0.jarcpe:2.3:a:apache:commons_beanutils:1.11.0:*:*:*:*:*:*:*pkg:maven/commons-beanutils/commons-beanutils@1.11.0 0Highest170
commons-codec-1.17.1.jarpkg:maven/commons-codec/commons-codec@1.17.1 0121
commons-lang3-3.18.0.jarcpe:2.3:a:apache:commons_lang:3.18.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-lang3@3.18.0 0Highest145
commons-logging-1.2.jarpkg:maven/commons-logging/commons-logging@1.2 0117
commons-text-1.14.0.jarcpe:2.3:a:apache:commons_text:1.14.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-text@1.14.0 0Highest73
httpclient-4.5.14.jarcpe:2.3:a:apache:httpclient:4.5.14:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 0Highest32
httpcore-4.4.16.jarcpe:2.3:a:apache:httpcomponents_core:4.4.16:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpcore@4.4.16 0Highest32
jackson-core-2.18.2.jarcpe:2.3:a:fasterxml:jackson-core:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.2 0Highest47
jackson-databind-2.18.2.jarcpe:2.3:a:fasterxml:jackson-core:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2HIGH7Highest41
org.bedework:bw-util-http:6.2.2-SNAPSHOTpkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT 06
org.bedework:bw-util-servlet:6.2.2-SNAPSHOTpkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT 06

Dependencies (vulnerable)

bw-base-2.0.0.jar

Description:

This project provides base classes, types and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-base/2.0.0/bw-base-2.0.0.jar
MD5: 0480624145ad4fc5daeba898b7132099
SHA1: b24b7279e0475bb3c8c84e37af400ad87877c955
SHA256:10d27642e3bf1f2f4f85320293b5041b7e34cba02cc2656f29e79f75cee97cc5
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - jsp support:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-base-2.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.0
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

bw-util-config-6.1.0.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-config/6.1.0/bw-util-config-6.1.0.jar
MD5: 7db546c39232fd82b5d944d498618fe6
SHA1: b8e8a91513c79a8df1eec8c216afbd7b68599389
SHA256:360b90c0406fc847340472e7d3653f8c7c1aa2e6304fa748b15b9a89dd95c4c8
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-config-6.1.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

bw-util-jmx-6.1.0.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-jmx/6.1.0/bw-util-jmx-6.1.0.jar
MD5: 2c7532087d8a5fa7f422c3accd146533
SHA1: dbe25fb4201c3eea12f73efb8e07bb1616f2d567
SHA256:771ace3629d3cdec7238de84c96624d056e4afcdacf78bebf7a3aee3710ce81c
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-jmx-6.1.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

bw-util-logging-6.0.0.jar

Description:

This project provides logging utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-logging/6.0.0/bw-util-logging-6.0.0.jar
MD5: 2c63b9031e2d0852a00e57753320b409
SHA1: a12c15e6670f1298c8c4779d08b24595e921aceb
SHA256:e26bbaf5a5dcad998990fdc647f448b2e2dcac6eb628be6945fe24d53759b745
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-logging-6.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

bw-util-misc-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-misc/6.1.1-SNAPSHOT/bw-util-misc-6.1.1-SNAPSHOT.jar
MD5: d7b9b8fa6ba87568ef5f174ad292850b
SHA1: 149c399da656052d514c3afc073ce77ee39d3281
SHA256:61c456937882b1773120d6040af400d82c047e55646f7b6e7d8d3450f2988bfd
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-misc-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jmx@6.1.0
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

bw-util-properties-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-properties/6.1.1-SNAPSHOT/bw-util-properties-6.1.1-SNAPSHOT.jar
MD5: 0acb6f62930b18463a03b495ebfdbba7
SHA1: 75a0504b6bd1279d396c678c581d5d9de7adfbb8
SHA256:6c2edd36dcd8b50aedef25f90ca669ec9a8988f1a1439b2cc127282ffbfd1a96
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-properties-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-config@6.1.0
  • pkg:maven/org.bedework/bw-util-config@6.1.0
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

bw-util-xml-6.1.1-SNAPSHOT.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-xml/6.1.1-SNAPSHOT/bw-util-xml-6.1.1-SNAPSHOT.jar
MD5: a76e8bf313047b33086e2b425696fb50
SHA1: df59c3262834676cc0c2e764e0f7f9dfe515f35d
SHA256:12b8a71944d135c3676624a7b43741f20a044fb1dbb8c4ed40c138c6d16951ce
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

bw-util-xml-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.0
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-config@6.1.0

Identifiers

commons-beanutils-1.11.0.jar

Description:

Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-beanutils/commons-beanutils/1.11.0/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256:9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Project/Scope: Bedework: network util - jsp support:compile
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT

Identifiers

commons-codec-1.17.1.jar

Description:

     The Apache Commons Codec component contains encoders and decoders for
     various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-codec/commons-codec/1.17.1/commons-codec-1.17.1.jar
MD5: 7b3438ab4c6d91e0066d410947e43f3e
SHA1: 973638b7149d333563584137ebf13a691bb60579
SHA256:f9f6cb103f2ddc3c99a9d80ada2ae7bf0685111fd6bffccb72033d1da4e6ff23
Referenced In Projects/Scopes:
  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

commons-codec-1.17.1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.apache.httpcomponents/httpclient@4.5.14
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

commons-lang3-3.18.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17 and 21 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.18.0/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256:4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-jmx@6.1.0
  • pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT

Identifiers

commons-logging-1.2.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256:daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Projects/Scopes:
  • Bedework: network util - http:compile
  • Bedework: network util - jsp support:compile
  • Bedework: network util - webbdav handling:compile

commons-logging-1.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/commons-beanutils/commons-beanutils@1.11.0
  • pkg:maven/org.apache.httpcomponents/httpclient@4.5.14

Identifiers

commons-text-1.14.0.jar

Description:

Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256:121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

commons-text-1.14.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-jmx@6.1.0
  • pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

httpclient-4.5.14.jar

Description:

   Apache HttpComponents Client
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jar
MD5: 2cb357c4b763f47e58af6cad47df6ba3
SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98
SHA256:c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Referenced In Projects/Scopes:

  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

httpclient-4.5.14.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

httpcore-4.4.16.jar

Description:

   Apache HttpComponents Core (blocking I/O)
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jar
MD5: 28d2cd9bf8789fd2ec774fb88436ebd1
SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850
SHA256:6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Referenced In Projects/Scopes:

  • Bedework: network util - http:compile
  • Bedework: network util - webbdav handling:compile

httpcore-4.4.16.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

jackson-core-2.18.2.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.2/jackson-core-2.18.2.jar
MD5: bf935e6eca3a57defa13918661905cb0
SHA1: fb64ccac5c27dca8819418eb4e443a9f496d9ee7
SHA256:d8054ae7c0d1c2d2f55d28e46026ebe5892881f3fab5f439233184381c3b4a1f
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

jackson-core-2.18.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT

Identifiers

jackson-databind-2.18.2.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.18.2/jackson-databind-2.18.2.jar
MD5: 1b56887bcd3eaea1ff710eb673e610b0
SHA1: deef8697b92141fb6caf7aa86966cff4eec9b04f
SHA256:4b364e6850dc89172fcf1d4dd26b8ff5488eda44ff4657e22dd265203dd5ab3c
Referenced In Projects/Scopes:
  • Bedework: network util - servlet filters:compile
  • Bedework: network util - http:compile
  • Bedework: network util - servlet support:compile
  • Bedework: network util - webbdav handling:compile

jackson-databind-2.18.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT

Identifiers

CVE-2026-54512  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-502 Deserialization of Untrusted Data, CWE-184 Incomplete List of Disallowed Inputs

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-54513  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-184 Incomplete List of Disallowed Inputs

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-54518 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://guide.sonatype.com/vulnerability/CVE-2026-54518 for details
CWE-863 Incorrect Authorization

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-59888 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-59889 (OSSINDEX)  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.
CWE-863 Incorrect Authorization

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:*

CVE-2026-54514  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CWE-918 Server-Side Request Forgery (SSRF)

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-54515  

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

org.bedework:bw-util-http:6.2.2-SNAPSHOT

Description:

Network (http, DAV,servlet etc) related utilities

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-http/pom.xml

Referenced In Project/Scope: Bedework: network util - webbdav handling
org.bedework:bw-util-http:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT

Identifiers

org.bedework:bw-util-servlet:6.2.2-SNAPSHOT

Description:

Network (http, DAV,servlet etc) related utilities

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-servlet/pom.xml

Referenced In Project/Scope: Bedework: network util - servlet filters
org.bedework:bw-util-servlet:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.