CVE-2026-54514Medium· 5.3▾ SunlitA flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.4%
Last analysed / modified upstream
A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JSON input containing specific network address information is processed, potentially leading to the disclosure of sensitive network configuration details.
jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution — rated Moderate by Red Hat. Released 2026-06-23, updated 2026-09-13.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Affected packages:
com.fasterxml.jackson.core:jackson-databind >= 2.0.0, < 2.18.8com.fasterxml.jackson.core:jackson-databind >= 2.19.0, < 2.21.4com.fasterxml.jackson.core:jackson-databind >= 3.0.0, < 3.1.4tools.jackson.core:jackson-databind >= 2.19.0, < 2.21.4tools.jackson.core:jackson-databind >= 3.0.0, < 3.1.4Patched in:
com.fasterxml.jackson.core:jackson-databind 2.18.8com.fasterxml.jackson.core:jackson-databind 2.21.4com.fasterxml.jackson.core:jackson-databind 3.1.4tools.jackson.core:jackson-databind 2.21.4tools.jackson.core:jackson-databind 3.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84377Medium· 6.5LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-78682High· 7.5nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)
CVE-2026-75899High· 7.5fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
CVE-2026-75975High· 7.5fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
CVE-2026-57516High· 8.8ray: Ray: Remote code execution via unsafe deserialization in WebDataset reader (CVE-2026-57516)
CVE-2026-56816High· 7.5io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)