CVE-2026-86321Medium· 5.3▾ TwilightPoC availableA vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulat…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86511Medium· 5.3A vulnerability was found in java-json-tools jackson-coreutils 2.0
CVE-2026-86513Medium· 5.3A security flaw has been discovered in java-json-tools jackson-coreutils 2.0
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-86512Medium· 6.3A vulnerability was identified in java-json-tools json-patch up to 1.13
CVE-2026-86319Medium· 5.3A vulnerability has been found in java-json-tools json-patch up to 1.13
CVE-2026-86318Medium· 5.3A flaw has been found in java-json-tools json-patch up to 1.13