---
id: CVE-2026-86513
title: A security flaw has been discovered in java-json-tools jackson-coreutils 2.0
summary: >-
  A security flaw has been discovered in java-json-tools jackson-coreutils 2.0.
  This vulnerability affects the function TreePointer.tokensFromInput of the
  file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the
  compon…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-770
vendor: java-json-tools
product: jackson-coreutils
affected:
  - jackson-coreutils 2.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T13:17:30.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86513'
references:
  - url: 'https://github.com/java-json-tools/jackson-coreutils/'
    label: cna@vuldb.com
  - url: 'https://github.com/java-json-tools/jackson-coreutils/issues/66'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86513'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908445'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399667'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399667/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/java-json-tools/jackson-coreutils/issues/66'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T12:27:47.023446Z'
epss: 0.00701
epssPercentile: 0.51298
ingestedAt: '2026-09-08T15:33:26.982Z'
---

## Overview

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
