java-json-tools has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-400 (3). Most affected products: jackson-coreutils (3), json-patch (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Products
- jackson-coreutils 3
- json-patch 3
Worst active — by depth score
CVE-2026-86512Medium· 6.3A vulnerability was identified in java-json-tools json-patch up to 1.1347CVE-2026-86513Medium· 5.3A security flaw has been discovered in java-json-tools jackson-coreutils 2.041CVE-2026-86511Medium· 5.3A vulnerability was found in java-json-tools jackson-coreutils 2.041CVE-2026-86321Medium· 5.3A vulnerability was found in java-json-tools jackson-coreutils 2.041CVE-2026-86319Medium· 5.3A vulnerability has been found in java-json-tools json-patch up to 1.1341
java-json-tools vulnerabilities
CVEs affecting java-json-tools, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-86513Medium· 5.3PoCA security flaw has been discovered in java-json-tools jackson-coreutils 2.0
A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the compon…
CVE-2026-86512Medium· 6.3PoCA vulnerability was identified in java-json-tools json-patch up to 1.13
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move O…
CVE-2026-86511Medium· 5.3PoCA vulnerability was found in java-json-tools jackson-coreutils 2.0
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation res…
CVE-2026-86321Medium· 5.3PoCA vulnerability was found in java-json-tools jackson-coreutils 2.0
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulat…
CVE-2026-86319Medium· 5.3PoCA vulnerability has been found in java-json-tools json-patch up to 1.13
A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Ha…
CVE-2026-86318Medium· 5.3PoCA flaw has been found in java-json-tools json-patch up to 1.13
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…