| Release | Version |
|---|---|
| bullseye | 2.12.1-1 |
| bullseye (security) | 2.14.1-2~deb11u1 |
| bookworm | 2.14.1-2~deb12u1 |
| trixie | 2.14.1-2~deb13u1 |
| forky | 2.14.1-2 |
| sid | 2.14.1-2 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-18401 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | The non-blocking (asynchronous) JSON parser in jackson-core does not e ... |
| Bug | Description |
|---|---|
| CVE-2026-68494 | The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 ... |
| CVE-2026-29062 | jackson-core contains core low-level incremental ("streaming") parser ... |
| CVE-2025-52999 | jackson-core contains core low-level incremental ("streaming") parser ... |
| CVE-2025-49128 | Jackson-core contains core low-level incremental ("streaming") parser ... |
| DSA / DLA | Description |
|---|---|
| DSA-6336-1 | jackson-core - security update |
| DLA-4623-1 | jackson-core - security update |