CVE-2026-68496

CVE-2026-68496 published: The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows ...

View full NVD advisory → ← Back to CVE watch