vulnerability

Alma Linux: CVE-2025-52999: Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Jul 30, 2025
Added
Aug 11, 2025
Modified
Dec 17, 2025

Description

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Solutions

alma-upgrade-apache-commons-collectionsalma-upgrade-apache-commons-langalma-upgrade-apache-commons-netalma-upgrade-bea-stax-apialma-upgrade-fasterxml-oss-parentalma-upgrade-glassfish-fastinfosetalma-upgrade-glassfish-jaxb-apialma-upgrade-glassfish-jaxb-corealma-upgrade-glassfish-jaxb-runtimealma-upgrade-glassfish-jaxb-txw2alma-upgrade-jackson-annotationsalma-upgrade-jackson-bomalma-upgrade-jackson-corealma-upgrade-jackson-databindalma-upgrade-jackson-jaxrs-json-provideralma-upgrade-jackson-jaxrs-providersalma-upgrade-jackson-module-jaxb-annotationsalma-upgrade-jackson-modules-basealma-upgrade-jackson-parentalma-upgrade-jakarta-commons-httpclientalma-upgrade-javassistalma-upgrade-javassist-javadocalma-upgrade-pki-jackson-annotationsalma-upgrade-pki-jackson-corealma-upgrade-pki-jackson-databindalma-upgrade-pki-jackson-jaxrs-json-provideralma-upgrade-pki-jackson-jaxrs-providersalma-upgrade-pki-jackson-module-jaxb-annotationsalma-upgrade-pki-servlet-enginealma-upgrade-relaxngdatatypealma-upgrade-slf4jalma-upgrade-slf4j-jdk14alma-upgrade-stax-exalma-upgrade-velocityalma-upgrade-xalan-j2alma-upgrade-xerces-j2alma-upgrade-xml-commons-apisalma-upgrade-xml-commons-resolveralma-upgrade-xmlstreambufferalma-upgrade-xsom
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.