-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Jackson Release 2.21.6
Tatu Saloranta edited this page Aug 15, 2026
·
39 revisions
Patch version of 2.21, released on August 14, 2026.
Following fixes are included in this patch release.
- #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
- #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser [CVE-2026-68498]
-
#1651: Fix object context handling for buffered
INCLUDE_NON_NULLtokens
-
#6099: Resolve classes without initialization in
TypeFactory.findClass() -
#6101:
@JsonInclude(NON_EMPTY, content=CUSTOM)does not omit a Map property after all entries are filtered -
#6116: Reject non-ASCII digits in
InetAddressliteral validation -
#6127: Add
StreamReadConstraintsnumber len constraint tojavax.xml.datatype.GregorianCalendarandjavax.xml.datatype.Duration[CVE-2026-68497] -
#6129: Limit the supported URL schemes for
java.nio.file.Pathdeserialization [CVE-2026-19032] -
#6155: Add
java.lang.Comparableas an "unsafe" polymorphic base type -
#6165: Apply number length limits to
BigDecimal/BigInteger/Double/FloatMap keys
-
#725: Ensure
maxNameLengthlimit enforced for CBOR parser [CVE-2026-68495] -
#727:
CBORParser.nextFieldName(SerializableString)confuses 5-bit length marker 23 with 24 ("1-byte length follows") -
#728:
CBORParser.nextFieldName(SerializableString)consumes Object entry slot twice on fast-path miss, truncating definite-length Objects -
#735: "stringref" property-name paths pass 5-bit length marker instead of actual length to
shouldReferenceString() - #736: Long Object property names added to "stringref" reference table twice
- #708: Proto3 fields without label fail to parse
-
#712: Support protobuf
maptype idiomatically - #714: Packed repeated field fails to decode when array spans an input buffer reload
-
#715: ProtobufGenerator._reportWrongWireType() always reports
string, ignoring actual type
-
#720:
SmileGeneratorwrites past output buffer (ArrayIndexOutOfBoundsException) for very long Strings due to int overflow in maxLen -
#726: Ensure
maxNameLengthlimit enforced for Smile parser [CVE-2026-68496]
- #702: Expand TOML dotted key nesting checks
-
#891: Enforce
StreamReadConstraints.maxNestingDepthinFromXmlParser
-
#624:
YAMLAnchorReplayingParserproduces invalid sequence of events when using the merge operator inside an anchor -
#701:
ALWAYS_QUOTE_NUMBERS_AS_STRINGSdoes not quote YAML 1.1 exponent (1e5), hex (0x1F) and underscore (12_34) number forms -
#707: Should constraint deeply nested YAML merge keys in
YAMLAnchorReplayingParser[GHSA-255r-36wv-4qpr]
-
#387: Validate length of input in
InstantDeserializer