-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Jackson Release 3.1.6
Tatu Saloranta edited this page Aug 14, 2026
·
40 revisions
Patch version of 3.1, released on August 14, 2026.
Following fixes are included in this patch release.
- #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
- #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser [CVE-2026-68498]
-
#1651: Fix object context handling for buffered
INCLUDE_NON_NULLtokens
-
#6096: Honor
@JsonViewinBeanAsArrayDeserializerupdate path -
#6099: Resolve classes without initialization in
TypeFactory.findClass() - #6109: Mark built-in JDK 8 handlers as Jackson standard implementations
-
#6115: Honor
@JsonIgnorePropertiesbefore any-setter on more deser paths -
#6116: Reject non-ASCII digits in
InetAddressliteral validation -
#6127: Add
StreamReadConstraintsnumber len constraint tojavax.xml.datatype.GregorianCalendarandjavax.xml.datatype.Duration[CVE-2026-68497] -
#6129: Limit the supported URL schemes for
java.nio.file.Pathdeserialization [CVE-2026-19032] -
#6133: Limit number sizes allowed in
java.time.Instantdeserializer -
#6137:
DefaultCacheProvider.Builderdoes not preserve default cache sizes for unspecified values -
#6155: Add
java.lang.Comparableas an "unsafe" polymorphic base type -
#6165: Apply number length limits to
BigDecimal/BigInteger/Double/FloatMap keys
-
#725: Ensure
maxNameLengthlimit enforced for CBOR parser [CVE-2026-68495] -
#727:
CBORParser.nextFieldName(SerializableString)confuses 5-bit length marker 23 with 24 ("1-byte length follows") -
#728:
CBORParser.nextFieldName(SerializableString)consumes Object entry slot twice on fast-path miss, truncating definite-length Objects -
#735: "stringref" property-name paths pass 5-bit length marker instead of actual length to
shouldReferenceString() - #736: Long Object property names added to "stringref" reference table twice
-
#742: Use
ArrayDequeinstead ofStackinCBORParser
- #708: Proto3 fields without label fail to parse
-
#712: Support protobuf
maptype idiomatically - #714: Packed repeated field fails to decode when array spans an input buffer reload
-
#715: ProtobufGenerator._reportWrongWireType() always reports
string, ignoring actual type
-
#720:
SmileGeneratorwrites past output buffer (ArrayIndexOutOfBoundsException) for very long Strings due to int overflow in maxLen -
#726: Ensure
maxNameLengthlimit enforced for Smile parser [CVE-2026-68496]
- #702: Expand TOML dotted key nesting checks
-
#891: Enforce
StreamReadConstraints.maxNestingDepthinFromXmlParser
-
#701:
ALWAYS_QUOTE_NUMBERS_AS_STRINGSdoes not quote YAML 1.1 exponent (1e5), hex (0x1F) and underscore (12_34) number forms -
#707: Should constraint deeply nested YAML merge keys in
YAMLAnchorReplayingParser[GHSA-255r-36wv-4qpr]
- #355: Blackbird silently reverts Optional (reference-type) properties to reflection MethodProperty: Jdk8OptionalDeserializer fails isDefaultDeserializer check