Skip to content

Jackson Release 3.1.6

Tatu Saloranta edited this page Aug 14, 2026 · 40 revisions

Patch version of 3.1, released on August 14, 2026.

Following fixes are included in this patch release.

Changes, core

  • #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
  • #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser [CVE-2026-68498]
  • #1651: Fix object context handling for buffered INCLUDE_NON_NULL tokens
  • #6096: Honor @JsonView in BeanAsArrayDeserializer update path
  • #6099: Resolve classes without initialization in TypeFactory.findClass()
  • #6109: Mark built-in JDK 8 handlers as Jackson standard implementations
  • #6115: Honor @JsonIgnoreProperties before any-setter on more deser paths
  • #6116: Reject non-ASCII digits in InetAddress literal validation
  • #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.GregorianCalendar and javax.xml.datatype.Duration [CVE-2026-68497]
  • #6129: Limit the supported URL schemes for java.nio.file.Path deserialization [CVE-2026-19032]
  • #6133: Limit number sizes allowed in java.time.Instant deserializer
  • #6137: DefaultCacheProvider.Builder does not preserve default cache sizes for unspecified values
  • #6155: Add java.lang.Comparable as an "unsafe" polymorphic base type
  • #6165: Apply number length limits to BigDecimal/BigInteger/Double/Float Map keys

Changes, dataformats

CBOR

  • #725: Ensure maxNameLength limit enforced for CBOR parser [CVE-2026-68495]
  • #727: CBORParser.nextFieldName(SerializableString) confuses 5-bit length marker 23 with 24 ("1-byte length follows")
  • #728: CBORParser.nextFieldName(SerializableString) consumes Object entry slot twice on fast-path miss, truncating definite-length Objects
  • #735: "stringref" property-name paths pass 5-bit length marker instead of actual length to shouldReferenceString()
  • #736: Long Object property names added to "stringref" reference table twice
  • #742: Use ArrayDeque instead of Stack in CBORParser

Protobuf

  • #708: Proto3 fields without label fail to parse
  • #712: Support protobuf map type idiomatically
  • #714: Packed repeated field fails to decode when array spans an input buffer reload
  • #715: ProtobufGenerator._reportWrongWireType() always reports string, ignoring actual type

Smile

  • #720: SmileGenerator writes past output buffer (ArrayIndexOutOfBoundsException) for very long Strings due to int overflow in maxLen
  • #726: Ensure maxNameLength limit enforced for Smile parser [CVE-2026-68496]

TOML

  • #702: Expand TOML dotted key nesting checks

XML

  • #891: Enforce StreamReadConstraints.maxNestingDepth in FromXmlParser

YAML

  • #701: ALWAYS_QUOTE_NUMBERS_AS_STRINGS does not quote YAML 1.1 exponent (1e5), hex (0x1F) and underscore (12_34) number forms
  • #707: Should constraint deeply nested YAML merge keys in YAMLAnchorReplayingParser [GHSA-255r-36wv-4qpr]

Changes, Other modules

Blackbird

  • #355: Blackbird silently reverts Optional (reference-type) properties to reflection MethodProperty: Jdk8OptionalDeserializer fails isDefaultDeserializer check

Clone this wiki locally