CVE-2016-7051: Fasterxml Jackson-Dataformat-XML
High severity, CVSS 8.6. EPSS: 2.4% chance of exploitation in the next 30 days.
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
Affected products
- Fasterxml Jackson-Dataformat-XML: before 2.7.8 (fixed in 2.7.8); version 2.8.0 only; version 2.8.1 only; version 2.8.2 only; version 2.8.3 only
Published 2017-04-14. Last modified 2026-06-17.