CVE-2020-28491: Fasterxml Jackson-Dataformats-Binary
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Affected products
- Fasterxml Jackson-Dataformats-Binary: before 2.11.4 (fixed in 2.11.4); after 2.12.0, before 2.12.1 (fixed in 2.12.1); version 2.12.0 only
- Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 14.1.1.0.0 only
- Quarkus Quarkus: before 2.0.2 (fixed in 2.0.2)
Published 2021-02-18. Last modified 2026-06-17.