CVE-2020-28491: Fasterxml Jackson-Dataformats-Binary

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

Affected products

  • Fasterxml Jackson-Dataformats-Binary: before 2.11.4 (fixed in 2.11.4); after 2.12.0, before 2.12.1 (fixed in 2.12.1); version 2.12.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 14.1.1.0.0 only
  • Quarkus Quarkus: before 2.0.2 (fixed in 2.0.2)

Published 2021-02-18. Last modified 2026-06-17.