Visit NES for Jackson Home Page
NES for Jackson Databind 2.13.x Release Notes
6 versions
Comprehensive release notes and changelog for NES for Jackson Databind 2.13.x, including security patches, bug fixes, and feature updates across all supported versions.
September 2026
2.13.12
Released Sep 24, 2026 Full Version:
2.13.5-jackson-databind-2.13.12
Security Fixes
This release patches the following:
- CVE-2026-91776: bound the number and size of retained polymorphic type identifiers in TypeDeserializerBase
- CVE-2026-91777: avoid quadratic object-ID comparisons in CollectionReferringAccumulator and MapReferringAccumulator on reverse-order forward references
Dependency Upgrades
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.12
2.13.11
Released Sep 10, 2026 Full Version:
2.13.5-jackson-databind-2.13.11
Security Fixes
This release patches the following:
- CVE-2026-68497: enforce number-length limits when deserializing Duration and XMLGregorianCalendar
- CVE-2026-77310: disable DNS resolution when deserializing InetAddress
Dependency Upgrades
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.11
2.13.10
Released Sep 4, 2026 Full Version:
2.13.5-jackson-databind-2.13.10
Security Fixes
This release patches the following:
- CVE-2026-19032: restrict URL schemes in java.nio.file.Path deserialization
- CVE-2026-83557: include java.lang.Comparable in the unsafe base-type denylist
Dependency Upgrades
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.10
July 2026
2.13.9
Released Jul 26, 2026 Full Version:
2.13.5-jackson-databind-2.13.9
Dependency Upgrades
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.9
2.13.8
Released Jul 2, 2026 Full Version:
2.13.5-jackson-databind-2.13.8
Security Fixes
This release patches the following:
- CVE-2026-50193: avoid recursive JsonNode string serialization
- CVE-2026-54512: validate polymorphic generic type parameters
- CVE-2026-54513: validate array component subtype in BasicPolymorphicTypeValidator
- CVE-2026-54514: avoid eager DNS lookup in InetSocketAddress deserialization
- CVE-2026-54515: case-insensitive deserialization ignores per-property @JsonIgnoreProperties
- CVE-2026-54516: renamed @JsonIgnore'd setters can deserialize via private fields
- CVE-2026-54517: apply active @JsonView filter in property-based deserialization
Dependency Updates
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.8 - Jackson Annotations (NES)
2.13.5-jackson-annotations-2.13.8 - Jackson Core (NES)
2.13.5-jackson-core-2.13.8
September 2025
2.13.6
Released Sep 25, 2025 Full Version:
2.13.5-jackson-databind-2.13.6
Notes
- This release originates from the open‑source jackson-databind project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
Dependency Updates
- Jackson BOM (NES)
2.13.5-jackson-bom-2.13.6
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh