FlawAtlas
Search the atlas
CVE-2020-28491 High

Denial of Service (DoS) in Jackson Dataformat CBOR

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 2.8.0-rc1 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

Exploit probability 3.1%
Published December 9, 2021
Required by Not available
Last source change March 13, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

31 explicit affected versions

Maven com.fasterxml.jackson.dataformat:jackson-dataformat-cbor

46 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-28491

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

View original source
Open Source Vulnerabilities GHSA-xmc8-26q4-qjhx

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 2.8.0-rc1 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

View original source

05 / REFERENCES

Further evidence