{"id":"CVE-2020-28491","aliases":["GHSA-xmc8-26q4-qjhx"],"url":"https://o3.security/vulnerability/CVE-2020-28491","summary":"Denial of Service (DoS) in Jackson Dataformat CBOR","details":"This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.","published":"2021-02-18T16:15:13.207Z","modified":"2026-07-08T19:44:04.183786Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.03074,"percentile":0.86599,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","fixedVersion":"2.11.4"},{"ecosystem":"Maven","name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","fixedVersion":"2.12.1"}],"fix":{"url":"https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6","label":"FasterXML/jackson-dataformats-binary@de072d3"},"references":[{"type":"FIX","url":"https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-dataformats-binary/issues/186"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:44:04.183786Z"}}