@JsonView by-passed for unwrapped creator parameters [CVE-2026-54518] by cowtowncoder · Pull Request #5971 · FasterXML/jackson-databind (original) (raw)

added 2 commits

May 6, 2026 18:06

@cowtowncoder

@cowtowncoder

@cowtowncoder

@cowtowncoder cowtowncoder deleted the tatu-claude/3.1/jdb07-jsonview-unwrapped-creators branch

May 7, 2026 01:26

cowtowncoder added a commit that referenced this pull request

May 22, 2026

@cowtowncoder @claude

Honor the active @JSONVIEW in every property-based-creator buffering path, not just the originally-patched ones (sibling of #5969/#5971):

Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com

cowtowncoder added a commit that referenced this pull request

May 22, 2026

@cowtowncoder

#6004)

Honor the active @JSONVIEW in every property-based-creator buffering path, not just the originally-patched ones from #5969/#5971

dongjoon-hyun added a commit to apache/spark that referenced this pull request

Jun 5, 2026

@dongjoon-hyun

@cowtowncoder cowtowncoder changed the title@JsonView by-passed for unwrapped creator parameters @JsonView by-passed for unwrapped creator parameters [CVE-2026-54518]

Jun 16, 2026

@cowtowncoder cowtowncoder added the CVE

Issues related to public CVEs (security vuln reports)

label

Jun 16, 2026

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})