Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:22034-1 advisory.
- CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
- CVE-2026-19032: deserializer for `java.nio.file.Path` resolves attacker-supplied URIs without restricting the URI scheme (bsc#1277883).
- CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
- CVE-2026-68497: An unauthenticated attacker can therefore submit a single request of a few megabytes (bsc#1280125).
- CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
- CVE-2026-83557: incomplete `PolymorphicTypeValidator` denylist allows for arbitrary `Comparable` deserialization (bsc#1278008).
- CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
- CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks `maxErrorTokenLength` limit, which allows for unbounded `StringBuilder` growth and can lead to a DoS when malformed tokens are processed (bsc#1282505).
- CVE-2026-91776: `TypeDeserializerBase._findDeserializer()` caches the resolved deserializer under the raw, attacker- supplied type ID, which can lead to unbounded cache growth under certain configurations (bsc#1282491).
- CVE-2026-91777: forward-reference completion for `@JsonIdentityInfo` object IDs performs a linear scan of the pending- reference accumulator for every resolved ID, which can lead to quadratic CPU work during deserialization (bsc#1282492).
Changes for jackson-annotations:
- Update to 2.18.11
Changes for jackson-core:
- Update to 2.18.11
* #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
* #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
* #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
* #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)
Changes for jackson-databind:
- Update to 2.18.11
* #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
* #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
* #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
* #6099: Resolve classes without initialization in TypeFactory.findClass()
* #6116: Reject non-ASCII digits in InetAddress literal validation
* #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
* #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
* #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
* #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: openSUSE-2026-22034-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:jackson-annotations-javadoc, p-cpe:/a:novell:opensuse:jackson-annotations, p-cpe:/a:novell:opensuse:jackson-core-javadoc, p-cpe:/a:novell:opensuse:jackson-core, p-cpe:/a:novell:opensuse:jackson-databind-javadoc, p-cpe:/a:novell:opensuse:jackson-databind
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 10/6/2026
Vulnerability Publication Date: 2/28/2026