openSUSE 16: jackson-annotations / jackson-annotations-javadoc / jackson-core / etc (openSUSE-SU-2026:22034-1)

high Nessus Plugin ID 364341

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:22034-1 advisory.

- CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
- CVE-2026-19032: deserializer for `java.nio.file.Path` resolves attacker-supplied URIs without restricting the URI scheme (bsc#1277883).
- CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
- CVE-2026-68497: An unauthenticated attacker can therefore submit a single request of a few megabytes (bsc#1280125).
- CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
- CVE-2026-83557: incomplete `PolymorphicTypeValidator` denylist allows for arbitrary `Comparable` deserialization (bsc#1278008).
- CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
- CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks `maxErrorTokenLength` limit, which allows for unbounded `StringBuilder` growth and can lead to a DoS when malformed tokens are processed (bsc#1282505).
- CVE-2026-91776: `TypeDeserializerBase._findDeserializer()` caches the resolved deserializer under the raw, attacker- supplied type ID, which can lead to unbounded cache growth under certain configurations (bsc#1282491).
- CVE-2026-91777: forward-reference completion for `@JsonIdentityInfo` object IDs performs a linear scan of the pending- reference accumulator for every resolved ID, which can lead to quadratic CPU work during deserialization (bsc#1282492).

Changes for jackson-annotations:

- Update to 2.18.11

Changes for jackson-core:

- Update to 2.18.11
* #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
* #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
* #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
* #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)

Changes for jackson-databind:

- Update to 2.18.11
* #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
* #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
* #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
* #6099: Resolve classes without initialization in TypeFactory.findClass()
* #6116: Reject non-ASCII digits in InetAddress literal validation
* #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
* #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
* #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
* #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1273856

https://bugzilla.suse.com/1273857

https://bugzilla.suse.com/1277883

https://bugzilla.suse.com/1278008

https://bugzilla.suse.com/1280125

https://bugzilla.suse.com/1282491

https://bugzilla.suse.com/1282492

https://bugzilla.suse.com/1282505

https://bugzilla.suse.com/1282641

https://bugzilla.suse.com/1282645

https://www.suse.com/security/cve/CVE-2026-18401

https://www.suse.com/security/cve/CVE-2026-19032

https://www.suse.com/security/cve/CVE-2026-68494

https://www.suse.com/security/cve/CVE-2026-68497

https://www.suse.com/security/cve/CVE-2026-68498

https://www.suse.com/security/cve/CVE-2026-83557

https://www.suse.com/security/cve/CVE-2026-89407

https://www.suse.com/security/cve/CVE-2026-89425

https://www.suse.com/security/cve/CVE-2026-91776

https://www.suse.com/security/cve/CVE-2026-91777

Plugin Details

Severity: High

ID: 364341

File Name: openSUSE-2026-22034-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/9/2026

Updated: 10/9/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.18

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-83557

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-68494

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:jackson-annotations-javadoc, p-cpe:/a:novell:opensuse:jackson-annotations, p-cpe:/a:novell:opensuse:jackson-core-javadoc, p-cpe:/a:novell:opensuse:jackson-core, p-cpe:/a:novell:opensuse:jackson-databind-javadoc, p-cpe:/a:novell:opensuse:jackson-databind

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 2/28/2026

Reference Information

CVE: CVE-2026-18401, CVE-2026-19032, CVE-2026-68494, CVE-2026-68497, CVE-2026-68498, CVE-2026-83557, CVE-2026-89407, CVE-2026-89425, CVE-2026-91776, CVE-2026-91777