Skip to content

[GHSA-72hv-8253-57qq] jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition - #8980

Closed
anthonydahanne wants to merge 1 commit into
anthonydahanne/advisory-improvement-8980from
anthonydahanne-GHSA-72hv-8253-57qq
Closed

[GHSA-72hv-8253-57qq] jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition#8980
anthonydahanne wants to merge 1 commit into
anthonydahanne/advisory-improvement-8980from
anthonydahanne-GHSA-72hv-8253-57qq

Conversation

@anthonydahanne

Copy link
Copy Markdown

Updates

  • References

Comments
Hello reviewers!
Requesting that the CVE ID for this advisory be set to CVE-2026-18401, assigned by HeroDevs (CNA, org 36c7be3b-2937-45df-85ea-ca7133ea542c) and published 2026-08-04. The CVE record cites this GHSA in its source.advisory field.

The advisory currently shows "No known CVE" and the OSV export in github/advisory-database has "aliases": [], so downstream consumers treat the GHSA and the CVE as two separate vulnerabilities. Setting the CVE ID would populate aliases and deduplicate them.

I have added the CVE record URL to the references, but the CVE ID field itself is not editable through this form

Thank you!

@github

github commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Hi there @cowtowncoder! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI balanced review requested due to automatic review settings August 4, 2026 19:52
@github-actions
github-actions Bot changed the base branch from main to anthonydahanne/advisory-improvement-8980 August 4, 2026 19:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a CVE.org reference for the jackson-core advisory, but does not associate the CVE alias.

Changes:

  • Updates the modification timestamp.
  • Adds the CVE-2026-18401 reference URL.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

},
{
"type": "WEB",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-18401"

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do the change

@anthonydahanne

Copy link
Copy Markdown
Author

super seeded with #8982

@github-actions
github-actions Bot deleted the anthonydahanne-GHSA-72hv-8253-57qq branch August 4, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants