-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 13:27:34 +0200 Source: jackson-core Architecture: source Version: 2.14.1-2 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Closes: 1108367 Changes: jackson-core (2.14.1-2) unstable; urgency=medium . * Team upload. . [ Markus Koschany and Emmanuel Arias ] * CVE-2025-52999: A limit was added to avoid a StackoverflowError if the parsed JSON is very deeply nested. The StackoverflowError issue happens in jackson-databind but this change in jackson-core stops it from happening unless you increase the StreamReadConstraints.maxNestingDepth() to a high number. (Closes: #1108367). * Declare compliance with Debian Policy 4.7.4. Checksums-Sha1: e137e5ec89028f143a7c5376671cead9e44525ba 2375 jackson-core_2.14.1-2.dsc 517a2371a79892a77d9eec98b597368b5b9a2670 738136 jackson-core_2.14.1.orig.tar.xz 55a58c86b87389ef26542b487144ed4843be91e0 48968 jackson-core_2.14.1-2.debian.tar.xz 04e25c090af03ccfaebbe024d019be595043f419 15811 jackson-core_2.14.1-2_amd64.buildinfo Checksums-Sha256: 883f858940dd56aa6e2a4683bc1ffc02cbe354a01f6f3bf6a6116f0b9b67a6fa 2375 jackson-core_2.14.1-2.dsc d9eb6aa1898c4d5a582c52e69da249efae25e4d2c809c57dc6b6ee01c4b0fb3b 738136 jackson-core_2.14.1.orig.tar.xz 0c6e23f04491029793e574e543b476d7f2ee5143a1d6f852e96efa9c67364040 48968 jackson-core_2.14.1-2.debian.tar.xz 29b38f85a2799ca7cb6829d5cd3d214d374a4ce29b94c277d519eae6ca99c35b 15811 jackson-core_2.14.1-2_amd64.buildinfo Files: c0622dd9b76c815a45d3027dcac74174 2375 java optional jackson-core_2.14.1-2.dsc 38458c564bc7bed7e92d2cc2b46b1764 738136 java optional jackson-core_2.14.1.orig.tar.xz 9c40043876f1cc0fc9496e58a4dd9349 48968 java optional jackson-core_2.14.1-2.debian.tar.xz b421239da9b9216c15561276c9a4b4c2 15811 java optional jackson-core_2.14.1-2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmnf+OxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkKTYP+gP3IQBn3lC4eGe5TstH4Wg59alOf5ieoqTp Q1RsJ9JvZ6EFqEmTlvRCRKRN1NLYZwQc5mHFLblFVUIU1xAIXiI6PA3vD73ojJbX /6W3jMn8K+0cY1HFwgOw34ewQjDJ1Do47L6ij2GxJmTc1/rs3qQskG+ggxWZslkE cZVRABPiiwoNV7wjQM627FmpNSHP464PE+v3juHlUQYchPihtijBE6IYX5rPRm+z hyjhnHe7iqokiTKcCzHZMMcXhjmzr0tt9sSyyy/CRxMF54g36Czd+DnD8F9b76ZJ Hf/lQVRcKfWqpBx94M+juX8/SxAaSQBEm2HnAecpaU9m5nY6HSqRk3XvCdMf/Mfu URO9nC+6Cduycenjs/Vm8uRnAS5Qixw8V6E1XYA4z4bIzGYHiVjNzlN+3ROe/C/C qZSAugzqgGR/eG6Ex8c2Rjs9e/SiH+nuemXQXcsYsD0ICekeJAGmnyHp/RoeBwiG HX4ZM2fJIog+JT7rWXPTQvZmFyeFizZR23Rfoq3fiLpRpxBe+z6oVHN1MWeSGv02 D0Vag8oN/i76oaJalTsiIi9mMN1fMGT5RNTlWAaxMXq5uR6vrSi7rf5GKY2DRTst nJk9gWzqTZGsshmDawP80poAA/otNmhWPanxDWENlyxHQVQcDUR/QYKSIjjian4A EtTwIr3X =8z+I -----END PGP SIGNATURE-----