CVE advisoryCRITICAL
CVE-2019-17267
FasterXML Jackson Databind Polymorphic Typing Vulnerability.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A polymorphic typing vulnerability in jackson-databind allows remote code execution via specially crafted data. This issue is relevant because the library is widely used in Java applications, potentially exposing systems to network-based attacks. Confirming usage and external data exposure is critical.