CVE-2026-18401 affects multiple packages. The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). See references for individual vulnerability details.