Denial of Service via Unbounded Numeric Deserialization in Jackson Databind
A vulnerability in jackson-databind allows unauthenticated attackers to cause CPU exhaustion and denial of service by supplying specially crafted strings that bypass length constraints during XML datatype deserialization.
CVE search metadata
CVE search record: CVE-2026-68497. Severity: high. CVSS: 7.5. EPSS: 0.58%. KEV: no. Product: jackson-databind (>= 3.2.0, < 3.2.2), jackson-databind (>= 3.0.0, < 3.1.6), jackson-databind (>= 2.14.0, < 2.18.10), jackson-databind (>= 2.19.0, < 2.21.6), jackson-databind (>= 2.22.0, < 2.22.2). Brief: Denial of Service via Unbounded Numeric Deserialization in Jackson Databind. Brief link: https://feed.craftedsignal.io/briefs/2026-09-jackson-databind-dos/
Jackson-databind versions 3.2.1 and earlier, along with specific versions of the 2.x branch, contain a denial of service vulnerability (CVE-2026-68497) triggered by the deserialization of javax.xml.datatype.Duration and XMLGregorianCalendar objects. The library passes raw JSON string tokens directly to the JDK's DatatypeFactory.newDuration() or newXMLGregorianCalendar() methods without applying length validation. While jackson-core enforces a maxNumberLength constraint for JSON number tokens, this guard does not apply to digits encapsulated within a JSON string token.
Because the JDK materializes these numeric components into java.math.BigInteger or BigDecimal using constructors with O(n²) complexity, an attacker can supply a small payload (e.g., 1 - 5 MB) that results in significant CPU consumption lasting for minutes. This behavior allows an unauthenticated attacker to saturate server worker threads with a limited number of requests, effectively denying service to legitimate traffic. The vulnerability is present in default configurations of the JsonMapper and does not require advanced features like polymorphic typing to exploit.
Attack Chain
- Attacker identifies an internet-facing application that uses
jackson-databindto deserialize JSON into POJOs containingjavax.xml.datatype.DurationorXMLGregorianCalendarfields. - Attacker constructs a malicious JSON payload where the field value is a string containing an extremely long sequence of numeric characters (e.g., "P" + 5,000,000 nines + "Y").
- Attacker submits the payload via an HTTP POST request to the application's API endpoint.
- The
jackson-databindlibrary performs default deserialization and identifies the target field type. - The library passes the attacker-supplied string token to
CoreXMLDeserializers, which omits a length check against the string content. - The
DatatypeFactoryparses the string, invoking the O(n²)BigInteger(String)orBigDecimal(String)constructors within the JDK. - The server CPU utilization spikes to 100% for the duration of the parsing process, causing thread exhaustion and blocking subsequent requests.
Impact
Successful exploitation results in a persistent denial of service condition. A single small request of approximately 5 MB can consume several minutes of single-threaded CPU time. By orchestrating a low-volume, concurrent stream of such requests, an attacker can fully exhaust available application worker threads, leading to application-wide unavailability. This vulnerability impacts any service utilizing affected versions of jackson-databind to process user-supplied configuration or XML-derived data models.
Recommendation
- Upgrade
jackson-databindto a patched version immediately: 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. - If immediate patching is not feasible, implement a transport-layer length constraint on all JSON inputs to reject payloads containing abnormally long strings destined for XML-datatype fields.
- Review application DTOs for fields typed
javax.xml.datatype.DurationorXMLGregorianCalendarand implement custom deserializers that enforce strict length bounds on the input string before passing it to the JDK factory methods.