<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Jackson-Databind (&gt;= 2.19.0, &lt; 2.21.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jackson-databind--2.19.0--2.21.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 22:15:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jackson-databind--2.19.0--2.21.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service via Unbounded Numeric Deserialization in Jackson Databind</title><link>https://feed.craftedsignal.io/briefs/2026-09-jackson-databind-dos/</link><pubDate>Mon, 28 Sep 2026 22:15:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-jackson-databind-dos/</guid><description>A vulnerability in jackson-databind allows unauthenticated attackers to cause CPU exhaustion and denial of service by supplying specially crafted strings that bypass length constraints during XML datatype deserialization.</description><content:encoded><![CDATA[<p>Jackson-databind versions 3.2.1 and earlier, along with specific versions of the 2.x branch, contain a denial of service vulnerability (CVE-2026-68497) triggered by the deserialization of <code>javax.xml.datatype.Duration</code> and <code>XMLGregorianCalendar</code> objects. The library passes raw JSON string tokens directly to the JDK's <code>DatatypeFactory.newDuration()</code> or <code>newXMLGregorianCalendar()</code> methods without applying length validation. While <code>jackson-core</code> enforces a <code>maxNumberLength</code> constraint for JSON number tokens, this guard does not apply to digits encapsulated within a JSON string token.</p>
<p>Because the JDK materializes these numeric components into <code>java.math.BigInteger</code> or <code>BigDecimal</code> using constructors with O(n²) complexity, an attacker can supply a small payload (e.g., 1 - 5 MB) that results in significant CPU consumption lasting for minutes. This behavior allows an unauthenticated attacker to saturate server worker threads with a limited number of requests, effectively denying service to legitimate traffic. The vulnerability is present in default configurations of the <code>JsonMapper</code> and does not require advanced features like polymorphic typing to exploit.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an internet-facing application that uses <code>jackson-databind</code> to deserialize JSON into POJOs containing <code>javax.xml.datatype.Duration</code> or <code>XMLGregorianCalendar</code> fields.</li>
<li>Attacker constructs a malicious JSON payload where the field value is a string containing an extremely long sequence of numeric characters (e.g., &quot;P&quot; + 5,000,000 nines + &quot;Y&quot;).</li>
<li>Attacker submits the payload via an HTTP POST request to the application's API endpoint.</li>
<li>The <code>jackson-databind</code> library performs default deserialization and identifies the target field type.</li>
<li>The library passes the attacker-supplied string token to <code>CoreXMLDeserializers</code>, which omits a length check against the string content.</li>
<li>The <code>DatatypeFactory</code> parses the string, invoking the O(n²) <code>BigInteger(String)</code> or <code>BigDecimal(String)</code> constructors within the JDK.</li>
<li>The server CPU utilization spikes to 100% for the duration of the parsing process, causing thread exhaustion and blocking subsequent requests.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a persistent denial of service condition. A single small request of approximately 5 MB can consume several minutes of single-threaded CPU time. By orchestrating a low-volume, concurrent stream of such requests, an attacker can fully exhaust available application worker threads, leading to application-wide unavailability. This vulnerability impacts any service utilizing affected versions of <code>jackson-databind</code> to process user-supplied configuration or XML-derived data models.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>jackson-databind</code> to a patched version immediately: 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.</li>
<li>If immediate patching is not feasible, implement a transport-layer length constraint on all JSON inputs to reject payloads containing abnormally long strings destined for XML-datatype fields.</li>
<li>Review application DTOs for fields typed <code>javax.xml.datatype.Duration</code> or <code>XMLGregorianCalendar</code> and implement custom deserializers that enforce strict length bounds on the input string before passing it to the JDK factory methods.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>deserialization</category></item></channel></rss>