{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/jackson-databind--2.22.0--2.22.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-68497"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["jackson-databind (\u003e= 3.2.0, \u003c 3.2.2)","jackson-databind (\u003e= 3.0.0, \u003c 3.1.6)","jackson-databind (\u003e= 2.14.0, \u003c 2.18.10)","jackson-databind (\u003e= 2.19.0, \u003c 2.21.6)","jackson-databind (\u003e= 2.22.0, \u003c 2.22.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","deserialization"],"_cs_type":"advisory","_cs_vendors":["FasterXML"],"content_html":"\u003cp\u003eJackson-databind versions 3.2.1 and earlier, along with specific versions of the 2.x branch, contain a denial of service vulnerability (CVE-2026-68497) triggered by the deserialization of \u003ccode\u003ejavax.xml.datatype.Duration\u003c/code\u003e and \u003ccode\u003eXMLGregorianCalendar\u003c/code\u003e objects. The library passes raw JSON string tokens directly to the JDK's \u003ccode\u003eDatatypeFactory.newDuration()\u003c/code\u003e or \u003ccode\u003enewXMLGregorianCalendar()\u003c/code\u003e methods without applying length validation. While \u003ccode\u003ejackson-core\u003c/code\u003e enforces a \u003ccode\u003emaxNumberLength\u003c/code\u003e constraint for JSON number tokens, this guard does not apply to digits encapsulated within a JSON string token.\u003c/p\u003e\n\u003cp\u003eBecause the JDK materializes these numeric components into \u003ccode\u003ejava.math.BigInteger\u003c/code\u003e or \u003ccode\u003eBigDecimal\u003c/code\u003e using constructors with O(n²) complexity, an attacker can supply a small payload (e.g., 1 - 5 MB) that results in significant CPU consumption lasting for minutes. This behavior allows an unauthenticated attacker to saturate server worker threads with a limited number of requests, effectively denying service to legitimate traffic. The vulnerability is present in default configurations of the \u003ccode\u003eJsonMapper\u003c/code\u003e and does not require advanced features like polymorphic typing to exploit.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing application that uses \u003ccode\u003ejackson-databind\u003c/code\u003e to deserialize JSON into POJOs containing \u003ccode\u003ejavax.xml.datatype.Duration\u003c/code\u003e or \u003ccode\u003eXMLGregorianCalendar\u003c/code\u003e fields.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious JSON payload where the field value is a string containing an extremely long sequence of numeric characters (e.g., \u0026quot;P\u0026quot; + 5,000,000 nines + \u0026quot;Y\u0026quot;).\u003c/li\u003e\n\u003cli\u003eAttacker submits the payload via an HTTP POST request to the application's API endpoint.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ejackson-databind\u003c/code\u003e library performs default deserialization and identifies the target field type.\u003c/li\u003e\n\u003cli\u003eThe library passes the attacker-supplied string token to \u003ccode\u003eCoreXMLDeserializers\u003c/code\u003e, which omits a length check against the string content.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eDatatypeFactory\u003c/code\u003e parses the string, invoking the O(n²) \u003ccode\u003eBigInteger(String)\u003c/code\u003e or \u003ccode\u003eBigDecimal(String)\u003c/code\u003e constructors within the JDK.\u003c/li\u003e\n\u003cli\u003eThe server CPU utilization spikes to 100% for the duration of the parsing process, causing thread exhaustion and blocking subsequent requests.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial of service condition. A single small request of approximately 5 MB can consume several minutes of single-threaded CPU time. By orchestrating a low-volume, concurrent stream of such requests, an attacker can fully exhaust available application worker threads, leading to application-wide unavailability. This vulnerability impacts any service utilizing affected versions of \u003ccode\u003ejackson-databind\u003c/code\u003e to process user-supplied configuration or XML-derived data models.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ejackson-databind\u003c/code\u003e to a patched version immediately: 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, implement a transport-layer length constraint on all JSON inputs to reject payloads containing abnormally long strings destined for XML-datatype fields.\u003c/li\u003e\n\u003cli\u003eReview application DTOs for fields typed \u003ccode\u003ejavax.xml.datatype.Duration\u003c/code\u003e or \u003ccode\u003eXMLGregorianCalendar\u003c/code\u003e and implement custom deserializers that enforce strict length bounds on the input string before passing it to the JDK factory methods.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T22:15:35Z","date_published":"2026-09-28T22:15:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jackson-databind-dos/","summary":"A vulnerability in jackson-databind allows unauthenticated attackers to cause CPU exhaustion and denial of service by supplying specially crafted strings that bypass length constraints during XML datatype deserialization.","title":"Denial of Service via Unbounded Numeric Deserialization in Jackson Databind","url":"https://feed.craftedsignal.io/briefs/2026-09-jackson-databind-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Jackson-Databind (\u003e= 2.22.0, \u003c 2.22.2)","version":"https://jsonfeed.org/version/1.1"}