Source: jackson-databind
Version: 2.14.0+ds-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/FasterXML/jackson-databind/pull/6127
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for jackson-databind.

CVE-2026-68497[0]:
| jackson-databind binds a JSON string to a
| javax.xml.datatype.Duration or
| javax.xml.datatype.XMLGregorianCalendar field by passing the raw
| string verbatim to DatatypeFactory.newDuration(value) or
| newXMLGregorianCalendar(value) in
| CoreXMLDeserializers.Std._deserialize. These deserializers are
| registered by default with no opt-in, so a plain ObjectMapper or
| JsonMapper with no polymorphic typing and no special configuration
| reaches this path. The XML Schema lexical grammar permits numeric
| components of arbitrary length, which the JDK materializes through
| the native BigInteger(String) and BigDecimal(String) constructors,
| both quadratic in digit count. Because the digits sit inside a JSON
| string token rather than a JSON number token, jackson-core's
| StreamReadConstraints.maxNumberLength guard never applies; jackson's
| own NumberDeserializers call validateIntegerLength or
| validateFPLength before parsing a stringified number, but the XML
| datatype deserializer omits that pre-check. An unauthenticated
| attacker can therefore submit a single request of a few megabytes,
| such as a Duration value consisting of the letter P followed by
| several million digits and the letter Y, and force tens of seconds
| to several minutes of single-threaded CPU work; a handful of
| concurrent requests can saturate a server's worker threads. This
| affects com.fasterxml.jackson.core:jackson-databind from 2.0.0
| before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before
| 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before
| 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10,
| 2.21.6, 2.22.2, 3.1.6, or 3.2.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-68497
    https://www.cve.org/CVERecord?id=CVE-2026-68497
[1] https://github.com/FasterXML/jackson-databind/pull/6127
[2] 
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
[3] 
https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to