Source: jackson-databind Version: 2.14.0+ds-2 Severity: important Tags: security upstream Forwarded: https://github.com/FasterXML/jackson-databind/pull/6127 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jackson-databind. CVE-2026-68497[0]: | jackson-databind binds a JSON string to a | javax.xml.datatype.Duration or | javax.xml.datatype.XMLGregorianCalendar field by passing the raw | string verbatim to DatatypeFactory.newDuration(value) or | newXMLGregorianCalendar(value) in | CoreXMLDeserializers.Std._deserialize. These deserializers are | registered by default with no opt-in, so a plain ObjectMapper or | JsonMapper with no polymorphic typing and no special configuration | reaches this path. The XML Schema lexical grammar permits numeric | components of arbitrary length, which the JDK materializes through | the native BigInteger(String) and BigDecimal(String) constructors, | both quadratic in digit count. Because the digits sit inside a JSON | string token rather than a JSON number token, jackson-core's | StreamReadConstraints.maxNumberLength guard never applies; jackson's | own NumberDeserializers call validateIntegerLength or | validateFPLength before parsing a stringified number, but the XML | datatype deserializer omits that pre-check. An unauthenticated | attacker can therefore submit a single request of a few megabytes, | such as a Duration value consisting of the letter P followed by | several million digits and the letter Y, and force tens of seconds | to several minutes of single-threaded CPU work; a handful of | concurrent requests can saturate a server's worker threads. This | affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 | before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before | 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before | 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, | 2.21.6, 2.22.2, 3.1.6, or 3.2.2. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-68497 https://www.cve.org/CVERecord?id=CVE-2026-68497 [1] https://github.com/FasterXML/jackson-databind/pull/6127 [2] https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7 [3] https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd Please adjust the affected versions in the BTS as needed. Regards, Salvatore

