CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-68497

CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

Alon Barad
Alon Barad
Software Engineer

Sep 29, 2026·6 min read·5 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can exhaust server CPU resources and trigger a total Denial of Service by submitting crafted JSON payloads containing extremely long XML Duration or XMLGregorianCalendar strings.

CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.

Vulnerability Overview

The vulnerability resides within the com.fasterxml.jackson.databind.ext.CoreXMLDeserializers module of the FasterXML jackson-databind library. This component provides standard deserializers for core XML datatypes defined within the javax.xml.datatype package. Specifically, it handles the binding of JSON string representations to javax.xml.datatype.Duration and javax.xml.datatype.XMLGregorianCalendar target objects.

Under normal execution, applications rely on these deserializers to translate incoming serialized JSON data into structured Java XML structures. However, because Jackson treats these fields as strings rather than direct numeric entities during the initial tokenization phase, standard numeric length protections are not applied. This introduces a significant attack surface where unauthenticated remote requests can transfer massive, unfiltered payloads directly to core system components.

The resulting impact is classified under CWE-400 (Uncontrolled Resource Consumption). By exploiting this flaw, a remote attacker can saturate the hosting JVM's execution threads, leading to complete CPU resource exhaustion and an application-wide Denial of Service.

Root Cause Analysis

The underlying defect is a logical bypass of Jackson's built-in defense-in-depth mechanisms, compounded by algorithmic complexity limitations in standard JDK library classes. Jackson provides a protection mechanism, StreamReadConstraints.maxNumberLength (defaulting to 1,000 characters), designed to reject excessively long numerical values before they are parsed. This mechanism is only triggered when Jackson processes numeric JSON tokens.

Because XML duration and calendar properties are enclosed in double quotes within the JSON payload, Jackson parses them as VALUE_STRING tokens. This diverts the processing logic away from numeric deserialization constraints. Instead, the input is subject to maxStringLength, which is set to a default limit of 20,000,000 characters. Consequently, an attacker can pass megabytes of numeric digits inside a JSON string without triggering any initial parsing errors.

Once parsed as a string, CoreXMLDeserializers.Std._deserialize passes the raw value directly to DatatypeFactory.newDuration(value) or DatatypeFactory.newXMLGregorianCalendar(value). These standard JDK implementation classes process numeric sub-components by instantiating java.math.BigInteger or java.math.BigDecimal objects. Both of these JDK classes historically rely on parsing algorithms with quadratic $O(n^2)$ time complexity with respect to digit length. Processing strings containing millions of digits blocks the active JVM execution thread for minutes, leading to rapid thread-pool exhaustion.

Code Analysis

Prior to the patch, the deserialization path in com.fasterxml.jackson.databind.ext.CoreXMLDeserializers immediately delegated the string parsing task to the native DatatypeFactory instance without performing size validation.

// Vulnerable Code Path
protected Object _deserialize(String value, DeserializationContext ctxt)
{
    switch (_kind) {
    case TYPE_DURATION:
        // Raw, unvalidated value passed directly to the JDK factory
        return _dataTypeFactory.newDuration(value);
    case TYPE_QNAME:
        return QName.valueOf(value);
    case TYPE_G_CALENDAR:
        // Raw, unvalidated value passed directly to the JDK factory
        return _dataTypeFactory.newXMLGregorianCalendar(value);
    }
}

The official patch mitigates this vulnerability by calling Jackson's internal StreamReadConstraints validators on the string length before attempting instantiation. The validation methods validateIntegerLength() and validateFPLength() enforce the default 1,000-character upper limit, which is sufficient for any legitimate date, time, or duration representation.

// Patched Code Path in CoreXMLDeserializers.java
protected Object _deserialize(String value, DeserializationContext ctxt)
{
    switch (_kind) {
    case TYPE_DURATION:
        // Validate length against integer constraints prior to JDK parsing
        ctxt.getParser().streamReadConstraints().validateIntegerLength(value.length());
        return _dataTypeFactory.newDuration(value);
    case TYPE_QNAME:
        return QName.valueOf(value);
    case TYPE_G_CALENDAR:
        // Validate length against floating point constraints prior to JDK parsing
        ctxt.getParser().streamReadConstraints().validateFPLength(value.length());
        return _dataTypeFactory.newXMLGregorianCalendar(value);
    }
}

By evaluating value.length() against these constraints, the application throws a deserialization exception early in the execution flow. This prevents the execution path from reaching the complex, resource-intensive algorithmic calculations in the JDK.

Exploitation Methodology

To exploit this vulnerability, an attacker must identify a web application endpoint that exposes a JSON interface mapping to a Java object that uses javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar fields. Because these endpoints are often exposed externally for API integration or form submissions, authentication is typically not required to reach the vulnerable deserialization code path.

The attacker crafts a payload containing a structured string with an extremely large sequence of numbers. In the case of a Duration target, the attacker formats the payload with the standard duration prefix (P), followed by several million digits, and terminates it with a time unit designator such as Y (Years).

{
  "duration": "P999999999999999999999999999999999999[... truncated 2,000,000 digits ...]99999999Y"
}

When standard Java web containers (e.g., Spring Boot running embedded Tomcat) process this request, a single HTTP worker thread is assigned to parse the JSON. When the parser reaches the duration field, the execution thread enters the JDK's quadratic string conversion loop, pinning the CPU core at 100% utilization. By sending a small batch of concurrent requests, an attacker can saturate all available worker threads, preventing the container from handling legitimate incoming traffic.

Impact Assessment

The potential impact of successful exploitation is a complete Denial of Service (DoS) of the targeted application. Because the vulnerability targets thread pools at the web container level, the entire application server becomes unresponsive, affecting all hosted services and endpoints, even those that do not use XML datatypes.

The CVSS v3.1 base score of 7.5 reflects this severe availability threat. Because exploitation requires no authentication, zero user interaction, and only standard HTTP requests, the attack complexity is classified as low.

While there is no unauthorized access to data (Confidentiality) or unauthorized modification of system files (Integrity), the ease with which a single system can be rendered completely non-functional makes this a high-priority risk. This is especially true for enterprise platforms and microservices that process large volumes of public API requests.

Remediation and Mitigation

The primary remediation strategy is upgrading the jackson-databind dependency to a patched version. These releases introduce the length validation checks inside the CoreXMLDeserializers class, neutralizing the attack vector at the deserializer layer.

If upgrading dependencies is not immediately feasible, organizations should implement transport-layer request limitations. Configuring API Gateways, reverse proxies, or Web Application Firewalls (WAFs) to reject JSON payloads exceeding a reasonable maximum size (e.g., 50 KB to 100 KB) will prevent the transmission of the millions of characters required to trigger the CPU starvation loop.

Alternatively, developers can modify affected data models to bind incoming duration and calendar inputs as standard java.lang.String objects. After deserialization, the application code can manually validate that the string length does not exceed normal bounds (e.g., 100 characters) before passing the value to the DatatypeFactory constructor.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Systems

Applications utilizing FasterXML jackson-databind for parsing JSON payloads into javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar Java types.Web services and APIs built on Java-based frameworks (such as Spring Boot, Quarkus, Micronaut, and JAX-RS) incorporating vulnerable Jackson versions.

Affected Versions Detail

Product
Affected Versions
Fixed Version
jackson-databind
FasterXML
>= 2.0.0, < 2.18.102.18.10
jackson-databind
FasterXML
>= 2.19.0, < 2.21.62.21.6
jackson-databind
FasterXML
>= 2.22.0, < 2.22.22.22.2
jackson-databind
tools.jackson.core
>= 3.0.0, < 3.1.63.1.6
jackson-databind
tools.jackson.core
>= 3.2.0, < 3.2.23.2.2
AttributeDetail
CWE IDCWE-400 / CWE-1333
Attack VectorNetwork
CVSS v3.1 Score7.5 (High)
Exploit StatusPoC / Conceptual
CISA KEV StatusNot Listed
Ransomware AssociationNo

MITRE ATT&CK Mapping

T1499Endpoint Denial of Service
Impact
CWE-400
Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, enabling an actor to influence the amount of resources consumed.

References & Sources

  • [1]Authoritative CVE Record
  • [2]GitHub Advisory Database (GHSA-q4xh-88c3-wmh7)
  • [3]GitHub Patch Commit
  • [4]GitHub Pull Request #6127
  • [5]National Vulnerability Database (NVD)

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•15 minutes ago•CVE-2026-77310
5.3

CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.

Alon Barad
Alon Barad
1 views•4 min read
•about 1 hour ago•CVE-2026-19032
5.3

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-92905
5.3

CVE-2026-92905: Denial of Service in Zoho ManageEngine EventLog Analyzer and Log360 Log Collector

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.

Alon Barad
Alon Barad
7 views•5 min read
•about 3 hours ago•CVE-2026-88773
10.0

CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•CVE-2026-88058
8.6

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

Alon Barad
Alon Barad
5 views•9 min read
•about 4 hours ago•CVE-2026-101910
6.9

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

Alon Barad
Alon Barad
5 views•6 min read