Executive brief
Jackson-core, a widely-used JSON parsing library in Java applications, contains an incomplete fix for a number length validation bypass. Attackers can exploit the non-blocking parser by streaming specially-crafted JSON data in small chunks, causing it to accumulate excessive heap memory per connection. This allows denial-of-service attacks against reactive web frameworks such as Spring WebFlux and Quarkus that process untrusted JSON input.
Technical details
The vulnerability is an incomplete fix to CVE-2026-18401 affecting the non-blocking UTF-8 JSON parser (NonBlockingUtf8JsonParserBase). The integer parsing paths in _startPositiveNumber(), _startNegativeNumber(), and _finishNumberIntegralPart() fail to invoke validateIntegerLength() when the parser exhausts input while in the MINOR_NUMBER_INTEGER_DIGITS state and returns NOT_AVAILABLE. This allows attackers to stream incomplete number values in many small chunks, causing _textBuffer.expandCurrentSegment() to grow unbounded by maxNumberLength (capped at 1000 digits) and instead constrained only by maxStringLength (20 MiB default)—a ~20,000x amplification. The attack requires only the ability to send data to a vulnerable parsing endpoint; no authentication or user interaction is needed. The synchronous parsers and non-blocking parser on complete buffered input are unaffected. Patches are available in jackson-core 2.18.6, 2.21.1, and later.
Affected products
- FasterXML jackson-core 2.15.0 through 2.18.5, 2.19.0 through 2.21.0
- FasterXML jackson-core 3.0.0 through 3.1.3
Timeline
- 2026-08-04: disclosed
- 2026-05-21: patched: Fix commit landed; included in 2.22.0 and 3.2.0 onward