Junglewise Threat Intelligence

CVE-2026-68494: FasterXML jackson-core incomplete number length validation bypass

CVE-2026-68494 · Severity: info · CVSS 7.5 · Published 2026-08-04

Technologies: FasterXML Jackson-Core. Vendors: FasterXML.

Executive brief

Jackson-core, a widely-used JSON parsing library in Java applications, contains an incomplete fix for a number length validation bypass. Attackers can exploit the non-blocking parser by streaming specially-crafted JSON data in small chunks, causing it to accumulate excessive heap memory per connection. This allows denial-of-service attacks against reactive web frameworks such as Spring WebFlux and Quarkus that process untrusted JSON input.

Technical details

The vulnerability is an incomplete fix to CVE-2026-18401 affecting the non-blocking UTF-8 JSON parser (NonBlockingUtf8JsonParserBase). The integer parsing paths in _startPositiveNumber(), _startNegativeNumber(), and _finishNumberIntegralPart() fail to invoke validateIntegerLength() when the parser exhausts input while in the MINOR_NUMBER_INTEGER_DIGITS state and returns NOT_AVAILABLE. This allows attackers to stream incomplete number values in many small chunks, causing _textBuffer.expandCurrentSegment() to grow unbounded by maxNumberLength (capped at 1000 digits) and instead constrained only by maxStringLength (20 MiB default)—a ~20,000x amplification. The attack requires only the ability to send data to a vulnerable parsing endpoint; no authentication or user interaction is needed. The synchronous parsers and non-blocking parser on complete buffered input are unaffected. Patches are available in jackson-core 2.18.6, 2.21.1, and later.

Affected products

  • FasterXML jackson-core 2.15.0 through 2.18.5, 2.19.0 through 2.21.0
  • FasterXML jackson-core 3.0.0 through 3.1.3

Timeline

  • 2026-08-04: disclosed
  • 2026-05-21: patched: Fix commit landed; included in 2.22.0 and 3.2.0 onward

Related threats