Junglewise Threat Intelligence

CVE-2026-68497: FasterXML jackson-databind quadratic parse in XML datatype deserialization

CVE-2026-68497 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: FasterXML Jackson Databind. Vendors: FasterXML.

Executive brief

jackson-databind, a widely-used JSON parsing library, has a performance vulnerability in its XML datatype handling. When deserializing Duration or XMLGregorianCalendar fields, the library passes raw JSON strings directly to underlying Java parsers without validating string length, allowing an attacker to submit specially crafted payloads (e.g., millions of digits) that force the server to spend minutes of CPU work processing a single request, leading to service degradation and denial of service.

Technical details

The vulnerability is a quadratic-complexity algorithmic DoS in the javax.xml.datatype.DatatypeFactory parsing of Duration and XMLGregorianCalendar values. When jackson-databind deserializes these types, it bypasses its normal StreamReadConstraints.maxNumberLength guards by passing JSON string tokens directly to DatatypeFactory methods, which then construct BigInteger and BigDecimal objects from the digit sequences via Java's native constructors—both of which have quadratic behavior on large digit counts. An unauthenticated attacker can submit a JSON payload of a few megabytes (e.g., the string "P" + millions of digits + "Y" for a Duration) to force tens of seconds to minutes of single-threaded CPU consumption per request. Affected versions: jackson-databind 2.0.0–2.18.9, 2.19.0–2.21.5, 2.22.0–2.22.1, 3.0.0–3.1.5, and 3.2.0–3.2.1. Patches are available in 2.18.10, 2.21.6, 2.22.2, 3.1.6, and 3.2.2.

Affected products

  • FasterXML jackson-databind 2.0.0 before 2.18.10, 2.19.0 before 2.21.6, 2.22.0 before 2.22.2, 3.0.0 before 3.1.6, 3.2.0 before 3.2.2

Timeline

  • 2026-09-11: disclosed: CVE-2026-68497 published
  • 2026-09-11: patched: Fixes available in versions 2.18.10, 2.21.6, 2.22.2, 3.1.6, 3.2.2

Related threats