Executive brief
jackson-core, a JSON parsing library used in Java applications, contains a performance flaw in its numeric validation code. When an attacker supplies specially crafted JSON with very long digit strings, the validation logic performs expensive backtracking operations that grow with the square of the input length. This can cause a server to hang and become unresponsive, potentially bringing down applications that deserialize untrusted JSON.
Technical details
The NumberInput.looksLikeValidNumber() method uses regex patterns with adjacent quantifiers (PATTERN_FLOAT and PATTERN_FLOAT_TRAILING_DOT) that trigger catastrophic backtracking on failed matches. The method is reached through jackson-databind's String-to-number coercion for BigDecimal, BigInteger, Double, and Float types, with no input length constraints by default (StreamReadConstraints.maxStringLength=20,000,000). The O(n²) computational cost allows a 160,000-character string to consume ~74 seconds; modest concurrent requests can exhaust thread pools.
Affected products
- FasterXML jackson-core 2.17.0 through 2.17.x
Timeline
- 2026-09-22: disclosed: CVE-2026-89407 published