Junglewise Threat Intelligence

CVE-2026-89407: FasterXML jackson-core regular expression denial of service in NumberInput

CVE-2026-89407 · Severity: high · CVSS 7.5 · Published 2026-09-22

Technologies: FasterXML Jackson-Core. Vendors: FasterXML.

Executive brief

jackson-core, a JSON parsing library used in Java applications, contains a performance flaw in its numeric validation code. When an attacker supplies specially crafted JSON with very long digit strings, the validation logic performs expensive backtracking operations that grow with the square of the input length. This can cause a server to hang and become unresponsive, potentially bringing down applications that deserialize untrusted JSON.

Technical details

The NumberInput.looksLikeValidNumber() method uses regex patterns with adjacent quantifiers (PATTERN_FLOAT and PATTERN_FLOAT_TRAILING_DOT) that trigger catastrophic backtracking on failed matches. The method is reached through jackson-databind's String-to-number coercion for BigDecimal, BigInteger, Double, and Float types, with no input length constraints by default (StreamReadConstraints.maxStringLength=20,000,000). The O(n²) computational cost allows a 160,000-character string to consume ~74 seconds; modest concurrent requests can exhaust thread pools.

Affected products

  • FasterXML jackson-core 2.17.0 through 2.17.x

Timeline

  • 2026-09-22: disclosed: CVE-2026-89407 published

References

Related threats