CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind
Vulnerability ID: CVE-2026-68497
CVSS Score: 7.5
Published: 2026-09-28
CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.
TL;DR
Unauthenticated remote attackers can exhaust server CPU resources and trigger a total Denial of Service by submitting crafted JSON payloads containing extremely long XML Duration or XMLGregorianCalendar strings.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400 / CWE-1333
- Attack Vector: Network
- CVSS v3.1 Score: 7.5 (High)
- Exploit Status: PoC / Conceptual
- CISA KEV Status: Not Listed
- Ransomware Association: No
Affected Systems
- Applications utilizing FasterXML jackson-databind for parsing JSON payloads into javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar Java types.
- Web services and APIs built on Java-based frameworks (such as Spring Boot, Quarkus, Micronaut, and JAX-RS) incorporating vulnerable Jackson versions.
-
jackson-databind: >= 2.0.0, < 2.18.10 (Fixed in:
2.18.10) -
jackson-databind: >= 2.19.0, < 2.21.6 (Fixed in:
2.21.6) -
jackson-databind: >= 2.22.0, < 2.22.2 (Fixed in:
2.22.2) -
jackson-databind: >= 3.0.0, < 3.1.6 (Fixed in:
3.1.6) -
jackson-databind: >= 3.2.0, < 3.2.2 (Fixed in:
3.2.2)
Code Analysis
Commit: a99b7e7
Call validateIntegerLength and validateFPLength constraints within CoreXMLDeserializers to restrict maximum processed character count for XML datatypes.
Mitigation Strategies
- Upgrade FasterXML jackson-databind to a patched release version (2.18.10+, 2.21.6+, 2.22.2+, 3.1.6+, or 3.2.2+).
- Deploy Web Application Firewall (WAF) or API Gateway rules to restrict the maximum HTTP POST request body size to prevent massive payload delivery.
- Refactor target Java models to bind XML fields as standard Strings, manually validating input lengths before processing.
Remediation Steps:
- Audit application dependency trees to identify vulnerable instances of com.fasterxml.jackson.core:jackson-databind.
- Update build configuration files (e.g., pom.xml or build.gradle) to enforce the use of a secure, patched version of Jackson.
- Deploy the updated application to staging environments and run integration tests to verify the compatibility of the patched library.
- Apply payload size limit restrictions on edge proxy servers (such as Nginx, HAProxy, or AWS ALB) as an immediate defense-in-depth measure.
References
- Authoritative CVE Record
- GitHub Advisory Database (GHSA-q4xh-88c3-wmh7)
- GitHub Patch Commit
- GitHub Pull Request #6127
- National Vulnerability Database (NVD)
Read the full report for CVE-2026-68497 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)