DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-68497: CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

Vulnerability ID: CVE-2026-68497
CVSS Score: 7.5
Published: 2026-09-28

CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.

TL;DR

Unauthenticated remote attackers can exhaust server CPU resources and trigger a total Denial of Service by submitting crafted JSON payloads containing extremely long XML Duration or XMLGregorianCalendar strings.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 / CWE-1333
  • Attack Vector: Network
  • CVSS v3.1 Score: 7.5 (High)
  • Exploit Status: PoC / Conceptual
  • CISA KEV Status: Not Listed
  • Ransomware Association: No

Affected Systems

  • Applications utilizing FasterXML jackson-databind for parsing JSON payloads into javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar Java types.
  • Web services and APIs built on Java-based frameworks (such as Spring Boot, Quarkus, Micronaut, and JAX-RS) incorporating vulnerable Jackson versions.
  • jackson-databind: >= 2.0.0, < 2.18.10 (Fixed in: 2.18.10)
  • jackson-databind: >= 2.19.0, < 2.21.6 (Fixed in: 2.21.6)
  • jackson-databind: >= 2.22.0, < 2.22.2 (Fixed in: 2.22.2)
  • jackson-databind: >= 3.0.0, < 3.1.6 (Fixed in: 3.1.6)
  • jackson-databind: >= 3.2.0, < 3.2.2 (Fixed in: 3.2.2)

Code Analysis

Commit: a99b7e7

Call validateIntegerLength and validateFPLength constraints within CoreXMLDeserializers to restrict maximum processed character count for XML datatypes.

Mitigation Strategies

  • Upgrade FasterXML jackson-databind to a patched release version (2.18.10+, 2.21.6+, 2.22.2+, 3.1.6+, or 3.2.2+).
  • Deploy Web Application Firewall (WAF) or API Gateway rules to restrict the maximum HTTP POST request body size to prevent massive payload delivery.
  • Refactor target Java models to bind XML fields as standard Strings, manually validating input lengths before processing.

Remediation Steps:

  1. Audit application dependency trees to identify vulnerable instances of com.fasterxml.jackson.core:jackson-databind.
  2. Update build configuration files (e.g., pom.xml or build.gradle) to enforce the use of a secure, patched version of Jackson.
  3. Deploy the updated application to staging environments and run integration tests to verify the compatibility of the patched library.
  4. Apply payload size limit restrictions on edge proxy servers (such as Nginx, HAProxy, or AWS ALB) as an immediate defense-in-depth measure.

References


Read the full report for CVE-2026-68497 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)