Description
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: CPU Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Jackson Databind deserializes XML Schema Duration and XMLGregorianCalendar values by passing a raw JSON string directly to the JDK's DatatypeFactory. Because the JSON parser does not impose a length limit on the string, an attacker can submit a value containing millions of numeric digits. Parsing these digits into BigInteger and BigDecimal is quadratic in the digit count, consuming significant CPU resources and causing a denial‑of‑service for legitimate requests.

Affected Systems

All versions of FasterXML's Jackson Databind library prior to the patched releases affect the com.fasterxml.jackson.core:jackson-databind component from 2.0.0 to 2.18.9, from 2.19.0 to 2.21.5, and from 2.22.0 to 2.22.1, and the tools.jackson.core:jackson-databind component from 3.0.0 to 3.1.5 and from 3.2.0 to 3.2.1. Any application using these libraries without upgrading is vulnerable, and the issue is triggered by the default ObjectMapper configuration.

Risk and Exploitability

The CVSS score of 7.5 denotes a high impact vulnerability. EPSS data is unavailable, but the issue has been publicly documented and can be exploited remotely by any unauthenticated actor who crafts a large JSON payload. The exploit requires only standard network access to the target's JSON endpoint; the attacker does not need authentication. Because the parsing is single‑threaded and CPU‑bound, multiple concurrent requests can saturate the server's worker threads and lead to service disruption. The vulnerability is not listed in the CISA KEV catalog, but its remote nature and high CPU cost make it a serious threat.

Generated by OpenCVE AI on September 11, 2026 at 18:22 UTC.

Remediation

Vendor Solution

Upgrade to jackson-databind 2.18.10, 2.21.6, 2.22.2 (com.fasterxml.jackson.core) or 3.1.6, 3.2.2 (tools.jackson.core). The fix applies the same validate-length-then-parse idiom already used by NumberDeserializers, calling StreamReadConstraints length validation on the raw string before delegating to DatatypeFactory. The guard deliberately does not extend to javax.xml.namespace.QName, whose local parts may legitimately be long.


Vendor Workaround

Avoid binding javax.xml.datatype.Duration and javax.xml.datatype.XMLGregorianCalendar fields directly from untrusted JSON. Where such fields are required, impose a maximum request body size and a maximum string length at the transport layer, or bind the value as a String, length-check it, and convert it in application code.


OpenCVE Recommended Actions

  • Upgrade to the patched versions of Jackson Databind (2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2).
  • Configure the ObjectMapper to disallow deserialization of javax.xml.datatype.Duration and XMLGregorianCalendar types, or bind these fields as strings and perform application‑level validation.
  • Enforce request size limits and maximum JSON string lengths at the transport layer to limit payload size and prevent excessive CPU usage.

Generated by OpenCVE AI on September 11, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q4xh-88c3-wmh7 jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Fasterxml
Fasterxml jackson-databind
Vendors & Products Fasterxml
Fasterxml jackson-databind
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.
Title jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service
Weaknesses CWE-1333
CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Fasterxml Jackson-databind
cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published:

Updated: 2026-09-11T16:32:46.146Z

Reserved: 2026-07-30T15:20:37.473Z

Link: CVE-2026-68497

cve-icon Vulnrichment

Updated: 2026-09-11T16:28:30.398Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T16:17:39.610

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-68497

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T15:49:30Z

Links: CVE-2026-68497 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:45:02Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity

  • CWE-400

    Uncontrolled Resource Consumption