Impact
Jackson Databind deserializes XML Schema Duration and XMLGregorianCalendar values by passing a raw JSON string directly to the JDK's DatatypeFactory. Because the JSON parser does not impose a length limit on the string, an attacker can submit a value containing millions of numeric digits. Parsing these digits into BigInteger and BigDecimal is quadratic in the digit count, consuming significant CPU resources and causing a denial‑of‑service for legitimate requests.
Affected Systems
All versions of FasterXML's Jackson Databind library prior to the patched releases affect the com.fasterxml.jackson.core:jackson-databind component from 2.0.0 to 2.18.9, from 2.19.0 to 2.21.5, and from 2.22.0 to 2.22.1, and the tools.jackson.core:jackson-databind component from 3.0.0 to 3.1.5 and from 3.2.0 to 3.2.1. Any application using these libraries without upgrading is vulnerable, and the issue is triggered by the default ObjectMapper configuration.
Risk and Exploitability
The CVSS score of 7.5 denotes a high impact vulnerability. EPSS data is unavailable, but the issue has been publicly documented and can be exploited remotely by any unauthenticated actor who crafts a large JSON payload. The exploit requires only standard network access to the target's JSON endpoint; the attacker does not need authentication. Because the parsing is single‑threaded and CPU‑bound, multiple concurrent requests can saturate the server's worker threads and lead to service disruption. The vulnerability is not listed in the CISA KEV catalog, but its remote nature and high CPU cost make it a serious threat.
OpenCVE Enrichment
Github GHSA