Impact
The issue resides in the BigDecimal.toPlainString method within jackson-coreutils 2.0, where an attacker can craft input that forces the method to consume excessive CPU or memory. This does not enable code execution or data disclosure, but it can degrade availability of the Java process. The flaw is classified as resource exhaustion (CWE-400) and improper resource management (CWE-404).
Affected Systems
Any Java application that includes the java‑json‑tools jackson‑coreutils library version 2.0 and calls BigDecimal.toPlainString, especially when the input originates from an untrusted source, is susceptible.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity. EPSS data is unavailable, yet the exploit is publicly disclosed and can be launched remotely, raising the likelihood of abuse. The vulnerability is not listed in CISA KEV, but defenders should treat it as a moderate risk and watch for abnormal CPU or memory usage that could signal an attack.
OpenCVE Enrichment