jackson-core is vulnerable to Denial of Service (DoS)
87
High Risk
jackson-core does not call validateIntegerLength() when the non-blocking parser runs out of input in MINOR_NUMBER_INTEGER_DIGITS and returns NOT_AVAILABLE, an incomplete fix for CVE-2026-18401. A stream of digits with no terminator grows the text buffer up to maxStringLength instead of maxNumberLength, so a single connection can exhaust heap memory. Synchronous parsers and the async parser on a complete value still enforce the limit. The fix adds _setIntLength() calls on those integer digit exits before the parser returns NOT_AVAILABLE.
You are affected if you are using a version that falls within the vulnerable range and your application feeds chunked JSON to the non-blocking parser.
jackson-core is vulnerable to Denial of Service (DoS) in versions 2.15.0 - 2.18.7 and 2.19.0 - 2.21.3.
Upgrade the jackson-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.