Intel

AIKIDO-2026-919437

jackson-core is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-68494 Published 2 days ago

87

High Risk

This Affects:

JAVAjackson-core
3.0.0 - 3.1.3
Fixed in 3.1.4
Are you affected? Scan for Free

TL;DR

jackson-core does not call validateIntegerLength() when the non-blocking parser runs out of input in MINOR_NUMBER_INTEGER_DIGITS and returns NOT_AVAILABLE, an incomplete fix for CVE-2026-18401. A stream of digits with no terminator grows the text buffer up to maxStringLength instead of maxNumberLength, so a single connection can exhaust heap memory. Synchronous parsers and the async parser on a complete value still enforce the limit. The fix adds _setIntLength() calls on those integer digit exits before the parser returns NOT_AVAILABLE.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application feeds chunked JSON to the non-blocking parser.

Background info

jackson-core is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 3.1.3.

How to fix this

Upgrade the jackson-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform