Memory Exhaustion Vulnerability in FasterXML Jackson Dataformats
CVE-2026-68495

7.5HIGH

Key Information:

Vendor

Fasterxml

Vendor
CVE Published:
1 October 2026

What is CVE-2026-68495?

The CBOR parser in FasterXML's jackson-dataformats-binary contains a vulnerability that allows attackers to submit CBOR documents with property names of unbounded length. This occurs because the parser does not enforce the maxNameLength limit during the decoding of JSON object property names. As a result, attackers can cause memory exhaustion, leading to a denial of service. The issue impacts all versions prior to 2.16.0. If exploited, the limits imposed on property names are dictated only by the attacker's ability to upload data and the available system memory.

Affected Version(s)

jackson-dataformats-binary 2.16.0 <= 2.18.9

jackson-dataformats-binary 2.19.0 <= 2.21.5

jackson-dataformats-binary 2.22.0 <= 2.22.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tinyb0y
.