Memory Exhaustion Vulnerability in FasterXML Jackson Dataformats
CVE-2026-68495
7.5HIGH
What is CVE-2026-68495?
The CBOR parser in FasterXML's jackson-dataformats-binary contains a vulnerability that allows attackers to submit CBOR documents with property names of unbounded length. This occurs because the parser does not enforce the maxNameLength limit during the decoding of JSON object property names. As a result, attackers can cause memory exhaustion, leading to a denial of service. The issue impacts all versions prior to 2.16.0. If exploited, the limits imposed on property names are dictated only by the attacker's ability to upload data and the available system memory.
Affected Version(s)
jackson-dataformats-binary 2.16.0 <= 2.18.9
jackson-dataformats-binary 2.19.0 <= 2.21.5
jackson-dataformats-binary 2.22.0 <= 2.22.1
