CVE-2026-68497
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path.
Leer descripción completaMostrar menos
The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.58%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access92 % - Impacto principal
T1499.004Application or System Exploitationimpact95 %
Vulnerabilidad de DoS por computación costosa en deserialización XML sin autenticación requerida. Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N permite explotación remota; ataques concurrentes saturan threads del servidor (CWE-400: uncontrolled resource consumption).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-400, CWE-1333
Referencias
- https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd
- https://github.com/FasterXML/jackson-databind/pull/6127
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68497",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-68497",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-11T16:26:23.881034Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
"affectedData": [
{
"repo": "https://github.com/FasterXML/jackson-databind",
"vendor": "FasterXML",
"product": "jackson-databind",
"versions": [
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.18.10",
"versionType": "maven"
},
{
"status": "affected",
"version": "2.19.0",
"lessThan": "2.21.6",
"versionType": "maven"
},
{
"status": "affected",
"version": "2.22.0",
"lessThan": "2.22.2",
"versionType": "maven"
}
],
"packageName": "com.fasterxml.jackson.core:jackson-databind",
"programFiles": [
"src/main/java/com/fasterxml/jackson/databind/ext/CoreXMLDeserializers.java"
],
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "com.fasterxml.jackson.databind.ext.CoreXMLDeserializers.Std._deserialize"
}
]
},
{
"repo": "https://github.com/FasterXML/jackson-databind",
"vendor": "FasterXML",
"product": "jackson-databind",
"versions": [
{
"status": "affected",
"version": "3.0.0",
"lessThan": "3.1.6",
"versionType": "maven"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.2",
"versionType": "maven"
}
],
"packageName": "tools.jackson.core:jackson-databind",
"programFiles": [
"src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java"
],
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "tools.jackson.databind.ext.CoreXMLDeserializers.Std._deserialize"
}
]
}
]
}
],
"published": "2026-09-11T16:17:39.610",
"references": [
{
"url": "https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd",
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c"
},
{
"url": "https://github.com/FasterXML/jackson-databind/pull/6127",
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c"
},
{
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7",
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c"
},
{
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
"description": [
{
"lang": "en",
"value": "CWE-400"
},
{
"lang": "en",
"value": "CWE-1333"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."
}
],
"lastModified": "2026-09-18T19:34:36.657",
"sourceIdentifier": "36c7be3b-2937-45df-85ea-ca7133ea542c"
}