Unknown · Jackson-Core · CVE-2026-89407
**Name of the Vulnerable Software and Affected Versions**
jackson-core versions 2.17.0 through 2.17.2
**Description**
The `looksLikeValidNumber()` function in `NumberInput` uses regular expressions to pre-validate stringified numbers. The `PATTERN FLOAT` regex contains adjacent quantifiers over the same character class, which causes Java's backtracking engine to retry every possible split point when an input fails to match. This results in the matching cost growing quadratically relative to the input length. An attacker can trigger this behavior by providing JSON that the application deserializes into numeric types such as `BigDecimal`, `BigInteger`, `Double`, or `Float` via default String-to-number coercion. Since the `maxStringLength` in `StreamReadConstraints` defaults to 20,000,000 characters, large inputs can be processed, potentially exhausting the server's request-handling thread pool with a small number of concurrent requests.
**Recommendations**
Update jackson-core to a version later than 2.17.2.