PT-2026-96783 · Unknown · Jackson-Core

·

CVE-2026-89407

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions jackson-core versions 2.17.0 through 2.17.2
Description The looksLikeValidNumber() function in NumberInput uses regular expressions to pre-validate stringified numbers. The PATTERN FLOAT regex contains adjacent quantifiers over the same character class, which causes Java's backtracking engine to retry every possible split point when an input fails to match. This results in the matching cost growing quadratically relative to the input length. An attacker can trigger this behavior by providing JSON that the application deserializes into numeric types such as BigDecimal, BigInteger, Double, or Float via default String-to-number coercion. Since the maxStringLength in StreamReadConstraints defaults to 20,000,000 characters, large inputs can be processed, potentially exhausting the server's request-handling thread pool with a small number of concurrent requests.
Recommendations Update jackson-core to a version later than 2.17.2.

Exploit

Fix

Resource Exhaustion

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89407
GHSA-P6PP-M3F8-5C89
OPENSUSE-SU-2026:11876-1
SUSE-SU-2026:4394-1

Affected Products

Jackson-Core