PT-2026-96783 · Unknown · Jackson-Core
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
jackson-core versions 2.17.0 through 2.17.2
Description
The
looksLikeValidNumber() function in NumberInput uses regular expressions to pre-validate stringified numbers. The PATTERN FLOAT regex contains adjacent quantifiers over the same character class, which causes Java's backtracking engine to retry every possible split point when an input fails to match. This results in the matching cost growing quadratically relative to the input length. An attacker can trigger this behavior by providing JSON that the application deserializes into numeric types such as BigDecimal, BigInteger, Double, or Float via default String-to-number coercion. Since the maxStringLength in StreamReadConstraints defaults to 20,000,000 characters, large inputs can be processed, potentially exhausting the server's request-handling thread pool with a small number of concurrent requests.Recommendations
Update jackson-core to a version later than 2.17.2.
Exploit
Fix
Resource Exhaustion
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jackson-Core