PT-2026-99156 · Suse+2 · Jackson-Annotations+4

·

CVE-2026-68496

·

Published

2026-09-24

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
This update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-base fixes the following issues:
  • CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
  • CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
  • CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639).
  • CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser (bsc#1282640).
  • CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
  • CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
  • CVE-2026-89425: UTF8DataInputJsonParser. reportInvalidToken()lacks maxErrorTokenLength limit, which allows for unbounded StringBuilder growth and can lead to a DoS when malformed tokens are processed (bsc#1282505).
Changes for jackson-annotations:
  • Update to 2.18.11
Changes for jackson-bom:
  • Update to 2.18.11
Changes for jackson-core:
  • Update to 2.18.11
  • #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
  • #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
  • #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
  • #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)
Changes for jackson-databind:
  • Update to 2.18.11
  • #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
  • #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
  • #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
  • #6099: Resolve classes without initialization in TypeFactory.findClass()
  • #6116: Reject non-ASCII digits in InetAddress literal validation
  • #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
  • #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
  • #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
  • #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys
Changes for jackson-dataformat-xml:
  • Update to 2.18.11
  • Fix build to avoid past-JDK-8 bytecode generation
  • #891: Enforce StreamReadConstraints.maxNestingDepth in FromXmlParser
Changes for jackson-dataformats-binary:
  • Update to 2.18.11
  • #783: (protobuf) Support StreamReadConstraints.maxDocumentLength in ProtobufParser
  • #785: (avro) Support StreamReadConstraints.maxDocumentLength and maxTokenCount in Avro parser
  • #803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion parser (partial fix for #358)
  • #805: (ion) Support StreamReadConstraints.maxDocumentLength in Ion parser (partial fix for #358)
  • #725: (cbor) Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639, CVE-2026-68495)
  • #726: (smile) Ensure maxNameLength limit enforced for Smile parser (bsc#1282640, CVE-2026-68496)
  • #727: (cbor) CBORParser.nextFieldName(SerializableString) confuses 5-bit length marker 23 with 24 ('1-byte length suffix follows')
  • #728: (cbor) CBORParser.nextFieldName(SerializableString) consumes Object entry slot twice on fast-path miss, truncating definite-length Objects
  • #733: (cbor) Long Strings not added to 'stringref' reference table, breaking following references
  • #735: (cbor) 'stringref' property-name paths pass 5-bit length marker instead of actual length to shouldReferenceString()
  • #736: (cbor) Long Object property names added to 'stringref' reference table twice
Changes for jackson-modules-base:
  • Update to 2.18.11

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68496
OPENSUSE-SU-2026:11878-1
SUSE-SU-2026:4394-1

Affected Products

Jackson-Annotations
Jackson-Core
Jackson-Databind
Jackson-Dataformat-Xml
Jackson-Dataformats-Binary