CVE-2026-91777: CWE-400 Uncontrolled Resource Consumption in FasterXML jackson-databind
CVE-2026-91777 is a high-severity vulnerability in FasterXML jackson-databind affecting versions from 2.5.0 through 3.2.2 in specified ranges. It involves uncontrolled resource consumption due to a quadratic CPU workload during deserialization of JSON documents with forward-reference completion for @JsonIdentityInfo object IDs. This occurs when unresolved object-ID references are defined in reverse order, causing excessive identity comparisons. Exploitation requires deserialization of attacker-controlled JSON into identity-enabled collections or maps.
AI Analysis
Technical Summary
The vulnerability arises from the forward-reference completion mechanism in jackson-databind's CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and MapDeserializer equivalent. The implementation performs a linear scan of pending references for each resolved ID, resulting in O(N²) identity comparisons when unresolved references are defined in reverse order. This leads to excessive CPU consumption during deserialization. The fix replaces the linear lookup with a keyed pending-reference structure to prevent quadratic complexity.
Potential Impact
An attacker who can supply JSON to an application using affected jackson-databind versions with identity-enabled collections or maps can cause excessive CPU consumption, leading to denial of service conditions. There is no impact on confidentiality or integrity, but availability is affected due to high CPU usage during deserialization.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the input data. Until a patch is available, avoid deserializing untrusted JSON into identity-enabled collections or maps to mitigate risk.
CVE-2026-91777: CWE-400 Uncontrolled Resource Consumption in FasterXML jackson-databind
Description
CVE-2026-91777 is a high-severity vulnerability in FasterXML jackson-databind affecting versions from 2.5.0 through 3.2.2 in specified ranges. It involves uncontrolled resource consumption due to a quadratic CPU workload during deserialization of JSON documents with forward-reference completion for @JsonIdentityInfo object IDs. This occurs when unresolved object-ID references are defined in reverse order, causing excessive identity comparisons. Exploitation requires deserialization of attacker-controlled JSON into identity-enabled collections or maps.
CVSS v3.1
Score 7.5high
Affected software
FasterXML
jackson-databind
FasterXML
jackson-databind
pkg:maven/FasterXML/com.fasterxml.jackson.core:jackson-databindpkg:maven/FasterXML/tools.jackson.core:jackson-databindRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the forward-reference completion mechanism in jackson-databind's CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and MapDeserializer equivalent. The implementation performs a linear scan of pending references for each resolved ID, resulting in O(N²) identity comparisons when unresolved references are defined in reverse order. This leads to excessive CPU consumption during deserialization. The fix replaces the linear lookup with a keyed pending-reference structure to prevent quadratic complexity.
Potential Impact
An attacker who can supply JSON to an application using affected jackson-databind versions with identity-enabled collections or maps can cause excessive CPU consumption, leading to denial of service conditions. There is no impact on confidentiality or integrity, but availability is affected due to high CPU usage during deserialization.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the input data. Until a patch is available, avoid deserializing untrusted JSON into identity-enabled collections or maps to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- HeroDevs
- Date Reserved
- 2026-09-15T01:25:58.562Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab33a68f7a7c54106284103
Added to database: 09/23/2026, 02:33:12 UTC
Last enriched: 09/23/2026, 02:47:39 UTC
Last updated: 09/23/2026, 03:26:51 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.