Tools.jackson.core:jackson core: Duplicate Advisory: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
A vulnerability in tools.jackson.core:jackson-core affects its asynchronous JSON parser's handling of streamed numeric input. The issue is an incomplete fix for a prior CVE, allowing an attacker to bypass the maxNumberLength constraint by streaming JSON numbers in many small chunks without terminators. This causes excessive memory allocation, potentially exhausting JVM heap memory. The flaw impacts versions from 2.15.0 through 2.18.7, 2.19.0 through 2.21.3, 2.22.0, and 3.0.0 through 3.1.3 and 3.2.0. Synchronous parsers and async parsers on complete input are not affected. Exploitation requires only the ability to stream data to a parsing endpoint, with no privileges or user interaction needed.
AI Analysis
Technical Summary
The vulnerability is a bypass of the maxNumberLength constraint in the non-blocking async JSON parser of jackson-core due to an incomplete fix for CVE-2026-18401. The parser fails to validate integer length when input is streamed in small chunks without a terminator byte, causing the internal buffer to grow up to the maxStringLength limit (20 MiB by default) instead of the intended maxNumberLength (1000 by default). This can lead to excessive heap memory consumption per connection, enabling denial-of-service conditions in reactive frameworks that feed data incrementally to the parser. The affected versions include jackson-core 2.15.0 through 2.18.7, 2.19.0 through 2.21.3, 2.22.0, and 3.0.0 through 3.1.3 and 3.2.0. The issue does not affect synchronous parsers or async parsers on complete input.
Potential Impact
An attacker can cause excessive memory consumption on servers using the affected async parser by streaming JSON numbers in many small chunks without terminators. This can exhaust JVM heap memory and potentially cause denial of service. No privileges or user interaction are required for exploitation. Reactive frameworks such as Spring WebFlux, Reactor, Quarkus, Helidon, and Vert.x that use the async parser in this manner are vulnerable. Synchronous parsers and async parsers operating on complete input are not impacted.
Mitigation Recommendations
No official patch links are provided in the advisory, and the advisory notes this is a duplicate of GHSA-r7wm-3cxj-wff9 which should be consulted for remediation status. Patch status is not yet confirmed — check the vendor advisory GHSA-r7wm-3cxj-wff9 for current remediation guidance. Operators should monitor vendor communications for updates and consider mitigating exposure by limiting concurrent connections or disabling async parsing of untrusted streamed input until a fix is confirmed.
Tools.jackson.core:jackson core: Duplicate Advisory: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
Description
A vulnerability in tools.jackson.core:jackson-core affects its asynchronous JSON parser's handling of streamed numeric input. The issue is an incomplete fix for a prior CVE, allowing an attacker to bypass the maxNumberLength constraint by streaming JSON numbers in many small chunks without terminators. This causes excessive memory allocation, potentially exhausting JVM heap memory. The flaw impacts versions from 2.15.0 through 2.18.7, 2.19.0 through 2.21.3, 2.22.0, and 3.0.0 through 3.1.3 and 3.2.0. Synchronous parsers and async parsers on complete input are not affected. Exploitation requires only the ability to stream data to a parsing endpoint, with no privileges or user interaction needed.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability is a bypass of the maxNumberLength constraint in the non-blocking async JSON parser of jackson-core due to an incomplete fix for CVE-2026-18401. The parser fails to validate integer length when input is streamed in small chunks without a terminator byte, causing the internal buffer to grow up to the maxStringLength limit (20 MiB by default) instead of the intended maxNumberLength (1000 by default). This can lead to excessive heap memory consumption per connection, enabling denial-of-service conditions in reactive frameworks that feed data incrementally to the parser. The affected versions include jackson-core 2.15.0 through 2.18.7, 2.19.0 through 2.21.3, 2.22.0, and 3.0.0 through 3.1.3 and 3.2.0. The issue does not affect synchronous parsers or async parsers on complete input.
Potential Impact
An attacker can cause excessive memory consumption on servers using the affected async parser by streaming JSON numbers in many small chunks without terminators. This can exhaust JVM heap memory and potentially cause denial of service. No privileges or user interaction are required for exploitation. Reactive frameworks such as Spring WebFlux, Reactor, Quarkus, Helidon, and Vert.x that use the async parser in this manner are vulnerable. Synchronous parsers and async parsers operating on complete input are not impacted.
Mitigation Recommendations
No official patch links are provided in the advisory, and the advisory notes this is a duplicate of GHSA-r7wm-3cxj-wff9 which should be consulted for remediation status. Patch status is not yet confirmed — check the vendor advisory GHSA-r7wm-3cxj-wff9 for current remediation guidance. Operators should monitor vendor communications for updates and consider mitigating exposure by limiting concurrent connections or disabling async parsing of untrusted streamed input until a fix is confirmed.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-642r-3gj9-2pj5
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6ac139aea43b0b3b89d69ae4
Added to database: 10/03/2026, 17:21:50 UTC
Last enriched: 10/03/2026, 17:39:25 UTC
Last updated: 10/04/2026, 03:10:40 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.