Threats Tagged 'ghsa-r7wm-3cxj-wff9'
View all threats tagged with 'ghsa-r7wm-3cxj-wff9'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-r7wm-3cxj-wff9'
Click on any threat for detailed analysis and mitigation recommendations
Com.fasterxml.jackson.core:jackson core: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) 0 A vulnerability in the jackson-core library's asynchronous JSON parser allows an attacker to bypass the maxNumberLength limit by streaming JSON numbers in many small chunks without a terminator byte. This causes unbounded memory allocation in the parser's text buffer, leading to potential memory exhaustion. The issue affects multiple versions including 2.18.6 and 2.21.1, and similar code in 3.x versions is presumed vulnerable. The problem arises because the integer length validation is not invoked when the parser runs out of input mid-integer, unlike the fraction path which is correctly validated. This vulnerability is a partial bypass of a previous fix and results in approximately 20,000 times amplification of the allowed number length. Join the discussion | GCVE Database | 07/21/2026, 21:58:53 UTC Added: 07/22/2026, 00:11:12 UTC |
Showing 1 to 1 of 1 result