CVE-2026-50193: falha de média gravidade em FasterXML jackson-databind
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.3epss 0.6%
probabilidade de exploração
0.6%top 52% das CVEs
exploração observada
nãonenhuma fonte reporta
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Produtos afetados
FasterXML · jackson-databindCVEs relacionadas — FasterXML jackson-databind
No mesmo produto, das mais perigosas para as menos.
CVE-2017-7525—CVE-2017-7525EPSS 37.7%CVE-2017-15095—CVE-2017-15095EPSS 8.4%CVE-2026-54513HIGHjackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)EPSS 1.2%CVE-2026-54512HIGHjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEPSS 1.0%CVE-2026-83557MEDIUMjackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base typesEPSS 0.7%CVE-2026-68497HIGHjackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of serviceEPSS 0.6%