A high-severity vulnerability affecting jackson-databind versions >= 2.22.0, <= 2.22.2 affecting jackson-databind versions perform exactly 2,003,000 ID comparisons, CVE-2026-91777, affects Jackson Databind versions with a CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The flaw is a quadratic CPU work during deserialization caused by the implementation's linear search of the pending accumulator for every resolved object ID in CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference and the corresponding map implementation. This behavior occurs when an unauthenticated source submits JSON to an application using the affected identity-enabled collection or map shape, allowing them to consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service. The issue does not require deep nesting or syntactically unusual JSON, and it affects versions >= 2.19.0, <= 2.21.6, >= 3.0.0, <= 3.1.6, >= 3.2.0, <= 3.2.2, and >= 2.5.0, <= 2.18.10.
We recommend you to update jackson-databind to version 2.21.7, 3.1.7, 3.2.3, 2.18.11, or 2.22.3.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting jackson-databind versions >= 2.22.0, <= 2.22.2 affecting jackson-databind versions perform exactly 2,003,000 ID comparisons, CVE-2026-91777, affects Jackson Databind versions with a CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The flaw is a quadratic CPU work during deserialization caused by the implementation's linear search of the pending accumulator for every resolved object ID in CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference and the corresponding map implementation. This behavior occurs when an unauthenticated source submits JSON to an application using the affected identity-enabled collection or map shape, allowing them to consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service. The issue does not require deep nesting or syntactically unusual JSON, and it affects versions >= 2.19.0, <= 2.21.6, >= 3.0.0, <= 3.1.6, >= 3.2.0, <= 3.2.2, and >= 2.5.0, <= 2.18.10.
We recommend you to update jackson-databind to version 2.21.7, 3.1.7, 3.2.3, 2.18.11, or 2.22.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]