CVE-2026-91777: CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind
CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind Vulnerability ID: CVE-2026-91777 CVSS Score: 7.5 Published: 2026-09-30 An uncontrolled resource consumption vulnerability in Fas
CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind
Vulnerability ID: CVE-2026-91777
CVSS Score: 7.5
Published: 2026-09-30
An uncontrolled resource consumption vulnerability in FasterXML jackson-databind allows remote unauthenticated attackers to cause a Denial of Service (DoS) via crafted JSON payloads containing out-of-order forward references in identity-enabled collections or maps.
TL;DR
A quadratic-time algorithmic complexity flaw in Jackson's forward-reference resolution mechanism allows unauthenticated remote attackers to trigger severe CPU thread starvation by submitting specialized JSON payloads containing out-of-order references.
β οΈ Exploit Status: POC
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- EPSS Score: 0.0045
- Impact: Denial of Service (CPU Exhaustion)
- Exploit Status: Proof of Concept available
- KEV Status: Not currently listed
Affected Systems
- jackson-databind
-
jackson-databind: >= 2.5.0, < 2.18.11 (Fixed in:
2.18.11) -
jackson-databind: >= 2.19.0, < 2.21.7 (Fixed in:
2.21.7) -
jackson-databind: >= 2.22.0, < 2.22.3 (Fixed in:
2.22.3) -
jackson-databind: >= 3.0.0, < 3.1.7 (Fixed in:
3.1.7) -
jackson-databind: >= 3.2.0, < 3.2.3 (Fixed in:
3.2.3)
Code Analysis
Commit: 37ad9b8
Replaced linear list reference tracking structures with HashMaps and sliding queues to limit lookup and merge operational complexity to linear O(N) scaling.
Mitigation Strategies
- Upgrade jackson-databind to 2.18.11, 2.21.7, 2.22.3, 3.1.7, or 3.2.3 depending on major version line
- Enforce maximum request size limits on HTTP endpoints utilizing Jackson deserialization
- Avoid the use of @JsonIdentityInfo on models accepting untrusted user-controlled input
Remediation Steps:
- Identify all direct and transitive dependencies containing 'jackson-databind' within dependency trees.
- Update project configuration files (pom.xml, build.gradle) to explicitly target safe versions.
- Redeploy application environments and verify thread resource performance during ingestion of out-of-order object graphs.
References
- GitHub Security Advisory GHSA-cxp5-3px4-pw24
- Fix Commit 37ad9b8
- FasterXML databind Issue #6204
- NVD - CVE-2026-91777
Read the full report for CVE-2026-91777 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.