Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

CVE-2026-91777: CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind

CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind Vulnerability ID: CVE-2026-91777 CVSS Score: 7.5 Published: 2026-09-30 An uncontrolled resource consumption vulnerability in Fas

CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind

Vulnerability ID: CVE-2026-91777
CVSS Score: 7.5
Published: 2026-09-30

An uncontrolled resource consumption vulnerability in FasterXML jackson-databind allows remote unauthenticated attackers to cause a Denial of Service (DoS) via crafted JSON payloads containing out-of-order forward references in identity-enabled collections or maps.

TL;DR

A quadratic-time algorithmic complexity flaw in Jackson's forward-reference resolution mechanism allows unauthenticated remote attackers to trigger severe CPU thread starvation by submitting specialized JSON payloads containing out-of-order references.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.0045
  • Impact: Denial of Service (CPU Exhaustion)
  • Exploit Status: Proof of Concept available
  • KEV Status: Not currently listed

Affected Systems

  • jackson-databind
  • jackson-databind: >= 2.5.0, < 2.18.11 (Fixed in: 2.18.11)
  • jackson-databind: >= 2.19.0, < 2.21.7 (Fixed in: 2.21.7)
  • jackson-databind: >= 2.22.0, < 2.22.3 (Fixed in: 2.22.3)
  • jackson-databind: >= 3.0.0, < 3.1.7 (Fixed in: 3.1.7)
  • jackson-databind: >= 3.2.0, < 3.2.3 (Fixed in: 3.2.3)

Code Analysis

Commit: 37ad9b8

Replaced linear list reference tracking structures with HashMaps and sliding queues to limit lookup and merge operational complexity to linear O(N) scaling.

Mitigation Strategies

  • Upgrade jackson-databind to 2.18.11, 2.21.7, 2.22.3, 3.1.7, or 3.2.3 depending on major version line
  • Enforce maximum request size limits on HTTP endpoints utilizing Jackson deserialization
  • Avoid the use of @JsonIdentityInfo on models accepting untrusted user-controlled input

Remediation Steps:

  1. Identify all direct and transitive dependencies containing 'jackson-databind' within dependency trees.
  2. Update project configuration files (pom.xml, build.gradle) to explicitly target safe versions.
  3. Redeploy application environments and verify thread resource performance during ingestion of out-of-order object graphs.

References

Read the full report for CVE-2026-91777 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.