Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-91777

jackson-databind quadratic forward-reference completion
Back to all
CVE

CVE-2026-91777

jackson-databind quadratic forward-reference completion

Summary

When an @JsonIdentityInfo collection or map first creates N unresolved

object-ID references and later resolves the same IDs in reverse order,

jackson-databind scans the remaining pending-reference accumulator for each

resolution. A shallow JSON document whose size grows linearly can therefore

cause quadratic CPU work during deserialization.

Details

The affected path is forward-reference completion in

CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference()

and the corresponding map implementation. The implementation performs a

linear search of the pending accumulator for every resolved object ID.

The behavior is runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and

3.2.1. Current 2.22 and 3.2 source branches retained the same design when

rechecked. A 2.4.0 control fails closed before successful reverse-order

completion, so 2.5.0 is the conservative runtime-confirmed affected floor.

The patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.

The vulnerable application must deserialize attacker-influenced JSON into an

identity-enabled collection or map. The issue does not require deep nesting or

syntactically unusual JSON.

Suggested correction: replace repeated linear lookup/removal with a keyed

pending-reference structure or another design that provides linear or

amortized-linear completion. A regression should preserve input order,

duplicate-ID behavior, and unresolved-ID errors while bounding reverse-order

resolution work.

PoC

The proof constructs a shallow collection containing N unresolved

@JsonIdentityInfo references followed by definitions of those same IDs in

reverse order. Its ID class counts equals() calls, giving a deterministic

work measure rather than a timing-dependent result.

With N=2,000, affected versions perform exactly 2,003,000 ID comparisons. An

equally sized control in which every reference is already resolved performs

zero comparisons in the pending-reference lookup path. The run is bounded to

a 512 MiB JVM. The result demonstrates quadratic growth: approximately

N * (N + 1) / 2 comparisons, plus fixed setup comparisons.

Impact

An unauthenticated source that can submit JSON to an application using the

affected identity-enabled collection or map shape can consume quadratic CPU

and exhaust a request-time or worker-capacity budget, causing denial of

service. The application model/configuration prerequisite is material. No

confidentiality, integrity, code-execution, or parser-depth impact is claimed.

Requested credit: Daniel Birtwhistle

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Related Resources

No items found.

References

https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24, https://nvd.nist.gov/vuln/detail/CVE-2026-91777, https://github.com/FasterXML/jackson-databind/issues/6204, https://github.com/FasterXML/jackson-databind/pull/6204, https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67, https://github.com/FasterXML/jackson-databind, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3

Severity

7.5

CVSS Score
0
10

Basic Information

Base CVSS
7.5
EPSS Probability
0.0045%
EPSS Percentile
0.3691%
Introduced Version
2.19.0,3.0.0,3.2.0,2.5.0,2.22.0,0
Fix Available
2.21.7,3.1.7,3.2.3,2.18.11,2.22.3,2.0.0-r10,5.19.11-r2,6.2.10-r2,6.3.0-r3,2.19.0-r5,2.19.0-r3,4.0.13-r8,4.2.4-r8,4.0.13-r7,4.2.4-r7,3.0.0-r34,3.1.0-r41,3.2.3-r20,3.3.2-r4,3.0.0-r16,3.1.0-r17,3.2.3-r15,3.3.2-r6,10.2.0-r2,3.3.3-r4,3.3.3-r2,8.8.40-r2,8.6.39-r15,8.7.42-r2,5.0.9-r9,5.0.8-r17,5.0.1-r4,0.6.3-r19,8.5.0.254-r1,2.5.146-r6,1.7.0.1-r3,4.14.4-r2,5.1.1-r1,1.6.1-r6,1.6.1-r5,8.19.22-r2,9.2.8-r18,9.3.8-r11,8.19.22-r3,9.2.8-r17,9.3.8-r4,1.16.1-r2,1.16.1-r3,0.13.0-r3,13.9.0-r1,2.27.6-r4,2.28.5-r4,3.0.1-r6,8.14.5-r9,9.8.0-r2,1.6.0-r19,3.3.6-r20,2.7.0-r44,15.0.22-r19,15.1.7-r31,15.2.6-r29,16.0.15-r2,16.1.4-r13,16.2.3-r1,5.6.3-r5,1.5.0-r16,1.5.0-r9,3.7.2-r62,3.8.1-r64,3.9.2-r17,4.0.2-r14,4.1.2-r11,4.2.2-r2,4.3.1-r11,1.1.0-r4,1.1.0-r5,4.1.2-r13,4.2.2-r1,4.3.1-r9,1.23.0-r2,2026.3.5-r2,6.5.1-r20,1.20.3-r19,1.21.5-r6,1.22.3-r17,1.23.1-r7,1.20.3-r18,1.21.5-r10,1.22.3-r14,1.23.1-r8,9.4.7-r4,9.5.4-r4,0.1.126-r2,0.1.126-r1,0.63.19-r0,2026.02.3-r7,2026.04.0-r6,2026.05.0-r15,2026.06.0-r12,2026.07.1-r5,5.26.31-r2,26.04.6-r4,2023.45-r18,2025.20-r4,5.5.0-r26,5.5.0-r21,2.19.6-r17,3.9.0-r1,3.6.3-r2,26.5.7-r30,26.6.7-r3,0.5.2-r3,0.5.2-r4,4.1.1-r2,2.7.0-r11,10.0.0-r15,10.0.0-r8,2.0.7-r7,0.18.0-r3,0.18.0-r2,1.2.0-r7,1.2.0-r6,0.10.5-r33,4.3.1.5-r3,3.8.2-r2,6.16.0-r2,6.16.0-r1,483-r9,13.9-r32,41.0.1-r4,3.6.1-r30,3.8.7-r2,3.9.6-r3,3.8.7-r3,3.9.6-r2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading