Vulnerability GHSA-cxp5-3px4-pw24

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
September 30, 2026 at 03:37 PM UTC
jackson-databind quadratic forward-reference completion
2.8.0 - 2.8.1 and 2.8.9 - 2.9.1 and 2.9.10 - 2.11.0 and 2.12.7 and 2.13.3 - 2.13.5
2.8.0 - 2.8.1 and 2.8.9 - 2.9.1 and 2.9.10 - 2.11.0 and 2.12.7 and 2.13.3 - 2.13.5

Summary

jackson-databind quadratic forward-reference completion

Details

Summary

When an @JsonIdentityInfo collection or map first creates N unresolved object-ID references and later resolves the same IDs in reverse order, jackson-databind scans the remaining pending-reference accumulator for each resolution. A shallow JSON document whose size grows linearly can therefore cause quadratic CPU work during deserialization.

Details

The affected path is forward-reference completion in CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the corresponding map implementation. The implementation performs a linear search of the pending accumulator for every resolved object ID.

The behavior is runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and 3.2.1. Current 2.22 and 3.2 source branches retained the same design when rechecked. A 2.4.0 control fails closed before successful reverse-order completion, so 2.5.0 is the conservative runtime-confirmed affected floor. The patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.

The vulnerable application must deserialize attacker-influenced JSON into an identity-enabled collection or map. The issue does not require deep nesting or syntactically unusual JSON.

Suggested correction: replace repeated linear lookup/removal with a keyed pending-reference structure or another design that provides linear or amortized-linear completion. A regression should preserve input order, duplicate-ID behavior, and unresolved-ID errors while bounding reverse-order resolution work.

PoC

The proof constructs a shallow collection containing N unresolved @JsonIdentityInfo references followed by definitions of those same IDs in reverse order. Its ID class counts equals() calls, giving a deterministic work measure rather than a timing-dependent result.

With N=2,000, affected versions perform exactly 2,003,000 ID comparisons. An equally sized control in which every reference is already resolved performs zero comparisons in the pending-reference lookup path. The run is bounded to a 512 MiB JVM. The result demonstrates quadratic growth: approximately N * (N + 1) / 2 comparisons, plus fixed setup comparisons.

Impact

An unauthenticated source that can submit JSON to an application using the affected identity-enabled collection or map shape can consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service. The application model/configuration prerequisite is material. No confidentiality, integrity, code-execution, or parser-depth impact is claimed.

Requested credit: Daniel Birtwhistle

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 hours ago
jackson-databind retains every unknown raw type ID
>=2.0.0 <2.0.3, >=2.0.4 <2.0.7, >=2.1.0 <2.1.6, >=2.2.0 <2.2.5, >=2.3.0 <2.3.6, ==2.4.0, ==2.4.1, ==2.10.0, ==2.10.0.pr1, ==2.10.0.pr2, ==2.10.0.pr3, >=2.10.1 <2.10.6, ==2.10.5.1, ==2.11.0, ==2.11.0.rc1, >=2.11.1 <2.11.5, >=2.12.0 <2.12.7, ==2.12.6.1, ==2.12.7, ==2.12.7.1, ==2.12.7.2, >=2.13.0 <2.13.3, ==2.13.2.1, ==2.13.2.2, ==2.13.3, ==2.13.4, ==2.13.4.1, ==2.13.4.2, ==2.13.5, >=2.14.0 <2.14.4, >=2.15.0 <2.15.5, >=2.16.0 <2.16.3, >=2.17.0 <2.17.4, >=2.18.0 <2.18.11, ==2.4.1.1, ==2.4.1.2, ==2.4.1.3, >=2.4.2 <2.4.6, ==2.4.5.1, ==2.4.6, ==2.4.6.1, >=2.5.0 <2.5.6, >=2.6.0 <2.6.8, ==2.6.7.1, ==2.6.7.2, ==2.6.7.3, ==2.6.7.4, ==2.6.7.5, >=2.7.0 <2.7.10, ==2.7.9.1, ==2.7.9.2, ==2.7.9.3, ==2.7.9.4, ==2.7.9.5, ==2.7.9.6, ==2.7.9.7, ==2.8.0, ==2.8.0.rc1, ==2.8.0.rc2, ==2.8.1, ==2.8.10, ==2.8.11, ==2.8.11.1, ==2.8.11.2, ==2.8.11.3, ==2.8.11.4, ==2.8.11.5, ==2.8.11.6, >=2.8.2 <2.8.9, ==2.8.8.1, ==2.8.9, ==2.9.0, ==2.9.0.pr1, ==2.9.0.pr2, ==2.9.0.pr3, ==2.9.0.pr4, ==2.9.1, ==2.9.10, ==2.9.10.1, ==2.9.10.2, ==2.9.10.3, ==2.9.10.4, ==2.9.10.5, ==2.9.10.6, ==2.9.10.7, ==2.9.10.8, >=2.9.2 <2.9.10, >=2.19.0 <2.19.5, >=2.20.0 <2.20.3, >=2.21.0 <2.21.7, >=2.22.0 <2.22.3, ==2.9.9.1, ==2.9.9.2, ==2.9.9.3 GHSA-wv8q-qhhj-9h54
>=2.0.0 <2.0.3, >=2.0.4 <2.0.7, >=2.1.0 <2.1.6, >=2.2.0 <2.2.5, >=2.3.0 <2.3.6, ==2.4.0, ==2.4.1, ==2.10.0, ==2.10.0.pr1, ==2.10.0.pr2, ==2.10.0.pr3, >=2.10.1 <2.10.6, ==2.10.5.1, ==2.11.0, ==2.11.0.rc1, >=2.11.1 <2.11.5, >=2.12.0 <2.12.7, ==2.12.6.1, ==2.12.7, ==2.12.7.1, ==2.12.7.2, >=2.13.0 <2.13.3, ==2.13.2.1, ==2.13.2.2, ==2.13.3, ==2.13.4, ==2.13.4.1, ==2.13.4.2, ==2.13.5, >=2.14.0 <2.14.4, >=2.15.0 <2.15.5, >=2.16.0 <2.16.3, >=2.17.0 <2.17.4, >=2.18.0 <2.18.11, ==2.4.1.1, ==2.4.1.2, ==2.4.1.3, >=2.4.2 <2.4.6, ==2.4.5.1, ==2.4.6, ==2.4.6.1, >=2.5.0 <2.5.6, >=2.6.0 <2.6.8, ==2.6.7.1, ==2.6.7.2, ==2.6.7.3, ==2.6.7.4, ==2.6.7.5, >=2.7.0 <2.7.10, ==2.7.9.1, ==2.7.9.2, ==2.7.9.3, ==2.7.9.4, ==2.7.9.5, ==2.7.9.6, ==2.7.9.7, ==2.8.0, ==2.8.0.rc1, ==2.8.0.rc2, ==2.8.1, ==2.8.10, ==2.8.11, ==2.8.11.1, ==2.8.11.2, ==2.8.11.3, ==2.8.11.4, ==2.8.11.5, ==2.8.11.6, >=2.8.2 <2.8.9, ==2.8.8.1, ==2.8.9, ==2.9.0, ==2.9.0.pr1, ==2.9.0.pr2, ==2.9.0.pr3, ==2.9.0.pr4, ==2.9.1, ==2.9.10, ==2.9.10.1, ==2.9.10.2, ==2.9.10.3, ==2.9.10.4, ==2.9.10.5, ==2.9.10.6, ==2.9.10.7, ==2.9.10.8, >=2.9.2 <2.9.10, >=2.19.0 <2.19.5, >=2.20.0 <2.20.3, >=2.21.0 <2.21.7, >=2.22.0 <2.22.3, ==2.9.9.1, ==2.9.9.2, ==2.9.9.3 GHSA-wv8q-qhhj-9h54
High Risk
3 hours ago
jackson-databind retains every unknown raw type ID
>=3.0.0 <3.0.5, >=3.1.0 <3.1.7, >=3.2.0 <3.2.3 GHSA-wv8q-qhhj-9h54
>=3.0.0 <3.0.5, >=3.1.0 <3.1.7, >=3.2.0 <3.2.3 GHSA-wv8q-qhhj-9h54
Medium Risk
1 day ago
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
Medium Risk
1 day ago
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
High Risk
1 day ago
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
2.22.0 - 2.22.1 GHSA-q4xh-88c3-wmh7
2.22.0 - 2.22.1 GHSA-q4xh-88c3-wmh7
View all vulnerabilities for these packages

Timeline

Published
3 hours ago
September 30, 2026 at 03:37 PM UTC
Fixed (2.21.7)
Unknown
Unknown
Fixed (2.18.11)
Unknown
Unknown
Fixed (2.22.3)
Unknown
Unknown
Fixed (3.1.7)
Unknown
Unknown
Fixed (3.2.3)
Unknown
Unknown
Last Modified
3 hours ago
September 30, 2026 at 03:46 PM UTC