GHSA-rgv9-q543-rqg4HighCVSS 7.5

Uncontrolled Resource Consumption in FasterXML jackson-databind

Published
October 3, 2022
Last Modified
May 21, 2026

🔗 CVE IDs covered (1)

📋 Description

In FasterXML jackson-databind before 2.12.7.1 and in 2.13.x before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. This issue can only happen when the UNWRAP_SINGLE_VALUE_ARRAYS feature is explicitly enabled.

🎯 Affected products2

  • maven/com.fasterxml.jackson.core:jackson-databind:>= 2.13.0, < 2.13.4
  • maven/com.fasterxml.jackson.core:jackson-databind:>= 2.4.0-rc1, < 2.12.7.1

🔗 References (12)