Sceawere

Vulnerability Detail

CVE-2026-68495UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CBOR Parser Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
FasterXML
Product
jackson-dataformats-binary
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and CBORParser._decodeChunkedName() delegates to the value-oriented _finishChunkedText() routine, which validates maxStringLength rather than maxNameLength. An attacker who can have a CBOR document parsed may therefore embed a single property name of unbounded length; the parser buffers the whole name in memory before returning it, whatever maxNameLength is configured to. Because StreamReadConstraints.maxDocumentLength is also disabled by default, nothing else bounds the name under default settings, so the only limits are the attacker's upload capacity and available heap, leading to memory exhaustion and denial of service. No privileges beyond the ability to submit data to a parsing endpoint are required, and exploitation needs only that the bytes reach CBORFactory parsing, directly or through an ObjectMapper configured with the CBOR module. jackson-core's own JSON parsers enforce maxNameLength incrementally during name decoding; this gap is specific to the binary formats. maxNameLength and validateNameLength were introduced in jackson-core 2.16.0, so releases before 2.16.0 do not contain the constraint that is left unenforced. This issue is tracked together with the Smile parser defect in the same vendor advisory, GHSA-3v8f-v6vx-fmrm, which covers both binary formats. The CBOR parser defect (jackson-dataformats-binary issue #725) is CVE-2026-68495; the Smile parser defect (issue #726) is assigned CVE-2026-68496.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-01T18:17:27.167Z",
  "pubdate": "2026-10-01T18:17:27.167Z",
  "executiveSummary": "The FasterXML jackson-dataformats-binary library contains a vulnerability in its CBOR parser that fails to enforce the maxNameLength constraint introduced in jackson-core 2.16.0. This allows an attacker to provide a specially crafted CBOR document containing an extremely long property name, bypassing configured security limits.\nThe vulnerability leads to uncontrolled memory consumption as the parser buffers the oversized property name in heap memory. This results in an out-of-memory (OOM) condition, facilitating a Denial of Service (DoS) attack against any application utilizing an ObjectMapper configured with the CBOR module.\nThe defect affects versions 2.16.0 and later, as these are the versions where the maxNameLength constraint was introduced and subsequently bypassed. No special privileges are required to trigger this vulnerability, as it only necessitates the ability to submit data to a parsing endpoint that utilizes the vulnerable CBORFactory.\nThe impact is significant for services that accept binary-encoded payloads from untrusted sources, as the lack of size validation on name fields enables memory exhaustion attacks that can crash the underlying JVM.",
  "technicalDetails": "The root cause of this vulnerability lies in the incorrect implementation of security constraint enforcement within the CBORParser class of the jackson-dataformats-binary library. Specifically, the parser fails to invoke StreamReadConstraints.validateNameLength() during the decoding of JSON object property names. This oversight applies to two internal decoding routines: CBORParser._decodeLongerName() and CBORParser._decodeChunkedName().\nIn the case of CBORParser._decodeLongerName(), property names of definite-length are processed without any length verification against the established StreamReadConstraints. For chunked property names, the parser delegates execution to the _finishChunkedText() method, which erroneously validates the maxStringLength constraint rather than the maxNameLength constraint required for object keys. Because StreamReadConstraints.maxDocumentLength is also disabled by default, the parser provides no secondary bounds for the total data processed.\nThe attack flow begins when an attacker transmits a maliciously crafted CBOR payload to an endpoint that utilizes the CBOR module for parsing. The attacker defines a property name of extreme length. Upon receipt, the CBORParser attempts to read the name and buffers the entire byte sequence into memory to resolve the field. Because the enforcement mechanism is bypassed, the parser continues to allocate heap memory to store the incoming name bytes until the process exhausts available system memory.\nThis vulnerability is distinct from the behavior of standard jackson-core JSON parsers, which perform incremental validation of name lengths during the decoding process. The issue is identified under CVE-2026-68495 (jackson-dataformats-binary issue #725). While the vulnerability affects versions 2.16.0 and later, it is implicitly absent in versions prior to 2.16.0 because those versions lacked the infrastructure for name length constraints entirely. The exhaustion of the heap leads to service instability or a full crash, effectively preventing the application from processing subsequent legitimate requests."
}
CVE-2026-68495: CBOR Parser Denial of Service (HIGH Severity, CVSS: 7.5) | Sceawere