AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-91777.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

### Summary When an `@JsonIdentityInfo` collection or map first creates N unresolved object-ID references and later resolves the same IDs in reverse order, jackson-databind scans the remaining pending-reference accumulator for each resolution. A shallow JSON document whose size grows linearly can therefore cause quadratic CPU work during deserialization. ### Details The affected path is forward-reference completion in `CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference()` and the corresponding map implementation. The implementation performs a linear search of the pending accumulator for every resolved object ID. The behavior is runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and 3.2.1. Current 2.22 and 3.2 source branches retained the same design when rechecked. A 2.4.0 control fails closed before successful reverse-order completion, so 2.5.0 is the conservative runtime-confirmed affected floor. The patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3. The vulnerable application must deserialize attacker-influenced JSON into an identity-enabled collection or map. The issue does not require deep nesting or syntactically unusual JSON. Suggest

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-cxp5-3px4-pw24

Open original source · Updated Sep 30, 2026

jackson-databind quadratic forward-reference completion

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
mavencom.fasterxml.jackson.core:jackson-databind>= 2.19.0,2.21.7
maventools.jackson.core:jackson-databind>= 3.0.0,3.1.7
maventools.jackson.core:jackson-databind>= 3.2.0,3.2.3
mavencom.fasterxml.jackson.core:jackson-databind>= 2.5.0,2.18.11
mavencom.fasterxml.jackson.core:jackson-databind>= 2.22.0,2.22.3

Original records & references

PUBLISHED 2026-09-30T11:37:24-04:00
MODIFIED 2026-09-30T11:37:26-04:00
INGESTED 2026-10-06T11:43:09-04:00