CVE Explorer
CVE-2026-50193
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"jackson-databind","vendor":"FasterXML","versions":[{"status":"affected","version":">= 2.10.0, < 2.14.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/FasterXML/jackson-databind/commit/a1fa4ae4ecf5cee16da465985f135f3e81816f8c","tags":["x_refsource_MISC"],"url":"https://github.com/FasterXML/jackson-databind/commit/a1fa4ae4ecf5cee16da465985f135f3e81816f8c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/references/2
{"name":"https://github.com/FasterXML/jackson-databind/issues/3447","tags":["x_refsource_MISC"],"url":"https://github.com/FasterXML/jackson-databind/issues/3447"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/references/1
{"name":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3wrr-7qpf-2prh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3wrr-7qpf-2prh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5278b2acb346917497c26f5f634dbd5368fab39524863543b9b02fc7e5ffe98a · sha256:276d9cca6541c48e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.