highCVSS 7.5Vulnerability

CVE-2026-89407

## Status **FULLY REPRODUCED** with a clean, textbook empirical signature: measured runtime grew almost exactly 4x for every doubling of input size across five consecutive doublings (5,000 → 160,000 characters), confirming O(n²) behavior. A single 160,000-character string (smaller than a typical HTTP request body) took **74.4 seconds** for one call to `NumberInput.looksLikeValidNumber()`. ## Affected Component / Version - **Package:** `com.fasterxml.jackson.core:jackson-core` - **Confirmed against:** `jackson-core-2.20.2` - **Affected file:** `src/main/java/com/fasterxml/jackson/core/io/NumberInput.java` (`PATTERN_FLOAT` line ~41-42, `PATTERN_FLOAT_TRAILING_DOT` line ~51, entry point `looksLikeValidNumber()` lines ~646-656) ## Technical Analysis ```java private final static Pattern PATTERN_FLOAT = Pattern.compile( "[+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?"); private final static Pattern PATTERN_FLOAT_TRAILING_DOT = Pattern.compile( "[+-]?[0-9]+[\\.]"); public static boolean looksLikeValidNumber(final String s) { // ... short-circuits only for null/empty/length==1 ... return PATTERN_FLOAT.matcher(s).matches() || PATTERN_FLOAT_TRAILING_DOT.matcher(s).matches(); } ``` `PATTERN_FLOAT` contains ambiguous, adjacent quantifiers over the identical character class: `[0-9]*` (optional digits), an optional `[.]`, then `[0-9]+` (required digits). Java's backtracking `Pattern`/`Matcher` engine has no possessive quantifiers or atomic grouping here, so on a non-matching input the engine must explore every possible split point between the `[0-9]*` and `[0-9]+` groups before concluding failure — the classic quadratic-backtracking shape. `looksLikeValidNumber()` compounds the cost by running a **second** full-string regex (`PATTERN_FLOAT_TRAILING_DOT`) whenever the first fails, roughly doubling the constant factor without changing the asymptotic class. Critically, the length gate that applies to this specific path is `StreamReadConstrai

Properties

summary
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
severity
high
cvss_score
7.5
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:19:21Z
source_url
https://github.com/advisories/GHSA-p6pp-m3f8-5c89
ghsa_updated
2026-10-01T15:19:23Z
ghsa_id
GHSA-p6pp-m3f8-5c89
last_source
GitHub Advisory Database
cve_id
CVE-2026-89407
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (7)

HAS_WEAKNESS (2)

→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Inefficient Regular Expression Complexity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (2)

←[Software]maven/com.fasterxml.jackson.core:jackson-core
←[Software]maven/tools.jackson.core:jackson-core

AFFECTS (2)

→[Software]maven/com.fasterxml.jackson.core:jackson-core
→[Software]maven/tools.jackson.core:jackson-core

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-89407 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal