highCVSS 7.5Vulnerability

CVE-2026-91777

### Summary When an `@JsonIdentityInfo` collection or map first creates N unresolved object-ID references and later resolves the same IDs in reverse order, jackson-databind scans the remaining pending-reference accumulator for each resolution. A shallow JSON document whose size grows linearly can therefore cause quadratic CPU work during deserialization. ### Details The affected path is forward-reference completion in `CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference()` and the corresponding map implementation. The implementation performs a linear search of the pending accumulator for every resolved object ID. The behavior is runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and 3.2.1. Current 2.22 and 3.2 source branches retained the same design when rechecked. A 2.4.0 control fails closed before successful reverse-order completion, so 2.5.0 is the conservative runtime-confirmed affected floor. The patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3. The vulnerable application must deserialize attacker-influenced JSON into an identity-enabled collection or map. The issue does not require deep nesting or syntactically unusual JSON. Suggested correction: replace repeated linear lookup/removal with a keyed pending-reference structure or another design that provides linear or amortized-linear completion. A regression should preserve input order, duplicate-ID behavior, and unresolved-ID errors while bounding reverse-order resolution work. ### PoC The proof constructs a shallow collection containing N unresolved `@JsonIdentityInfo` references followed by definitions of those same IDs in reverse order. Its ID class counts `equals()` calls, giving a deterministic work measure rather than a timing-dependent result. With N=2,000, affected versions perform exactly 2,003,000 ID comparisons. An equally sized control in which every reference is already resolved performs zero comparisons in the pending-reference lookup path. The

Properties

summary
jackson-databind quadratic forward-reference completion
severity
high
cvss_score
7.5
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T15:37:24Z
source_url
https://github.com/advisories/GHSA-cxp5-3px4-pw24
ghsa_updated
2026-09-30T15:37:26Z
ghsa_id
GHSA-cxp5-3px4-pw24
last_source
GitHub Advisory Database
cve_id
CVE-2026-91777
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
false

Related Entities (6)

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (2)

←[Software]maven/tools.jackson.core:jackson-databind
←[Software]maven/com.fasterxml.jackson.core:jackson-databind

AFFECTS (2)

→[Software]maven/tools.jackson.core:jackson-databind
→[Software]maven/com.fasterxml.jackson.core:jackson-databind

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-91777 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal