Maven: com.fasterxml.jackson.core:jackson-core

CVE-2026-89407

Safety vulnerability ID: SFTY-20260922-89449

Affected versions of the `com.fasterxml.jackson.core:jackson-core` package are vulnerable to Regular Expression Denial of Service (ReDoS) because `NumberInput.looksLikeValidNumber()` checks stringified numbers against regular expressions whose adjacent quantifiers cover the same digit class. The method's use of these regular expressions causes excessive backtracking when processing input that ultimately fails to match, leading to quadratic growth in matching time relative to input length. An attacker can exploit this by sending specially crafted JSON inputs that are coerced to numeric types, potentially tying up server request threads with a few concurrent requests due to the default `maxStringLength` not mitigating the issue.

Created at: Sep 29, 2026Updated at: Sep 29, 2026

Overview

jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()

Advisory

com.fasterxml.jackson.core:jackson-core – Regular Expression Denial of Service (ReDoS)

Affected Package

Affecting com.fasterxml.jackson.core:jackson-core package, versions>= 2.17.0, <= 2.18.10>= 2.19.0, <= 2.21.6>= 2.22.0, <= 2.22.2

Also affects

---

How to Fix

Upgradecom.fasterxml.jackson.core:jackson-coreto2.18.112.21.72.22.3or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more