Maven: com.fasterxml.jackson.core:jackson-core
CVE-2026-89407
Safety vulnerability ID: SFTY-20260922-89449
Affected versions of the `com.fasterxml.jackson.core:jackson-core` package are vulnerable to Regular Expression Denial of Service (ReDoS) because `NumberInput.looksLikeValidNumber()` checks stringified numbers against regular expressions whose adjacent quantifiers cover the same digit class. The method's use of these regular expressions causes excessive backtracking when processing input that ultimately fails to match, leading to quadratic growth in matching time relative to input length. An attacker can exploit this by sending specially crafted JSON inputs that are coerced to numeric types, potentially tying up server request threads with a few concurrent requests due to the default `maxStringLength` not mitigating the issue.
Overview
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
Advisory
com.fasterxml.jackson.core:jackson-core – Regular Expression Denial of Service (ReDoS)
Affected Package
Also affects
---
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260922-89449/CVE-2026-89407
- https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89
- https://nvd.nist.gov/vuln/detail/CVE-2026-89407
- https://github.com/FasterXML/jackson-core/issues/1649
- https://github.com/FasterXML/jackson-core/pull/1650
- https://github.com/FasterXML/jackson-core/pull/1701
- https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d
- https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff
- https://github.com/advisories/GHSA-p6pp-m3f8-5c89
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more