PT-2025-26867 · Unknown+7 · Jackson-Core+7

Pjfanning

·

Published

2025-06-06

·

Updated

2026-05-18

·

CVE-2025-52999

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: jackson-core versions prior to 2.15.0
Description: The issue arises when parsing input files with deeply nested data, potentially causing a StackoverflowError due to excessive depth. A configurable limit for traversal depth has been introduced, defaulting to 1000, to prevent this error. If the limit is reached, a StreamConstraintsException is thrown. Users should avoid parsing input files from untrusted sources as a workaround.
Recommendations: For versions prior to 2.15.0, update to version 2.15.0 or later to include the configurable depth limit and prevent StackoverflowError. As a temporary workaround, consider avoiding the parsing of deeply nested input files from untrusted sources until the update is applied.

Exploit

Fix

DoS

Generation of Error Message Containing Sensitive Information

Allocation of Resources Without Limits

Stack Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:12280
ALSA-2025:14126
BDU:2025-11087
BDU:2025-12587
CESA-2025_14126
CLEANSTART-2026-GH89210
CLEANSTART-2026-JU62349
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-WK99982
CVE-2025-52999
GHSA-6V53-7C9G-W56R
GHSA-H46C-H94J-95F3
INFSA-2025_12280
INFSA-2025_14126
RHSA-2025:10092
RHSA-2025:10097
RHSA-2025:10098
RHSA-2025:10104
RHSA-2025:10118
RHSA-2025:10119
RHSA-2025:10120
RHSA-2025:11473
RHSA-2025:12280
RHSA-2025:12281
RHSA-2025:12282
RHSA-2025:12283
RHSA-2025:14116
RHSA-2025:14117
RHSA-2025:14118
RHSA-2025:14126
RHSA-2025:14127
RHSA-2025_12280
RHSA-2025_14126
RHSA-2026:0742
RHSA-2026:0743
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917

Affected Products

Almalinux
Bitbucket
Centos
Debian
Red Hat
Red Os
Rocky Linux
Jackson-Core