CVE-2026-68496
Received Received - Intake

Memory Exhaustion in Jackson Smile Parser

Vulnerability report for CVE-2026-68496, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: HeroDevs

Description

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained _growArrayTo() call and performs no length validation. An attacker who can have a Smile document parsed may therefore embed a single property name of unbounded length; the parser buffers the whole name in memory before returning it, whatever maxNameLength is configured to. Because StreamReadConstraints.maxDocumentLength is also disabled by default, nothing else bounds the name under default settings, so the only limits are the attacker's upload capacity and available heap, leading to memory exhaustion and denial of service. No privileges beyond the ability to submit data to a parsing endpoint are required, and exploitation needs only that the bytes reach SmileFactory parsing, directly or through an ObjectMapper configured with the Smile module. jackson-core's own JSON parsers enforce maxNameLength incrementally during name decoding; this gap is specific to the binary formats. maxNameLength and validateNameLength were introduced in jackson-core 2.16.0, so releases before 2.16.0 do not contain the constraint that is left unenforced. This issue is tracked together with the CBOR parser defect in the same vendor advisory, GHSA-3v8f-v6vx-fmrm, which covers both binary formats. The Smile parser defect (jackson-dataformats-binary issue #726) is CVE-2026-68496; the CBOR parser defect (issue #725) is assigned CVE-2026-68495.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
fasterxml jackson-dataformats-binary to 2.16.0 (exc)
fasterxml jackson-core to 2.16.0 (exc)
fasterxml jackson-dataformats-binary to 2.18.10 (exc)
fasterxml jackson-dataformat-cbor to 2.18.10 (exc)
fasterxml jackson-dataformat-smile to 2.18.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-68496 is a vulnerability in the Smile parser of the Jackson Dataformats Binary library. It fails to enforce the maxNameLength limit when decoding JSON object property names, allowing attackers to craft property names of unbounded length. This bypasses length restrictions and can lead to memory exhaustion and denial of service.

Detection Guidance

To detect this vulnerability, check the version of jackson-dataformats-binary or jackson-core in use. If versions prior to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2 are installed, the system is vulnerable. Use commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect dependencies.

Impact Analysis

An attacker can exploit this by submitting a malicious Smile document to a parsing endpoint. The parser will buffer the entire property name in memory without length validation, consuming excessive memory and potentially crashing the system. This requires only the ability to submit data to the parser.

Compliance Impact

This vulnerability could lead to denial-of-service conditions due to memory exhaustion, which may disrupt services handling sensitive data. For GDPR, this could impact availability of personal data processing systems. For HIPAA, it might affect the integrity and availability of protected health information systems. However, the provided context does not explicitly link this vulnerability to compliance failures or specific regulatory impacts.

Mitigation Strategies

Upgrade jackson-dataformats-binary and jackson-core to patched versions (2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2). If upgrading is not possible, disable Smile/CBOR parsing or enforce strict input validation for untrusted data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68496. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart