github.com
https://github.com/FasterXML/jackson-databind CVE-2021-46877
HIGH
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
Record summary
CVE-2021-46877 has a selected CVSS score of 7.5 (high).
Description
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.fasterxml.jackson.core:jackson-databindBrowse Maven / com.fasterxml.jackson.core:jackson-databind | GitHub Advisory | 2.10.0 to < 2.12.6 · Fixed in 2.12.6 | affected |
| 2.13.0 to < 2.13.1 · Fixed in 2.13.1 | affected |
References
7github.com
https://github.com/FasterXML/jackson-databind/commit/3ccde7d938fea547e598fdefe9a82cff37fed5cb github.com
https://github.com/FasterXML/jackson-databind/issues/3328 github.com
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12.6 github.com
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13.1 groups.google.com
https://groups.google.com/g/jackson-user/c/OsBsirPM_Vw nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-46877