Upstream information

CVE-2026-68495 at MITRE

Description

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and CBORParser._decodeChunkedName() delegates to the value-oriented _finishChunkedText() routine, which validates maxStringLength rather than maxNameLength. An attacker who can have a CBOR document parsed may therefore embed a single property name of unbounded length; the parser buffers the whole name in memory before returning it, whatever maxNameLength is configured to. Because StreamReadConstraints.maxDocumentLength is also disabled by default, nothing else bounds the name under default settings, so the only limits are the attacker's upload capacity and available heap, leading to memory exhaustion and denial of service. No privileges beyond the ability to submit data to a parsing endpoint are required, and exploitation needs only that the bytes reach CBORFactory parsing, directly or through an ObjectMapper configured with the CBOR module. jackson-core's own JSON parsers enforce maxNameLength incrementally during name decoding; this gap is specific to the binary formats. maxNameLength and validateNameLength were introduced in jackson-core 2.16.0, so releases before 2.16.0 do not contain the constraint that is left unenforced. This issue is tracked together with the Smile parser defect in the same vendor advisory, GHSA-3v8f-v6vx-fmrm, which covers both binary formats. The CBOR parser defect (jackson-dataformats-binary issue #725) is CVE-2026-68495; the Smile parser defect (issue #726) is assigned CVE-2026-68496.

SUSE information

Overall state of this security issue: Pending

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail SUSE
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
SUSE Bugzilla entries: 1280125 [NEW], 1282639 [NEW]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 15 SP7
SUSE Linux Enterprise Server 15 SP7
SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP7-2026-4394
SUSE-SLE-Module-Development-Tools-15-SP7-2026-4394
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4394
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4394
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4394
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4394
SUSE Linux Enterprise Module for Basesystem 15 SP7
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP7-2026-4394
SUSE Linux Enterprise Module for Development Tools 15 SP7
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
Patchnames:
SUSE-SLE-Module-Development-Tools-15-SP7-2026-4394
SUSE Linux Enterprise Server 15 SP4-LTSS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4394
SUSE Linux Enterprise Server 15 SP5-LTSS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4394
SUSE Linux Enterprise Server 15 SP6-LTSS
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4394
SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4394
SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4394
SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • jackson-annotations >= 2.18.11-150200.3.28.1
  • jackson-core >= 2.18.11-150200.3.30.1
  • jackson-databind >= 2.18.11-150200.3.36.1
  • jackson-dataformat-cbor >= 2.18.11-150200.3.29.1
  • jackson-dataformat-xml >= 2.18.11-150200.5.8.1
Patchnames:
SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4394
openSUSE Tumbleweed
  • jackson-dataformat-cbor >= 2.18.11-1.1
  • jackson-dataformat-smile >= 2.18.11-1.1
  • jackson-dataformats-binary >= 2.18.11-1.1
  • jackson-dataformats-binary-javadoc >= 2.18.11-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11878


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

Product(s) Source package State
Products under general support and receiving all security fixes.
SUSE Linux Enterprise Desktop 15 SP7 jackson-annotations Released
SUSE Linux Enterprise Desktop 15 SP7 jackson-core Released
SUSE Linux Enterprise Desktop 15 SP7 jackson-databind Released
SUSE Linux Enterprise Desktop 15 SP7 jackson-dataformat-xml Released
SUSE Linux Enterprise Desktop 15 SP7 jackson-dataformats-binary Released
SUSE Linux Enterprise Module for Basesystem 15 SP7 jackson-annotations Released
SUSE Linux Enterprise Module for Basesystem 15 SP7 jackson-core Released
SUSE Linux Enterprise Module for Basesystem 15 SP7 jackson-databind Released
SUSE Linux Enterprise Module for Basesystem 15 SP7 jackson-dataformat-xml Released
SUSE Linux Enterprise Module for Development Tools 15 SP7 jackson-dataformats-binary Released
SUSE Linux Enterprise Server 15 SP7 jackson-annotations Released
SUSE Linux Enterprise Server 15 SP7 jackson-core Released
SUSE Linux Enterprise Server 15 SP7 jackson-databind Released
SUSE Linux Enterprise Server 15 SP7 jackson-dataformat-xml Released
SUSE Linux Enterprise Server 15 SP7 jackson-dataformats-binary Released
SUSE Linux Enterprise Server for SAP Applications 15 SP7 jackson-annotations Released
SUSE Linux Enterprise Server for SAP Applications 15 SP7 jackson-core Released
SUSE Linux Enterprise Server for SAP Applications 15 SP7 jackson-databind Released
SUSE Linux Enterprise Server for SAP Applications 15 SP7 jackson-dataformat-xml Released
SUSE Linux Enterprise Server for SAP Applications 15 SP7 jackson-dataformats-binary Released
Products under Long Term Service Pack support and receiving important and critical security fixes.
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS jackson-annotations Released
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS jackson-core Released
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS jackson-databind Released
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS jackson-dataformat-xml Released
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS jackson-dataformats-binary Released
SUSE Linux Enterprise High Performance Computing 15 SP5 jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS jackson-annotations Released
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS jackson-core Released
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS jackson-databind Released
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS jackson-dataformat-xml Released
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS jackson-dataformats-binary Released
SUSE Linux Enterprise Module for Development Tools 15 SP4 jackson-dataformats-binary Affected
SUSE Linux Enterprise Module for Development Tools 15 SP5 jackson-dataformats-binary Affected
SUSE Linux Enterprise Module for Development Tools 15 SP6 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP4 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP4-LTSS jackson-annotations Released
SUSE Linux Enterprise Server 15 SP4-LTSS jackson-core Released
SUSE Linux Enterprise Server 15 SP4-LTSS jackson-databind Released
SUSE Linux Enterprise Server 15 SP4-LTSS jackson-dataformat-xml Released
SUSE Linux Enterprise Server 15 SP4-LTSS jackson-dataformats-binary Released
SUSE Linux Enterprise Server 15 SP5 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP5-LTSS jackson-annotations Released
SUSE Linux Enterprise Server 15 SP5-LTSS jackson-core Released
SUSE Linux Enterprise Server 15 SP5-LTSS jackson-databind Released
SUSE Linux Enterprise Server 15 SP5-LTSS jackson-dataformat-xml Released
SUSE Linux Enterprise Server 15 SP5-LTSS jackson-dataformats-binary Released
SUSE Linux Enterprise Server 15 SP6 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP6-LTSS jackson-annotations Released
SUSE Linux Enterprise Server 15 SP6-LTSS jackson-core Released
SUSE Linux Enterprise Server 15 SP6-LTSS jackson-databind Released
SUSE Linux Enterprise Server 15 SP6-LTSS jackson-dataformat-xml Released
SUSE Linux Enterprise Server 15 SP6-LTSS jackson-dataformats-binary Released
SUSE Linux Enterprise Server for SAP Applications 15 SP4 jackson-annotations Released
SUSE Linux Enterprise Server for SAP Applications 15 SP4 jackson-core Released
SUSE Linux Enterprise Server for SAP Applications 15 SP4 jackson-databind Released
SUSE Linux Enterprise Server for SAP Applications 15 SP4 jackson-dataformat-xml Released
SUSE Linux Enterprise Server for SAP Applications 15 SP4 jackson-dataformats-binary Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 jackson-annotations Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 jackson-core Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 jackson-databind Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 jackson-dataformat-xml Released
SUSE Linux Enterprise Server for SAP Applications 15 SP5 jackson-dataformats-binary Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 jackson-annotations Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 jackson-core Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 jackson-databind Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 jackson-dataformat-xml Released
SUSE Linux Enterprise Server for SAP Applications 15 SP6 jackson-dataformats-binary Released
Products past their end of life and not receiving proactive updates anymore.
SUSE Enterprise Storage 7 jackson-dataformats-binary Affected
SUSE Enterprise Storage 7.1 jackson-dataformats-binary Affected
SUSE Linux Enterprise Desktop 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise Desktop 15 SP3 jackson-dataformats-binary Affected
SUSE Linux Enterprise Desktop 15 SP4 jackson-dataformats-binary Affected
SUSE Linux Enterprise Desktop 15 SP5 jackson-dataformats-binary Affected
SUSE Linux Enterprise Desktop 15 SP6 jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP3 jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP4 jackson-dataformats-binary Affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS jackson-annotations Released
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS jackson-core Released
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS jackson-databind Released
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS jackson-dataformat-xml Released
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS jackson-dataformats-binary Released
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS jackson-annotations Released
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS jackson-core Released
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS jackson-databind Released
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS jackson-dataformat-xml Released
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS jackson-dataformats-binary Released
SUSE Linux Enterprise Module for Development Tools 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise Module for Development Tools 15 SP3 jackson-dataformats-binary Affected
SUSE Linux Enterprise Real Time 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise Real Time 15 SP3 jackson-dataformats-binary Affected
SUSE Linux Enterprise Real Time 15 SP4 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP2-BCL jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP2-LTSS jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP3 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP3-BCL jackson-dataformats-binary Affected
SUSE Linux Enterprise Server 15 SP3-LTSS jackson-dataformats-binary Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP2 jackson-dataformats-binary Affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 jackson-dataformats-binary Affected
SUSE Manager Proxy 4.1 jackson-dataformats-binary Affected
SUSE Manager Proxy 4.2 jackson-dataformats-binary Affected
SUSE Manager Proxy 4.3 jackson-dataformats-binary Affected
SUSE Manager Proxy LTS 4.3 jackson-dataformat-xml Affected
SUSE Manager Retail Branch Server 4.1 jackson-dataformats-binary Affected
SUSE Manager Retail Branch Server 4.2 jackson-dataformats-binary Affected
SUSE Manager Retail Branch Server 4.3 jackson-dataformats-binary Affected
SUSE Manager Retail Branch Server LTS 4.3 jackson-dataformat-xml Affected
SUSE Manager Server 4.1 jackson-dataformats-binary Affected
SUSE Manager Server 4.2 jackson-dataformats-binary Affected
SUSE Manager Server 4.3 jackson-dataformats-binary Affected
SUSE Manager Server LTS 4.3 jackson-dataformat-xml Affected
openSUSE Leap 15.3 jackson-dataformats-binary Affected
openSUSE Leap 15.4 jackson-dataformats-binary Affected
openSUSE Leap 15.5 jackson-dataformats-binary Affected
openSUSE Leap 15.6 jackson-dataformats-binary Affected
Container Status
suse/multi-linux-manager/5.1/x86_64/server
suse/multi-linux-manager/5.1/x86_64/server-attestation
jackson-dataformat-xmlAffected


SUSE Timeline for this CVE

CVE page created: Thu Sep 17 16:05:28 2026
CVE page last modified: Thu Oct 1 20:46:00 2026