Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
jackson — This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security vulnerabilities reported in CVE-2025-52999, GHSA-2m67-wjpj-xhg9 and sonatype-2022-6438 while maintaining full compatibility with jackson‑core 2.13.5. | Kitploit
Tools/GitHubGitHub/sassoftware/jackson
General Purpose UtilitiesStatic AnalysisVulnerability AnalysisCode AnalysisSupply Chain Security
GitHubsassoftware/jackson

jackson

View Repository
1115 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security vulnerabilities reported in CVE-2025-52999, GHSA-2m67-wjpj-xhg9 and sonatype-2022-6438 while maintaining full compatibility with jackson‑core 2.13.5.

Share

Analysis and Remediation of Security Vulnerabilities in Jackson core 2.13.5

  • CVE-2025-52999
  • SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
  • SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 (GHSA-2m67-wjpj-xhg9)
  • SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538 (Sonatype-2022-6438)

This branch (2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9) contains a comprehensive security remediation of denial-of-service (DoS) and Allocation of Resources Without Limits or Throttling vulnerabilities targeting jackson-core 2.13.5. It introduces the StreamReadConstraints API — aligned with the API introduced in jackson-core 2.15.0 but extended with broader parser coverage and additional attack-vector protections — addressing a nesting-depth exhaustion attack (CVE-2025-52999), Allocation of Resources Without Limits or Throttling (SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924), a document length constraint bypass (SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 / GHSA-2m67-wjpj-xhg9), and a numeric token length exhaustion attack (Sonatype-2022-6438) while remaining compatible with the public API surface of jackson-core version 2.13.5.

Branch History

BranchVulnerabilities Addressed
2.13.5-CVE-2025-52999-sonatype-2022-6438CVE-2025-52999, Sonatype-2022-6438, SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9All of the above + GHSA-2m67-wjpj-xhg9 (document length constraint bypass)

The original branch (2.13.5-CVE-2025-52999-sonatype-2022-6438) remediates three vulnerabilities and is preserved on the sasso remote. This branch extends it with the additional remediation of GHSA-2m67-wjpj-xhg9, which enforces maxDocumentLength across all parser paths.


Vulnerability Overview

IDTypeSeverityCVSSUpstream Fix
CVE-2025-52999Denial of Service — unbounded nesting depthHigh7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)jackson-core 2.15.0
Sonatype-2022-6438 / SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538Denial of Service — unbounded numeric token lengthHigh7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)jackson-core 2.15.0
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924Allocation of Resources Without Limits or ThrottlingHigh8.7 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)jackson-core 2.18.6, 2.21.1 or higher.
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 / GHSA-2m67-wjpj-xhg9Allocation of Resources Without Limits or Throttling — document length constraint bypassHigh8.7 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)jackson-core 2.18.7, 2.21.2 or higher.

Affected and Remediated Versions

VersionCVE-2025-52999Sonatype-2022-6438 / SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551
2.13.5VulnerableVulnerableVulnerableVulnerable
2.13.5-CVE-2025-52999-sonatype-2022-6438RemediatedRemediatedRemediatedVulnerable
2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9RemediatedRemediatedRemediatedRemediated
2.14.xVulnerableVulnerableVulnerableVulnerable
2.15.xRemediatedRemediatedVulnerableVulnerable
2.16.xRemediatedRemediatedVulnerableVulnerable
2.17.xRemediatedRemediatedVulnerableVulnerable
2.18.6+RemediatedRemediatedRemediatedVulnerable
2.18.7+RemediatedRemediatedRemediatedRemediated
2.21.1+RemediatedRemediatedRemediatedVulnerable
2.21.2+RemediatedRemediatedRemediatedRemediated

Vulnerability Description

CVE-2025-52999 — Unbounded JSON Nesting Depth

NVD Entry

FieldValue
CVE IDCVE-2025-52999
Published2025-06-25
Last Modified2025-06-26
Source (CNA)GitHub, Inc.
CVSS v4.0 Score8.7 HIGH — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-121 — Stack-based Buffer Overflow
GitHub AdvisoryGHSA-h46c-h94j-95f3
Upstream Fix PRjackson-core#943

Official NVD Description

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackOverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1,000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Workaround: avoid parsing JSON input from untrusted sources until the remediated version is deployed.


Root cause: Prior to 2.15.0, JsonParser imposed no limit on how deeply nested a JSON document could be. Every array [ or object { token caused JsonReadContext.createChildArrayContext() / createChildObjectContext() to allocate a new context node on the heap and increment a reference chain. An attacker can craft a document with tens of thousands of nested levels, causing the Java Virtual Machine to exhaust its thread-stack or heap memory.

Vulnerable code path:

The same missing check is reached through each of the four parser implementations:

JsonParser.nextToken()                         // common entry point
  │
  ├─ ReaderBasedJsonParser          → _parsePunctuationMark()
  ├─ UTF8StreamJsonParser           → _parsePunctuationMark()
  ├─ UTF8DataInputJsonParser        → _parsePunctuationMark()
  └─ NonBlockingJsonParserBase      → _startArrayScope() / _startObjectScope()
                    │
                    ▼
  _parsingContext.createChildArrayContext()     // '[' encountered
  _parsingContext.createChildObjectContext()    // '{' encountered
  ⚠  no depth check — context chain grows without bound
Download Tool