
This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security vulnerabilities reported in CVE-2025-52999, GHSA-2m67-wjpj-xhg9 and sonatype-2022-6438 while maintaining full compatibility with jackson‑core 2.13.5.
This branch (2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9) contains a comprehensive security remediation of denial-of-service (DoS) and Allocation of Resources Without Limits or Throttling vulnerabilities targeting jackson-core 2.13.5. It introduces the StreamReadConstraints API —
aligned with the API introduced in jackson-core 2.15.0 but extended with broader parser coverage
and additional attack-vector protections — addressing a nesting-depth exhaustion attack
(CVE-2025-52999), Allocation of Resources Without Limits or Throttling (SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924), a document length constraint bypass (SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 / GHSA-2m67-wjpj-xhg9), and a numeric token length exhaustion attack (Sonatype-2022-6438) while remaining compatible with the public API surface of jackson-core version 2.13.5.
| Branch | Vulnerabilities Addressed |
|---|---|
2.13.5-CVE-2025-52999-sonatype-2022-6438 | CVE-2025-52999, Sonatype-2022-6438, SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 |
2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9 | All of the above + GHSA-2m67-wjpj-xhg9 (document length constraint bypass) |
The original branch (2.13.5-CVE-2025-52999-sonatype-2022-6438) remediates three vulnerabilities
and is preserved on the sasso remote. This branch extends it with the additional remediation of
GHSA-2m67-wjpj-xhg9,
which enforces maxDocumentLength across all parser paths.
| ID | Type | Severity | CVSS | Upstream Fix |
|---|---|---|---|---|
| CVE-2025-52999 | Denial of Service — unbounded nesting depth | High | 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | jackson-core 2.15.0 |
| Sonatype-2022-6438 / SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538 | Denial of Service — unbounded numeric token length | High | 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | jackson-core 2.15.0 |
| SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | Allocation of Resources Without Limits or Throttling | High | 8.7 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | jackson-core 2.18.6, 2.21.1 or higher. |
| SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 / GHSA-2m67-wjpj-xhg9 | Allocation of Resources Without Limits or Throttling — document length constraint bypass | High | 8.7 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | jackson-core 2.18.7, 2.21.2 or higher. |
| Version | CVE-2025-52999 | Sonatype-2022-6438 / SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 |
|---|---|---|---|---|
| 2.13.5 | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| 2.13.5-CVE-2025-52999-sonatype-2022-6438 | Remediated | Remediated | Remediated | Vulnerable |
| 2.13.5-CVE-2025-52999-sonatype-2022-6438-GHSA-2m67-wjpj-xhg9 | Remediated | Remediated | Remediated | Remediated |
| 2.14.x | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| 2.15.x | Remediated | Remediated | Vulnerable | Vulnerable |
| 2.16.x | Remediated | Remediated | Vulnerable | Vulnerable |
| 2.17.x | Remediated | Remediated | Vulnerable | Vulnerable |
| 2.18.6+ | Remediated | Remediated | Remediated | Vulnerable |
| 2.18.7+ | Remediated | Remediated | Remediated | Remediated |
| 2.21.1+ | Remediated | Remediated | Remediated | Vulnerable |
| 2.21.2+ | Remediated | Remediated | Remediated | Remediated |
NVD Entry
| Field | Value |
|---|---|
| CVE ID | CVE-2025-52999 |
| Published | 2025-06-25 |
| Last Modified | 2025-06-26 |
| Source (CNA) | GitHub, Inc. |
| CVSS v4.0 Score | 8.7 HIGH — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-121 — Stack-based Buffer Overflow |
| GitHub Advisory | GHSA-h46c-h94j-95f3 |
| Upstream Fix PR | jackson-core#943 |
Official NVD Description
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a
StackOverflowErrorif the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1,000. jackson-core will throw aStreamConstraintsExceptionif the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.
Workaround: avoid parsing JSON input from untrusted sources until the remediated version is deployed.
Root cause: Prior to 2.15.0, JsonParser imposed no limit on how deeply nested a JSON document
could be. Every array [ or object { token caused JsonReadContext.createChildArrayContext() /
createChildObjectContext() to allocate a new context node on the heap and increment a reference
chain. An attacker can craft a document with tens of thousands of nested levels, causing the Java Virtual Machine
to exhaust its thread-stack or heap memory.
Vulnerable code path:
The same missing check is reached through each of the four parser implementations:
JsonParser.nextToken() // common entry point
│
├─ ReaderBasedJsonParser → _parsePunctuationMark()
├─ UTF8StreamJsonParser → _parsePunctuationMark()
├─ UTF8DataInputJsonParser → _parsePunctuationMark()
└─ NonBlockingJsonParserBase → _startArrayScope() / _startObjectScope()
│
▼
_parsingContext.createChildArrayContext() // '[' encountered
_parsingContext.createChildObjectContext() // '{' encountered
⚠ no depth check — context chain grows without bound