{"id":"CVE-2022-42003","title":"In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS fe…","summary":"In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS fe…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-502"],"vendor":"fasterxml","product":"jackson-databind","affected":["jackson-databind < 2.12.7.1","jackson-databind >= 2.13.0, < 2.13.4.1","quarkus < 2.13.3","debian_linux = 10.0","debian_linux = 11.0","oncommand_workflow_automation"],"patched":["jackson-databind 2.13.4.1","quarkus 2.13.3"],"published":"2022-10-02","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:43.300","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-42003","references":[{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/issues/3590","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202210-21","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20221124-0004/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5283","label":"cve@mitre.org"},{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/issues/3590","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202210-21","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20221124-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5283","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T16:17:15.914139Z"},"epss":0.03409,"epssPercentile":0.88536,"ingestedAt":"2026-10-07T16:38:22.241Z","slug":"CVE-2022-42003","body":"## Overview\n\nIn FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.\n\n## Affected\n\n- `jackson-databind < 2.12.7.1`\n- `jackson-databind >= 2.13.0, < 2.13.4.1`\n- `quarkus < 2.13.3`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `oncommand_workflow_automation`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jackson-databind 2.13.4.1`\n- `quarkus 2.13.3`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}