{"id":"CVE-2022-42004","title":"In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays","summary":"In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain cust…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-502"],"vendor":"fasterxml","product":"jackson-databind","affected":["jackson-databind < 2.12.7.1","jackson-databind >= 2.13.0, < 2.13.4","quarkus < 2.13.0","debian_linux = 10.0","debian_linux = 11.0","oncommand_workflow_automation"],"patched":["jackson-databind 2.13.4","quarkus 2.13.0"],"published":"2022-10-02","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:43.607","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-42004","references":[{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/issues/3582","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202210-21","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20221118-0008/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5283","label":"cve@mitre.org"},{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/issues/3582","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202210-21","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20221118-0008/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5283","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-07T16:21:24.489201Z"},"epss":0.03409,"epssPercentile":0.88536,"ingestedAt":"2026-10-07T16:38:22.238Z","slug":"CVE-2022-42004","body":"## Overview\n\nIn FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.\n\n## Affected\n\n- `jackson-databind < 2.12.7.1`\n- `jackson-databind >= 2.13.0, < 2.13.4`\n- `quarkus < 2.13.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `oncommand_workflow_automation`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jackson-databind 2.13.4`\n- `quarkus 2.13.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}