{"id":"CVE-2026-50193","title":"jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)","summary":"A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that rea…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1050","CWE-400"],"vendor":"Red Hat","product":"Red Hat JBoss EAP 7.4 ELS for RHEL 8","affected":["openshift_developer_tools_and_services","openshift_serverless","ai_inference_server","amq_broker 7","amq_clients","build_of_apache_camel_hawtio 4","build_of_debezium 3","certificate_system 10","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","single_sign_on 7","streams_for_apache_kafka 2","jboss_eap_7_4_els_for_rhel_7_server","jboss_eap_7_4_els_for_rhel 8","jboss_eap_7_4_els_for_rhel 9","openshift_developer_tools_and_services 4.12","openshift_developer_tools_and_services 4.13","openshift_developer_tools_and_services 4.14","openshift_developer_tools_and_services 4.15","openshift_developer_tools_and_services 4.16","openshift_developer_tools_and_services 4.17","openshift_developer_tools_and_services 4.18","openshift_developer_tools_and_services 4.19","openshift_developer_tools_and_services 4.20","openshift_developer_tools_and_services 4.21","openshift_developer_tools_and_services 4.22","ai_inference_server 3.2","data_grid 8.6.2","lightspeed_formerly_insights_for_runtimes 1.0","openshift_ai 2.25","openshift_ai 3.4","openshift_dev_spaces 3.29","openshift_dev_spaces 3.30","build_of_apache_camel_4_18_3_for_spring_boot 3.5.16","streams_for_apache_kafka 3.2.1"],"patched":["jboss_eap_7_4_els_for_rhel_7_server","jboss_eap_7_4_els_for_rhel 8","jboss_eap_7_4_els_for_rhel 9","openshift_developer_tools_and_services 4.12","openshift_developer_tools_and_services 4.13","openshift_developer_tools_and_services 4.14","openshift_developer_tools_and_services 4.15","openshift_developer_tools_and_services 4.16","openshift_developer_tools_and_services 4.17","openshift_developer_tools_and_services 4.18","openshift_developer_tools_and_services 4.19","openshift_developer_tools_and_services 4.20","openshift_developer_tools_and_services 4.21","openshift_developer_tools_and_services 4.22","ai_inference_server 3.2","data_grid 8.6.2","lightspeed_formerly_insights_for_runtimes 1.0","openshift_ai 2.25","openshift_ai 3.4","openshift_dev_spaces 3.29","openshift_dev_spaces 3.30","build_of_apache_camel_4_18_3_for_spring_boot 3.5.16","streams_for_apache_kafka 3.2.1"],"published":"2026-06-23","updated":"2026-09-17","sourceUpdated":"2026-09-17T23:38:22+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50193.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50193.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-50193"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491999"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-50193"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50193"},{"url":"https://github.com/FasterXML/jackson-databind/commit/a1fa4ae4ecf5cee16da465985f135f3e81816f8c"},{"url":"https://github.com/FasterXML/jackson-databind/issues/3447"},{"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3wrr-7qpf-2prh"},{"url":"https://access.redhat.com/errata/RHSA-2026:53644"},{"url":"https://access.redhat.com/errata/RHSA-2026:53645"},{"url":"https://access.redhat.com/errata/RHSA-2026:53646"},{"url":"https://access.redhat.com/errata/RHSA-2026:60247"},{"url":"https://access.redhat.com/errata/RHSA-2026:60249"},{"url":"https://access.redhat.com/errata/RHSA-2026:60248"},{"url":"https://access.redhat.com/errata/RHSA-2026:60239"},{"url":"https://access.redhat.com/errata/RHSA-2026:60251"},{"url":"https://access.redhat.com/errata/RHSA-2026:60246"},{"url":"https://access.redhat.com/errata/RHSA-2026:60250"},{"url":"https://access.redhat.com/errata/RHSA-2026:60252"},{"url":"https://access.redhat.com/errata/RHSA-2026:60259"},{"url":"https://access.redhat.com/errata/RHSA-2026:60254"},{"url":"https://access.redhat.com/errata/RHSA-2026:60256"},{"url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"url":"https://access.redhat.com/errata/RHSA-2026:41951"},{"url":"https://access.redhat.com/errata/RHSA-2026:54440"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:48124"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://access.redhat.com/errata/RHSA-2026:54622"},{"url":"https://access.redhat.com/errata/RHSA-2026:53806"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435"},{"url":"https://github.com/advisories/GHSA-3wrr-7qpf-2prh"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00459,"epssPercentile":0.3894,"ecosystem":"maven","ingestedAt":"2026-06-26T16:43:14.620Z","slug":"CVE-2026-50193","body":"## Overview\n\nA flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that reads and processes it. This can lead to a Denial of Service (DoS) by consuming significant system resources, making the service unavailable to legitimate users.\n\n## Vendor advisories\n\n- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)\n- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)\n- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)\n- **RHSA-2026:60247** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.12 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60247)\n- **RHSA-2026:60249** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60249)\n- **RHSA-2026:60248** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60248)\n- **RHSA-2026:60239** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60239)\n- **RHSA-2026:60251** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60251)\n- **RHSA-2026:60246** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60246)\n- **RHSA-2026:60250** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60250)\n- **RHSA-2026:60252** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.19 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60252)\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat build of Apache Camel - HawtIO 4, … · no fix planned: Red Hat AI Inference Server, Red Hat build of Debezium 3, OpenShift Developer Tools and Services, OpenShift Serverless, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50193.json)\n- **RHSA-2026:60259** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.20 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60259)\n- **RHSA-2026:60254** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.21 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60254)\n- **RHSA-2026:60256** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.22 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60256)\n\n**jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing** — rated Important by Red Hat. Released 2026-06-23, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat AI Inference Server\n- Red Hat AMQ Broker 7\n- Red Hat AMQ Clients\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Debezium 3\n- Red Hat Certificate System 10\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nFixed:\n\n- Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server\n- Red Hat JBoss EAP 7.4 ELS for RHEL 8\n- Red Hat JBoss EAP 7.4 ELS for RHEL 9\n- OpenShift Developer Tools and Services 4.12\n- OpenShift Developer Tools and Services 4.13\n- OpenShift Developer Tools and Services 4.14\n- OpenShift Developer Tools and Services 4.15\n- OpenShift Developer Tools and Services 4.16\n- OpenShift Developer Tools and Services 4.17\n- OpenShift Developer Tools and Services 4.18\n- OpenShift Developer Tools and Services 4.19\n- OpenShift Developer Tools and Services 4.20\n- OpenShift Developer Tools and Services 4.21\n- OpenShift Developer Tools and Services 4.22\n- Red Hat AI Inference Server 3.2\n- Red Hat Data Grid 8.6.2\n- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift Dev Spaces 3.29\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16\n- Streams for Apache Kafka 3.2.1\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat build of Debezium 3\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat AMQ Broker 7\n- Red Hat AMQ Clients\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat Certificate System 10\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nNot affected:\n\n- OpenShift Developer Tools and Services 4.12\n- OpenShift Developer Tools and Services 4.13\n- OpenShift Developer Tools and Services 4.14\n- OpenShift Developer Tools and Services 4.15\n- OpenShift Developer Tools and Services 4.16\n- OpenShift Developer Tools and Services 4.17\n- OpenShift Developer Tools and Services 4.18\n- OpenShift Developer Tools and Services 4.19\n- OpenShift Developer Tools and Services 4.20\n- OpenShift Developer Tools and Services 4.21\n\n## Remediation\n\nBefore applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53644\nBefore applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53645\nBefore applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53646\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-50193)\n\nAffected packages:\n\n- `com.fasterxml.jackson.core:jackson-databind >= 2.10.0, <= 2.13.5`\n\nPatched in:\n\n- `com.fasterxml.jackson.core:jackson-databind 2.14.0`\n\nSource: https://github.com/advisories/GHSA-3wrr-7qpf-2prh","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5293,"id":"CVE-2026-50193","ts":1788887260891,"field":"cvss","old":null,"new":"7.5"},{"seq":5292,"id":"CVE-2026-50193","ts":1788887260891,"field":"severity","old":"medium","new":"high"},{"seq":4176,"id":"CVE-2026-50193","ts":1788886377592,"field":"cvss","old":"7.5","new":null},{"seq":4175,"id":"CVE-2026-50193","ts":1788886377592,"field":"severity","old":"high","new":"medium"},{"seq":3268,"id":"CVE-2026-50193","ts":1788883138699,"field":"cvss","old":null,"new":"7.5"},{"seq":3267,"id":"CVE-2026-50193","ts":1788883138699,"field":"severity","old":"medium","new":"high"}]}