CVE-2026-29062
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
06/03/2026
Last modified:
10/03/2026
Description
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constraint (default: 500) defined in StreamReadConstraints. A similar issue was found in ReaderBasedJsonParser. This allows a user to supply a JSON document with excessive nesting, which can cause a StackOverflowError when the structure is processed, leading to a Denial of Service (DoS). This issue has been patched in version 3.1.0.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fasterxml:jackson-core:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



