Resource exhaustion in jackson-core - CVE-2026-18401
Published: February 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the non-blocking (async) JSON parser in jackson-core bypasses the maxNumberLength constraint (default: 1000 characters) defined in StreamReadConstraints. A remote attacker can send JSON with arbitrarily long numbers through the async parser API and exhaust CPU resources, leading to a denial of service condition.
Affected software
IBM Virtualization Engine TS7700 3948-VED
System Storage Virtualization Engine TS7700 3948-VEF
Adobe Experience Manager
Virtualization Engine TS7700 3957-VED
How to mitigate CVE-2026-18401
Adobe Experience Manager - update to 6.5.25.0
Virtualization Engine TS7700 3957-VED - addressed in versions 8.60.0.115 VTD_EXEC.905, 8.60.0.116 VTD_EXEC.905
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.60.0.115 VTD_EXEC.905, 8.60.0.116 VTD_EXEC.905, 8.61.0.60 VTD_EXEC.906
System Storage Virtualization Engine TS7700 3948-VEF - addressed in versions 8.60.0.115 VTD_EXEC.905, 8.60.0.116 VTD_EXEC.905, 8.61.0.60 VTD_EXEC.906