Buffer overflow in jackson-core - CVE-2026-29062
Published: March 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error in UTF8DataInputJsonParser when parsing deeply nested JSON files. A remote attacker can pass a specially JSON data to the application and perform a denial of service attack.
Note, the vulnerability exists due to the fix for #VU112106 (CVE-2025-52999) has not been properly applied for the 3.x branch.
Affected software
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
Bamboo Data Center
IBM Automation Decision Services
How to mitigate CVE-2026-29062
Confluence Data Center - update to 10.2.11
Jira Software Data Center - update to 11.3.5
Jira Service Management Data Center - update to 11.3.5
Bamboo Data Center - update to 12.1.7
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
External References
Related Security Bulletins
- Remote denial of service in FasterXML jackson-core
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Automation Decision Services