CVE-2026-68497 | FasterXML jackson-databind up to 3.2.1 CoreXMLDeserializers CoreXMLDeserializers.Std._deserialize Value resource consumption
A vulnerability classified as problematic has been found in FasterXML jackson-databind up to 2.18.9/2.21.5/2.22.1/3.1.5/3.2.1. This vulnerability affects the function CoreXMLDeserializers.Std._deserialize of the component CoreXMLDeserializers. Performing a manipulation of the argument Value results in resource consumption.
This vulnerability is identified as CVE-2026-68497. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.