CVE-2026-86511
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.40%
- CWE
- CWE-400, CWE-404
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- java-json-tools jackson-coreutils
Weakness type
Related vulnerabilities
- CVE-2026-89147 — Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read
- CVE-2026-87908 — multiparty vulnerable to Denial of Service via unbounded part-header accumulation
- CVE-2026-45769 — ikev2: unbounded client transform storage can lead to resource exhaustion
- CVE-2026-45768 — Suricata ldap: unbounded responses per transaction can lead to resource exhaustion
- CVE-2026-45766 — Suricata nfs: unbounded stateful structures can lead to resource exhaustion
- CVE-2026-45765 — Suricata dnp3: unbounded reassembly can lead to resource exhaustion
- CVE-2026-45759 — Suricata http1: quadratic Content-Disposition processing can lead to denial of service
- CVE-2026-87106 — Consul vulnerable to a denial of service in the native RPC listener