Skip to content

server-sdk-9.3.1.jar: 5 vulnerabilities (highest severity is: 7.5) reachable #123

Description

@mend-for-github-com
Vulnerable Library - server-sdk-9.3.1.jar

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar

Vulnerabilities

Vulnerability Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (server-sdk version) Remediation Possible** Reachability
CVE-2025-48924 Medium 5.3 Not Defined 2.27% commons-lang3-3.17.0.jar Transitive N/A* ❌

Reachable

CVE-2026-89425 High 7.5 Not Defined 0.533% jackson-core-2.21.0.jar Transitive N/A* ❌
CVE-2026-89407 High 7.5 Not Defined jackson-core-2.21.0.jar Transitive N/A* ❌
CVE-2026-68494 High 7.5 Not Defined 0.372% jackson-core-2.21.0.jar Transitive N/A* ❌
CVE-2026-18401 Medium 5.3 Not Defined 0.31% jackson-core-2.21.0.jar Transitive N/A* ❌

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2025-48924

Vulnerable Library - commons-lang3-3.17.0.jar

Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.

The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml

Please ensure your build environment is up-to-date and kindly report any build issues.

Library home page: https://commons.apache.org/proper/commons-lang/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-lang3/3.17.0/b17d2136f0460dcc0d2016ceefca8723bdf4ee70/commons-lang3-3.17.0.jar

Dependency Hierarchy:

  • server-sdk-9.3.1.jar (Root Library)
    • ❌ commons-lang3-3.17.0.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

com.vonage.quickstart.messages.MessageStatusWebhook (Application)
  -> com.vonage.client.messages.MessageStatus (Extension)
   -> com.vonage.client.JsonableBaseObject (Extension)
    -> org.apache.commons.lang3.builder.HashCodeBuilder (Extension)
     -> org.apache.commons.lang3.builder.ReflectionToStringBuilder (Extension)
      -> ❌ org.apache.commons.lang3.ClassUtils (Vulnerable Component)

Vulnerability Details

Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2025-07-11

URL: CVE-2025-48924

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.27%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-07-11

Fix Resolution: https://github.com/apache/commons-lang.git - commons-lang-3.18.0,org.apache.commons:commons-lang3:3.18.0

CVE-2026-89425

Vulnerable Library - jackson-core-2.21.0.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: https://github.com/FasterXML/jackson-core

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar

Dependency Hierarchy:

  • server-sdk-9.3.1.jar (Root Library)
    • jackson-datatype-jsr310-2.21.0.jar
      • ❌ jackson-core-2.21.0.jar (Vulnerable Library)

Found in base branch: main

Vulnerability Details

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.

Publish Date: 2026-09-23

URL: CVE-2026-89425

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.533%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-23

Fix Resolution: com.fasterxml.jackson.core:jackson-core:2.18.11,com.fasterxml.jackson.core:jackson-core:2.21.7,com.fasterxml.jackson.core:jackson-core:2.22.3,tools.jackson.core:jackson-core:3.1.7,tools.jackson.core:jackson-core:3.2.3,https://github.com/FasterXML/jackson-core.git - jackson-core-3.2.3,https://github.com/FasterXML/jackson-core.git - jackson-core-2.22.3,https://github.com/FasterXML/jackson-core.git - jackson-core-2.21.7,https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.11,https://github.com/FasterXML/jackson-core.git - jackson-core-3.1.7

CVE-2026-89407

Vulnerable Library - jackson-core-2.21.0.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: https://github.com/FasterXML/jackson-core

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar

Dependency Hierarchy:

  • server-sdk-9.3.1.jar (Root Library)
    • jackson-datatype-jsr310-2.21.0.jar
      • ❌ jackson-core-2.21.0.jar (Vulnerable Library)

Found in base branch: main

Vulnerability Details

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9][.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9] run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. 
Matching cost therefore grows with the square of the input length. 
An attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). 
Because StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. 
Testing by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. 
The affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. 
The fix replaces both regular expressions with a hand-rolled single-pass scan.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-09-22

URL: CVE-2026-89407

Threat Assessment

Exploit Maturity: Not Defined

EPSS:

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-22

Fix Resolution: com.fasterxml.jackson.core:jackson-core:2.18.11,com.fasterxml.jackson.core:jackson-core:2.21.7,com.fasterxml.jackson.core:jackson-core:2.22.3,tools.jackson.core:jackson-core:3.1.7,tools.jackson.core:jackson-core:3.2.2,https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.11,https://github.com/FasterXML/jackson-core.git - jackson-core-2.22.3,https://github.com/FasterXML/jackson-core.git - jackson-core-3.2.2,https://github.com/FasterXML/jackson-core.git - jackson-core-2.21.7,https://github.com/FasterXML/jackson-core.git - jackson-core-3.1.7

CVE-2026-68494

Vulnerable Library - jackson-core-2.21.0.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: https://github.com/FasterXML/jackson-core

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar

Dependency Hierarchy:

  • server-sdk-9.3.1.jar (Root Library)
    • jackson-datatype-jsr310-2.21.0.jar
      • ❌ jackson-core-2.21.0.jar (Vulnerable Library)

Found in base branch: main

Vulnerability Details

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.
The earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.
As a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.
The equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.
Impact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.
Exploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.
This issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).

Publish Date: 2026-08-04

URL: CVE-2026-68494

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.372%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-04

Fix Resolution: com.fasterxml.jackson.core:jackson-core:2.18.8,tools.jackson.core:jackson-core:3.1.4,https://github.com/FasterXML/jackson-core.git - jackson-core-2.21.4,com.fasterxml.jackson.core:jackson-core:2.21.4,https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.8

CVE-2026-18401

Vulnerable Library - jackson-core-2.21.0.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: https://github.com/FasterXML/jackson-core

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar

Dependency Hierarchy:

  • server-sdk-9.3.1.jar (Root Library)
    • jackson-datatype-jsr310-2.21.0.jar
      • ❌ jackson-core-2.21.0.jar (Vulnerable Library)

Found in base branch: main

Vulnerability Details

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.
The synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.
Root cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.
Impact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.
No privileges or user interaction beyond the ability to submit data for parsing are required.
This issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.
Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0.

Publish Date: 2026-08-04

URL: CVE-2026-18401

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.31%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-04

Fix Resolution: https://github.com/FasterXML/jackson-core.git - jackson-core-2.21.1,com.fasterxml.jackson.core:jackson-core:2.18.6,com.fasterxml.jackson.core:jackson-core:2.21.1,https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.6,tools.jackson.core:jackson-core:3.1.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions