CVE-2025-49128

MEDIUM EPSS 23.1%
Published Jun 6, 20251y ago · Modified Jun 17, 20261w ago
4.0 CVSS 3.1
Medium
Find Similar
Published Jun 6, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of unintended memory content to be included in exception messages. When parsing JSON from a byte array with an offset and length, the exception message incorrectly reads from the beginning of the array instead of the logical payload start. This results in possible information disclosure in systems using pooled or reused buffers, like Netty or Vert.x. This issue was silently fixed in jackson-core version 2.13.0, released on September 30, 2021, via PR #652. All users should upgrade to version 2.13.0 or later. If upgrading is not immediately possible, applications can mitigate the issue by disabling exception message exposure to clients to avoid returning parsing exception messages in HTTP responses and/or disabling source inclusion in exceptions to prevent Jackson from embedding any source content in exception messages, avoiding leakage.

CVSS Details

Base Score
4.0
Exploitability
2.5
Impact
1.4
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
23.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-209

References 3

  • github.com https://github.com/FasterXML/jackson-core/commit/a6c297682737dde13337cb7c3020f299518609a8
  • github.com https://github.com/FasterXML/jackson-core/pull/652
  • github.com https://github.com/FasterXML/jackson-core/security/advisories/GHSA-wf8f-6423-gfxg

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.