CVE-2026-68494 | FasterXML jackson-core up to 3.2.0 Non-blocking parser _startPositiveNumber heap-based overflow (EUVD-2026-52703)

SecurityVulns

A vulnerability was found in FasterXML jackson-core up to 2.18.7/2.21.3/2.22.0/3.1.3/3.2.0. It has been declared as problematic. The impacted element is the function _startPositiveNumber of the component Non-blocking parser. Such manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely identified as CVE-2026-68494. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More