DNA View

CVE-2025-52999

Low
Low Medium High Critical
CVSS Score
Published: Jun 25, 2025
Last Modified: Jun 26, 2025

Vulnerability Description

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Available Security Patches

4 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update
Oracle

CPUOCT2025

Oracle Critical Patch Update Advisory - October 2025

Severity
Critical
Released
Oct 21, 2025
Restart Required
Security Update
SUSE

CVE-2025-52999

CVE-2025-52999

Severity
Unknown
Released
Aug 05, 2025
Security Update

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-121

Stack-based Buffer Overflow

Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Variant

Key Information

Published Date
June 25, 2025