{"id":"CVE-2025-52999","aliases":["GHSA-h46c-h94j-95f3"],"url":"https://o3.security/vulnerability/CVE-2025-52999","summary":"jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data","details":"jackson-core contains core low-level incremental (\"streaming\") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.","published":"2025-06-25T17:02:57.428Z","modified":"2026-07-15T01:49:02.244504292Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.fasterxml.jackson.core:jackson-core","fixedVersion":"2.15.0"}],"fix":{"url":"https://github.com/FasterXML/jackson-core/pull/943","label":"FasterXML/jackson-core#943"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52999.json"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-core/security/advisories/GHSA-h46c-h94j-95f3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52999"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-core/pull/943"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.244504292Z"}}