Stack-based Buffer Overflow Affecting druid package, versions <37.0.0-r56


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.77% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-DRUID-17706600
  • published30 Jun 2026
  • disclosed25 Jun 2025

Introduced: 25 Jun 2025

CVE-2025-52999  (opens in a new tab)
CWE-121  (opens in a new tab)

How to fix?

Upgrade Chainguard druid to version 37.0.0-r56 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream druid package and not the druid package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

CVSS Base Scores

version 3.1