PT-2026-97132 · Fasterxml · Jackson-Core

·

CVE-2026-89425

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions jackson-core versions 2.8.0 through 2.17.0
Description The UTF8DataInputJsonParser. reportInvalidToken() function in FasterXML jackson-core fails to limit the length of the offending-token text when building an error message. When a malformed token is supplied to a parser created via JsonFactory.createParser(DataInput), the parser appends characters to a StringBuilder in a loop without an upper bound, ignoring the ErrorReportConfiguration.getMaxErrorTokenLength() setting. This process bypasses ReadConstrainedTextBuffer, meaning maxStringLength and maxDocumentLength constraints do not mitigate the issue. A large malformed token can cause the StringBuilder to expand significantly due to byte-to-char expansion and internal array doubling, potentially triggering an OutOfMemoryError for the entire JVM.
Recommendations Update to a version where the UTF8DataInputJsonParser. reportInvalidToken() function is patched to respect token length limits. As a temporary workaround, avoid using JsonFactory.createParser(DataInput) when processing untrusted input.

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89425
GHSA-7HHH-6RMP-J9QF
OPENSUSE-SU-2026:11876-1
SUSE-SU-2026:4394-1

Affected Products

Jackson-Core