PT-2026-97132 · Fasterxml · Jackson-Core
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
jackson-core versions 2.8.0 through 2.17.0
Description
The
UTF8DataInputJsonParser. reportInvalidToken() function in FasterXML jackson-core fails to limit the length of the offending-token text when building an error message. When a malformed token is supplied to a parser created via JsonFactory.createParser(DataInput), the parser appends characters to a StringBuilder in a loop without an upper bound, ignoring the ErrorReportConfiguration.getMaxErrorTokenLength() setting. This process bypasses ReadConstrainedTextBuffer, meaning maxStringLength and maxDocumentLength constraints do not mitigate the issue. A large malformed token can cause the StringBuilder to expand significantly due to byte-to-char expansion and internal array doubling, potentially triggering an OutOfMemoryError for the entire JVM.Recommendations
Update to a version where the
UTF8DataInputJsonParser. reportInvalidToken() function is patched to respect token length limits.
As a temporary workaround, avoid using JsonFactory.createParser(DataInput) when processing untrusted input.Exploit
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jackson-Core