highCVSS 7.5Vulnerability

CVE-2026-89425

## Status **FULLY REPRODUCED.** A malformed token fed through `createParser(DataInput)` produced a 20,000,109-character exception message from a 20-million-character attacker payload, while the identical payload fed through `createParser(InputStream)` produced a correctly bounded 367-character message. ## Affected Component / Version - **Package:** `com.fasterxml.jackson.core:jackson-core` - **Confirmed against:** `jackson-core-2.20.2` - **Affected file:** `src/main/java/com/fasterxml/jackson/core/json/UTF8DataInputJsonParser.java` (`_reportInvalidToken(int, String, String)`, lines ~2763-2780 in the 2.20.2 tree) ## Technical Analysis `UTF8DataInputJsonParser._reportInvalidToken()` builds the offending-token description for its exception message by appending identifier characters one at a time to a bare `StringBuilder`: ```java protected void _reportInvalidToken(int ch, String matchedPart, String msg) throws IOException { StringBuilder sb = new StringBuilder(matchedPart); while (true) { char c = (char) _decodeCharForError(ch); if (!Character.isJavaIdentifierPart(c)) { break; } sb.append(c); ch = _inputData.readUnsignedByte(); } _reportError("Unrecognized token '"+sb.toString()+"': was expecting "+msg); } ``` There is **no check against `ErrorReportConfiguration.getMaxErrorTokenLength()`** (default 256) anywhere in this loop. By contrast, the sibling `UTF8StreamJsonParser` implementation of the same logic does enforce it: ```java // UTF8StreamJsonParser.java (control, correctly bounded) if (sb.length() >= _ioContext.errorReportConfiguration().getMaxErrorTokenLength()) { sb.append("..."); break; } ``` `ReaderBasedJsonParser` and `NonBlockingUtf8JsonParserBase` also correctly enforce the limit — this is a defect isolated to the `DataInput`-backed implementation specifically, confirmed by direct comparison of all four parser implementations in this tree. This path is additionally left

Properties

summary
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)
severity
high
cvss_score
7.5
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:20:27Z
source_url
https://github.com/advisories/GHSA-7hhh-6rmp-j9qf
ghsa_updated
2026-10-01T15:20:28Z
ghsa_id
GHSA-7hhh-6rmp-j9qf
last_source
GitHub Advisory Database
cve_id
CVE-2026-89425
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (7)

VULNERABLE_TO (2)

←[Software]maven/tools.jackson.core:jackson-core
←[Software]maven/com.fasterxml.jackson.core:jackson-core

AFFECTS (2)

→[Software]maven/tools.jackson.core:jackson-core
→[Software]maven/com.fasterxml.jackson.core:jackson-core

REPORTED_BY (1)

→[Source]GitHub Advisory Database

HAS_WEAKNESS (2)

→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-89425 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal