{"id":"CVE-2026-89425","summary":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth","details":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.","aliases":["GHSA-7hhh-6rmp-j9qf"],"modified":"2026-09-24T03:47:12.826278921Z","published":"2026-09-23T02:06:10.571Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89425.json","cna_assigner":"HeroDevs","cwe_ids":["CWE-400","CWE-770"]},"references":[{"type":"WEB","url":"https://repo1.maven.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89425.json"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-core/pull/1698"},{"type":"PACKAGE","url":"https://github.com/FasterXML/jackson-core"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fasterxml/jackson-core","events":[{"introduced":"0"},{"fixed":"9a463a5207fa1d0175551fa2c4962a13e4dcdebf"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"2.8.0"}]}}],"versions":["jackson-core-2.7.3b","jackson-core-2.7.3","jackson-core-2.7.2","jackson-core-2.7.1","jackson-core-2.7.0","jackson-core-2.7.0-rc3","jackson-core-2.7.0-rc2","jackson-core-2.7.0-rc1","jackson-core-2.6.1","jackson-core-2.6.0","jackson-core-2.6.0-rc4","jackson-core-2.6.0-rc3","jackson-core-2.6.0-rc2","jackson-core-2.6.0-rc1","jackson-core-2.5.0","jackson-core-2.5.0-rc1","jackson-core-2.4.1.1","jackson-core-2.4.1","jackson-core-2.4.0","jackson-core-2.4.0-rc3","jackson-core-2.4.0-rc2","jackson-core-2.4.0-rc1","jackson-core-2.3.0","jackson-core-2.3.0-rc1","jackson-core-2.2.2","jackson-core-2.2.1","jackson-core-2.2.0b","jackson-core-2.2.0-rc1","jackson-core-2.0.2","jackson-core-2.0.1","jackson-core-2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89425.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}