{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afasterxmljackson-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fasterxml:jackson-core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89425"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["jackson-core (2.8.0 - 2.18.10)","jackson-core (2.19.0 - 2.21.6)","jackson-core (2.22.0 - 2.22.2)","jackson-core (3.0.0 - 3.1.6)","jackson-core (3.2.0 - 3.2.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","java"],"_cs_type":"advisory","_cs_vendors":["FasterXML"],"content_html":"\u003cp\u003eFasterXML jackson-core is affected by an unbounded StringBuilder growth vulnerability located in the \u003ccode\u003eUTF8DataInputJsonParser._reportInvalidToken()\u003c/code\u003e method. This defect occurs when the parser is initialized via \u003ccode\u003eJsonFactory.createParser(DataInput)\u003c/code\u003e. Unlike other parser implementations in the library that correctly enforce a maximum error token length, this specific implementation fails to check \u003ccode\u003eErrorReportConfiguration.getMaxErrorTokenLength()\u003c/code\u003e (default 256) when building exception messages for invalid tokens.\u003c/p\u003e\n\u003cp\u003eAn attacker can trigger this by providing a long, malformed JSON token. Because the implementation appends characters one-by-one to an unbounded StringBuilder without bounds checking, the internal structure grows linearly with the input payload size. This expansion, compounded by byte-to-char conversion, can rapidly deplete heap memory. Critically, existing configuration mitigations such as \u003ccode\u003emaxDocumentLength\u003c/code\u003e or \u003ccode\u003emaxStringLength\u003c/code\u003e do not apply to this code path, leaving applications using the \u003ccode\u003eDataInput\u003c/code\u003e parser implementation without built-in defense against this denial-of-service vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to an \u003ccode\u003eOutOfMemoryError\u003c/code\u003e within the JVM hosting the vulnerable application. By supplying a large, malformed token, an attacker can cause the process to allocate excessive memory, forcing a crash and resulting in a denial-of-service for any system relying on this parser to process external JSON input. This affects a wide range of Jackson versions (2.8.0 through 3.2.2).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ejackson-core\u003c/code\u003e to a patched version once provided by the vendor.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, audit applications to determine if \u003ccode\u003eJsonFactory.createParser(DataInput)\u003c/code\u003e is used to process untrusted input.\u003c/li\u003e\n\u003cli\u003eWhere possible, migrate from \u003ccode\u003eDataInput\u003c/code\u003e sources to \u003ccode\u003eInputStream\u003c/code\u003e or \u003ccode\u003eReader\u003c/code\u003e based parsers, which currently enforce \u003ccode\u003emaxErrorTokenLength\u003c/code\u003e bounds correctly.\u003c/li\u003e\n\u003cli\u003eImplement application-level request size limits before passing data to the Jackson parser to mitigate the potential impact of large malicious payloads.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T20:22:17Z","date_published":"2026-10-01T20:22:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-jackson-core-dos/","summary":"The jackson-core library suffers from a denial-of-service vulnerability (CVE-2026-89425) where malformed tokens in DataInput-backed parsers cause unbounded memory consumption, leading to potential JVM process crashes.","title":"Unbounded StringBuilder Growth in jackson-core via DataInput","url":"https://feed.craftedsignal.io/briefs/2026-10-jackson-core-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:fasterxml:jackson-Core:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}