<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Jackson-Core (2.19.0 - 2.21.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jackson-core-2.19.0---2.21.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:22:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jackson-core-2.19.0---2.21.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unbounded StringBuilder Growth in jackson-core via DataInput</title><link>https://feed.craftedsignal.io/briefs/2026-10-jackson-core-dos/</link><pubDate>Thu, 01 Oct 2026 20:22:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-jackson-core-dos/</guid><description>The jackson-core library suffers from a denial-of-service vulnerability (CVE-2026-89425) where malformed tokens in DataInput-backed parsers cause unbounded memory consumption, leading to potential JVM process crashes.</description><content:encoded><![CDATA[<p>FasterXML jackson-core is affected by an unbounded StringBuilder growth vulnerability located in the <code>UTF8DataInputJsonParser._reportInvalidToken()</code> method. This defect occurs when the parser is initialized via <code>JsonFactory.createParser(DataInput)</code>. Unlike other parser implementations in the library that correctly enforce a maximum error token length, this specific implementation fails to check <code>ErrorReportConfiguration.getMaxErrorTokenLength()</code> (default 256) when building exception messages for invalid tokens.</p>
<p>An attacker can trigger this by providing a long, malformed JSON token. Because the implementation appends characters one-by-one to an unbounded StringBuilder without bounds checking, the internal structure grows linearly with the input payload size. This expansion, compounded by byte-to-char conversion, can rapidly deplete heap memory. Critically, existing configuration mitigations such as <code>maxDocumentLength</code> or <code>maxStringLength</code> do not apply to this code path, leaving applications using the <code>DataInput</code> parser implementation without built-in defense against this denial-of-service vector.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to an <code>OutOfMemoryError</code> within the JVM hosting the vulnerable application. By supplying a large, malformed token, an attacker can cause the process to allocate excessive memory, forcing a crash and resulting in a denial-of-service for any system relying on this parser to process external JSON input. This affects a wide range of Jackson versions (2.8.0 through 3.2.2).</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>jackson-core</code> to a patched version once provided by the vendor.</li>
<li>If immediate patching is not possible, audit applications to determine if <code>JsonFactory.createParser(DataInput)</code> is used to process untrusted input.</li>
<li>Where possible, migrate from <code>DataInput</code> sources to <code>InputStream</code> or <code>Reader</code> based parsers, which currently enforce <code>maxErrorTokenLength</code> bounds correctly.</li>
<li>Implement application-level request size limits before passing data to the Jackson parser to mitigate the potential impact of large malicious payloads.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>java</category></item></channel></rss>