Bug 2539084 (CVE-2026-89425)

Summary: CVE-2026-89425 com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aakkiang, abrianik, alinfoot, amctagga, anthomas, ant, anujha, aoconnor, aschwart, asoldano, asyoung, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, bniver, boliveir, bstansbe, ccranfor, cescoffi, cfu, cmah, csuconic, csutherl, dbruscin, dfreiber, dhanak, dlofthou, drichtar, drosa, drow, dschmidt, dsimansk, dsoumis, dtrifiro, ebaron, edewata, eglynn, ehelms, ehugonne, ewittman, flucifre, fmariani, fmongiar, gbenhaim, ggainey, ggrzybek, gkimetto, gmalinko, gmeno, groman, gsmet, gtanzill, gtully, istudens, ivassile, iweiss, janstey, jburrell, jbuscemi, jclere, jhollowa, jjoyce, jlanda, jmagne, jmartisk, jnethert, jpasqual, jpechane, jpretori, jraez, jschluet, jsherman, juwatts, jwon, kaycoth, kingland, kshier, kvanderr, lhh, manderse, mbenjamin, mburns, mcarlett, mdellweg, mfargett, mgarciac, mhackett, mhulan, mnovotny, mosmerov, mposolda, msvehla, nipatil, niyer, nmoumoul, nwallace, olubyans, osousa, ozzy, pantinor, parichar, pberan, pcreech, pdelbell, pesilva, pjindal, plodge, pmackay, prichard, prisingh, rchan, rgemmell, rgodfrey, rguimara, rhel-process-autobot, rkubis, rmartinc, rmaucher, rstancel, rstepani, sausingh, sbiarozk, sdawley, simaishi, skhandel, smallamp, snegrini, sostapov, ssilvert, stcannon, sthirugn, sthorger, szappis, taherrin, tasato, tbish, tcunning, thjenkin, tlavocat, tmalecek, twaugh, varjain, vdosoudi, vereddy, vkumar, vmuzikar, watson-tool-maintainers, weaton, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in FasterXML jackson-core. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted, malformed token to the JsonFactory.createParser(DataInput) method. The UTF8DataInputJsonParser component, responsible for handling DataInput sources, does not properly limit the size of the error message generated for invalid tokens. This unbounded growth of the StringBuilder can consume excessive memory, leading to an OutOfMemoryError and crashing the Java Virtual Machine (JVM).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539285, 2539286, 2539287    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-23 02:31:20 UTC
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.