Bug 2539084 (CVE-2026-89425)
| Summary: | CVE-2026-89425 com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aakkiang, abrianik, alinfoot, amctagga, anthomas, ant, anujha, aoconnor, aschwart, asoldano, asyoung, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, bniver, boliveir, bstansbe, ccranfor, cescoffi, cfu, cmah, csuconic, csutherl, dbruscin, dfreiber, dhanak, dlofthou, drichtar, drosa, drow, dschmidt, dsimansk, dsoumis, dtrifiro, ebaron, edewata, eglynn, ehelms, ehugonne, ewittman, flucifre, fmariani, fmongiar, gbenhaim, ggainey, ggrzybek, gkimetto, gmalinko, gmeno, groman, gsmet, gtanzill, gtully, istudens, ivassile, iweiss, janstey, jburrell, jbuscemi, jclere, jhollowa, jjoyce, jlanda, jmagne, jmartisk, jnethert, jpasqual, jpechane, jpretori, jraez, jschluet, jsherman, juwatts, jwon, kaycoth, kingland, kshier, kvanderr, lhh, manderse, mbenjamin, mburns, mcarlett, mdellweg, mfargett, mgarciac, mhackett, mhulan, mnovotny, mosmerov, mposolda, msvehla, nipatil, niyer, nmoumoul, nwallace, olubyans, osousa, ozzy, pantinor, parichar, pberan, pcreech, pdelbell, pesilva, pjindal, plodge, pmackay, prichard, prisingh, rchan, rgemmell, rgodfrey, rguimara, rhel-process-autobot, rkubis, rmartinc, rmaucher, rstancel, rstepani, sausingh, sbiarozk, sdawley, simaishi, skhandel, smallamp, snegrini, sostapov, ssilvert, stcannon, sthirugn, sthorger, szappis, taherrin, tasato, tbish, tcunning, thjenkin, tlavocat, tmalecek, twaugh, varjain, vdosoudi, vereddy, vkumar, vmuzikar, watson-tool-maintainers, weaton, yfang, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in FasterXML jackson-core. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted, malformed token to the JsonFactory.createParser(DataInput) method. The UTF8DataInputJsonParser component, responsible for handling DataInput sources, does not properly limit the size of the error message generated for invalid tokens. This unbounded growth of the StringBuilder can consume excessive memory, leading to an OutOfMemoryError and crashing the Java Virtual Machine (JVM).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2539285, 2539286, 2539287 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-23 02:31:20 UTC
|