CVE-2026-89425 Overview
CVE-2026-89425 is a resource exhaustion vulnerability [CWE-400] in FasterXML jackson-core. The flaw resides in UTF8DataInputJsonParser._reportInvalidToken(), which builds an error message by appending Java identifier characters to a StringBuilder without an upper bound. Unlike sibling parsers such as UTF8StreamJsonParser, this method never consults ErrorReportConfiguration.getMaxErrorTokenLength(). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) accumulates in full, allowing an attacker to trigger an OutOfMemoryError that terminates the JVM.
Critical Impact
A 20-million-character malformed token produces a 20,000,109-character exception message on the DataInput path, versus 367 characters on the InputStream path, enabling denial of service against any service parsing untrusted JSON through DataInput.
Affected Products
- FasterXML jackson-core versions 2.8.0 and later that expose UTF8DataInputJsonParser
- Applications invoking JsonFactory.createParser(DataInput) on untrusted input
- Downstream Java services and frameworks that embed jackson-core for JSON parsing
Discovery Timeline
- 2026-09-23 - CVE-2026-89425 published to the National Vulnerability Database
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-89425
Vulnerability Analysis
The defect lives in the error-reporting path of UTF8DataInputJsonParser. When the parser encounters an invalid token, _reportInvalidToken() iterates over incoming bytes and appends each Java identifier character to a StringBuilder. The loop terminates only when the input stream stops delivering identifier characters, so an attacker controls its runtime and memory footprint.
Three sibling parser implementations honor ErrorReportConfiguration.getMaxErrorTokenLength(), which defaults to 256 characters. The DataInput variant does not. As a result, the size of the accumulated token equals the size of the malformed input rather than the configured cap.
The StreamReadConstraints framework does not help either. The maxDocumentLength setting is not applied to DataInput sources, and maxStringLength covers only text buffered through ReadConstrainedTextBuffer, which this code path bypasses. Byte-to-char expansion and repeated internal array doubling amplify the payload well beyond its raw size.
Root Cause
The root cause is a missing bounds check in _reportInvalidToken(). The method was introduced together with createParser(DataInput) in jackson-core 2.8.0 and never received the length-limiting logic present in UTF8StreamJsonParser. Because none of the standard read constraints apply to this path, no runtime configuration can neutralize the flaw.
Attack Vector
An unauthenticated remote attacker sends a JSON document containing a very long malformed token to any endpoint that parses input through JsonFactory.createParser(DataInput). The parser attempts to build a diagnostic error message, growing the StringBuilder until the JVM raises OutOfMemoryError. The error is not confined to the request thread and can terminate the entire process.
No verified public exploit code is available. Consult the GitHub Security Advisory GHSA-7hhh-6rmp-j9qf and GitHub Pull Request #1698 for the authoritative technical description and fix.
Detection Methods for CVE-2026-89425
Indicators of Compromise
- Repeated java.lang.OutOfMemoryError events in application logs originating from com.fasterxml.jackson.core.json.UTF8DataInputJsonParser
- Exception messages containing extremely long token fragments, often millions of characters in length
- Sudden JVM heap growth followed by process termination immediately after inbound JSON traffic
Detection Strategies
- Inventory Java services that call JsonFactory.createParser(DataInput) and confirm the resolved jackson-core version at runtime
- Search source repositories and container images for jackson-core artifacts at versions 2.8.0 or later that have not been patched
- Add software composition analysis rules that flag vulnerable jackson-core coordinates in build manifests
Monitoring Recommendations
- Alert on JVM heap saturation and full garbage collection storms correlated with JSON ingestion endpoints
- Track HTTP requests carrying oversized payloads or abnormally long unquoted token sequences
- Monitor for parser stack traces referencing _reportInvalidToken in centralized log analytics
How to Mitigate CVE-2026-89425
Immediate Actions Required
- Upgrade jackson-core to the patched release referenced in GHSA-7hhh-6rmp-j9qf
- Audit application code for JsonFactory.createParser(DataInput) usage on untrusted input and refactor to InputStream or Reader sources where feasible
- Enforce request size limits at load balancers, API gateways, and reverse proxies in front of Java services
Patch Information
The fix is delivered through FasterXML/jackson-core Pull Request #1698, which aligns UTF8DataInputJsonParser._reportInvalidToken() with the bounded behavior of sibling parsers by honoring ErrorReportConfiguration.getMaxErrorTokenLength(). Consumers should upgrade to the corresponding released version identified in the advisory. Releases prior to 2.8.0 do not contain the affected class and are not vulnerable.
Workarounds
- Replace createParser(DataInput) calls with createParser(InputStream) so that maxStringLength and maxErrorTokenLength protections apply
- Cap inbound JSON payload size at the network edge to reduce the maximum accumulated token length
- Isolate parsers that must consume untrusted DataInput in a dedicated JVM with strict heap limits and automated restart
# Example Maven dependency override to pin a patched jackson-core version
mvn versions:use-dep-version -Dincludes=com.fasterxml.jackson.core:jackson-core -DdepVersion=<patched-version> -DforceVersion=true
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.