« Volver al listado

CVE-2026-89425

Estado: AplazadaAlta (7.5)—

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full.

Leer descripción completaMostrar menos

No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/AC:L/PR:N permite explotación remota sin autenticación mediante token malformado. Acumulación sin límite en StringBuilder causa exhaustión de memoria (OutOfMemoryError) en la JVM, constituyendo DoS de aplicación.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89425",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-89425",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-23T13:54:51.050132Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
      "affectedData": [
        {
          "repo": "https://github.com/FasterXML/jackson-core",
          "vendor": "FasterXML",
          "product": "jackson-core",
          "versions": [
            {
              "status": "affected",
              "version": "2.8.0",
              "versionType": "maven",
              "lessThanOrEqual": "2.18.10"
            },
            {
              "status": "affected",
              "version": "2.19.0",
              "versionType": "maven",
              "lessThanOrEqual": "2.21.6"
            },
            {
              "status": "affected",
              "version": "2.22.0",
              "versionType": "maven",
              "lessThanOrEqual": "2.22.2"
            }
          ],
          "packageName": "com.fasterxml.jackson.core:jackson-core",
          "collectionURL": "https://repo1.maven.org/maven2",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "com.fasterxml.jackson.core.json.UTF8DataInputJsonParser._reportInvalidToken"
            }
          ]
        },
        {
          "repo": "https://github.com/FasterXML/jackson-core",
          "vendor": "FasterXML",
          "product": "jackson-core",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0",
              "versionType": "maven",
              "lessThanOrEqual": "3.1.6"
            },
            {
              "status": "affected",
              "version": "3.2.0",
              "versionType": "maven",
              "lessThanOrEqual": "3.2.2"
            }
          ],
          "packageName": "tools.jackson.core:jackson-core",
          "collectionURL": "https://repo1.maven.org/maven2",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "tools.jackson.core.json.UTF8DataInputJsonParser._reportInvalidToken"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-23T03:17:04.357",
  "references": [
    {
      "url": "https://github.com/FasterXML/jackson-core/pull/1698",
      "source": "36c7be3b-2937-45df-85ea-ca7133ea542c"
    },
    {
      "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf",
      "source": "36c7be3b-2937-45df-85ea-ca7133ea542c"
    },
    {
      "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "36c7be3b-2937-45df-85ea-ca7133ea542c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        },
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."
    }
  ],
  "lastModified": "2026-09-24T20:43:32.537",
  "sourceIdentifier": "36c7be3b-2937-45df-85ea-ca7133ea542c"
}