{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89425.json"}],"title":"com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing","tracking":{"current_release_date":"2026-09-23T05:46:31+00:00","generator":{"date":"2026-09-23T05:46:31+00:00","engine":{"name":"Red Hat SDEngine","version":"5.4.0"}},"id":"CVE-2026-89425","initial_release_date":"2026-09-23T02:06:10.571000+00:00","revision_history":[{"date":"2026-09-23T02:06:10.571000+00:00","number":"1","summary":"Initial version"},{"date":"2026-09-23T05:34:26+00:00","number":"2","summary":"Current version"},{"date":"2026-09-23T05:46:31+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Hardened Images","product":{"name":"Red Hat Hardened Images","product_id":"red_hat_hardened_images","product_identification_helper":{"cpe":"cpe:/a:redhat:hummingbird:1"}}}],"category":"product_family","name":"Red Hat Hardened Images"},{"category":"product_version","name":"maven3.9.src","product":{"name":"maven3.9.src","product_id":"maven3.9.src","product_identification_helper":{"purl":"pkg:rpm/redhat/maven3.9@3.9.16-0.2.hum1?arch=src"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"maven3.9.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:maven3.9.src"},"product_reference":"maven3.9.src","relates_to_product_reference":"red_hat_hardened_images"}]},"vulnerabilities":[{"cve":"CVE-2026-89425","cwe":{"id":"CWE-1050","name":"Excessive Platform Resource Consumption within a Loop"},"discovery_date":"2026-09-23T02:30:57.997196+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2539084"}],"notes":[{"category":"description","text":"A flaw was found in FasterXML jackson-core. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted, malformed token to the JsonFactory.createParser(DataInput) method. The UTF8DataInputJsonParser component, responsible for handling DataInput sources, does not properly limit the size of the error message generated for invalid tokens. This unbounded growth of the StringBuilder can consume excessive memory, leading to an OutOfMemoryError and crashing the Java Virtual Machine (JVM).","title":"Vulnerability description"},{"category":"summary","text":"com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing","title":"Vulnerability summary"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_hardened_images:maven3.9.src"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-89425"},{"category":"external","summary":"RHBZ#2539084","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539084"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-89425","url":"https://www.cve.org/CVERecord?id=CVE-2026-89425"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425"},{"category":"external","summary":"https://github.com/FasterXML/jackson-core/pull/1698","url":"https://github.com/FasterXML/jackson-core/pull/1698"},{"category":"external","summary":"https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","url":"https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"}],"release_date":"2026-09-23T02:06:10.571000+00:00","remediations":[{"category":"none_available","details":"Affected","product_ids":["red_hat_hardened_images:maven3.9.src"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["red_hat_hardened_images:maven3.9.src"]}],"threats":[{"category":"impact","details":"Important","product_ids":["red_hat_hardened_images:maven3.9.src"]}],"title":"com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing"}]}