Allocation of Resources Without Limits or Throttling in jackson-core - CVE-2026-89425
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in UTF8DataInputJsonParser._reportInvalidToken() when processing malformed JSON tokens through a DataInput-backed parser. A remote attacker can supply a malformed token to cause a denial of service.