<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:31:48 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-MR78444 — UTF8DataInputJsonParser</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-mr78444</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi package. UTF8DataInputJsonParser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi package. UTF8DataInputJsonParser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-mr78444</guid>
    </item>
    <item>
      <title>EUVD-2026-374068</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374068</link>
      <description>EUVD-2026-374068</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374068</guid>
    </item>
    <item>
      <title>fkie_cve-2026-89425</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89425</link>
      <description>&lt;p&gt;UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-89425</guid>
    </item>
    <item>
      <title>GHSA-7hhh-6rmp-j9qf — jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -&gt; unbounded StringBuilde…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hhh-6rmp-j9qf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-core, Maven: tools.jackson.core:jackson-core&lt;/p&gt;
&lt;p&gt;## Status&lt;/p&gt;
&lt;p&gt;**FULLY REPRODUCED.** A malformed token fed through `createParser(DataInput)` produced a
20,000,109-character exception message from a 20-million-character attacker payload, while the
identical payload fed through `createParser(InputStream)` produced a correctly bounded
367-character message.&lt;/p&gt;
&lt;p&gt;## Affected Component / Version&lt;/p&gt;
&lt;p&gt;- **Package:** `com.fasterxml.jackson.core:jackson-core`
- **Confirmed against:** `jackson-core-2.20.2`
- **Affected file:** `src/main/java/com/fasterxml/jackson/core/json/UTF8DataInputJsonParser.java`
  (`_reportInvalidToken(int, String, String)`, lines ~2763-2780 in the 2.20.2 tree)&lt;/p&gt;
&lt;p&gt;## Technical Analysis&lt;/p&gt;
&lt;p&gt;`UTF8DataInputJsonParser._reportInvalidToken()` builds the offending-token description for its
exception message by appending identifier characters one at a time to a bare `StringBuilder`:&lt;/p&gt;
&lt;p&gt;```java
protected void _reportInvalidToken(int ch, String matchedPart, String msg) throws IOException {
    StringBuilder sb = new StringBuilder(matchedPart);
    while (true) {
        char c = (char) _decodeCharForError(ch);
        if (!Character.isJavaIdentifierPart(c)) {
            break;
        }
        sb.append(c);
        ch = _inputData.readUnsignedByte();
    }
    _reportError(&amp;#34;Unrecognized token &amp;#39;&amp;#34;+sb.toString()+&amp;#34;&amp;#39;: was expecting &amp;#34;+msg);
}
```&lt;/p&gt;
&lt;p&gt;There is **no check against `ErrorReportConfiguration.getMaxErrorTokenLength()`** (default 256)
anywhere in this loop. By contrast, the sibling `UTF8StreamJsonParser` implementation of the
same l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-core, Maven: tools.jackson.core:jackson-core&lt;/p&gt;
&lt;p&gt;## Status&lt;/p&gt;
&lt;p&gt;**FULLY REPRODUCED.** A malformed token fed through `createParser(DataInput)` produced a
20,000,109-character exception message from a 20-million-character attacker payload, while the
identical payload fed through `createParser(InputStream)` produced a correctly bounded
367-character message.&lt;/p&gt;
&lt;p&gt;## Affected Component / Version&lt;/p&gt;
&lt;p&gt;- **Package:** `com.fasterxml.jackson.core:jackson-core`
- **Confirmed against:** `jackson-core-2.20.2`
- **Affected file:** `src/main/java/com/fasterxml/jackson/core/json/UTF8DataInputJsonParser.java`
  (`_reportInvalidToken(int, String, String)`, lines ~2763-2780 in the 2.20.2 tree)&lt;/p&gt;
&lt;p&gt;## Technical Analysis&lt;/p&gt;
&lt;p&gt;`UTF8DataInputJsonParser._reportInvalidToken()` builds the offending-token description for its
exception message by appending identifier characters one at a time to a bare `StringBuilder`:&lt;/p&gt;
&lt;p&gt;```java
protected void _reportInvalidToken(int ch, String matchedPart, String msg) throws IOException {
    StringBuilder sb = new StringBuilder(matchedPart);
    while (true) {
        char c = (char) _decodeCharForError(ch);
        if (!Character.isJavaIdentifierPart(c)) {
            break;
        }
        sb.append(c);
        ch = _inputData.readUnsignedByte();
    }
    _reportError(&amp;#34;Unrecognized token &amp;#39;&amp;#34;+sb.toString()+&amp;#34;&amp;#39;: was expecting &amp;#34;+msg);
}
```&lt;/p&gt;
&lt;p&gt;There is **no check against `ErrorReportConfiguration.getMaxErrorTokenLength()`** (default 256)
anywhere in this loop. By contrast, the sibling `UTF8StreamJsonParser` implementation of the
same l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hhh-6rmp-j9qf</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11876-1 — jackson-core-2.18.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11876-1</link>
      <description>&lt;p&gt;jackson-core-2.18.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-core-2.18.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11876-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-89425</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89425</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jackson-core, Ubuntu:18.04:LTS: jackson-core, Ubuntu:20.04:LTS: jackson-core, Ubuntu:22.04:LTS: jackson-core, Ubuntu:24.04:LTS: jackson-core, Ubuntu:26.04:LTS: jackson-core&lt;/p&gt;
&lt;p&gt;UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jackson-core, Ubuntu:18.04:LTS: jackson-core, Ubuntu:20.04:LTS: jackson-core, Ubuntu:22.04:LTS: jackson-core, Ubuntu:24.04:LTS: jackson-core, Ubuntu:26.04:LTS: jackson-core&lt;/p&gt;
&lt;p&gt;UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89425</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3532 — FasterXML Jackson: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3532</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3532</guid>
    </item>
  </channel>
</rss>
