Chainguard: hono-adapter-mqtt: security update to 2.7.0-r45

high Tenable Self-Hosted Container Security Plugin ID 471646

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text
for its error message by appending Java identifier characters to a StringBuilder in a loop that has no
upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never
consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a
parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No
StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at
all, and maxStringLength does not cover this path because the accumulation bypasses
ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a
20-million-character malformed token on the DataInput path, against 367 characters for identical input on
the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char
expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError
for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput);
releases before 2.8.0 do not contain the affected class. (CVE-2026-89425)

Solution

Update the hono-adapter-mqtt library and its related packages to version 2.7.0-r45 or later.

Plugin Details

Severity: High

ID: 471646

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-89425

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/23/2026

Reference Information

CVE: CVE-2026-89425