Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text
for its error message by appending Java identifier characters to a StringBuilder in a loop that has no
upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never
consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a
parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No
StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at
all, and maxStringLength does not cover this path because the accumulation bypasses
ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a
20-million-character malformed token on the DataInput path, against 367 characters for identical input on
the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char
expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError
for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput);
releases before 2.8.0 do not contain the affected class. (CVE-2026-89425)
Solution
Update the hono-adapter-mqtt library and its related packages to version 2.7.0-r45 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 9/23/2026