SB2026072278 - Multiple vulnerabilities in jackson-databind
Published: July 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to bypass write-side authorization restrictions and populate view-restricted properties from untrusted input.
The vulnerability exists due to improper access control in BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId when processing JSON input with creator properties annotated with @JsonView and @JsonTypeInfo(include=As.EXTERNAL_PROPERTY). A remote attacker can send specially crafted JSON input to bypass write-side authorization restrictions and populate view-restricted properties from untrusted input.
Exploitation requires a property-based @JsonCreator on the outer type, a creator parameter annotated with a restricted @JsonView, and the same parameter annotated with polymorphic @JsonTypeInfo using As.EXTERNAL_PROPERTY.
2) Incorrect authorization (CVE-ID: CVE-2026-59889)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in UnwrappedPropertyHandler.processUnwrapped() when deserializing @JsonUnwrapped container properties under a less-privileged active view. A remote user can supply crafted JSON values for a property annotated with both @JsonView and @JsonUnwrapped to escalate privileges.
This affects the write-side authorization behavior of @JsonView during deserialization, including merge and builder-based deserialization paths.
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to modify dynamically determined object attributes.
The vulnerability exists due to improper control of dynamically determined object attributes in jackson-databind record deserialization when applying a PropertyNamingStrategy to `@JsonIgnore`-annotated Record properties. A remote attacker can supply a specially crafted JSON key to modify dynamically determined object attributes.
This issue affects Java Records during deserialization when a naming strategy is used and `@JsonIgnore` is relied on to prevent a component from being set from input.
4) Incorrect authorization (CVE-ID: CVE-2026-54518)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to bypass write-side authorization restrictions and modify view-restricted creator parameters.
The vulnerability exists due to improper authorization in UnwrappedPropertyHandler.processUnwrappedCreatorProperties() when processing untrusted JSON input for unwrapped creator parameters. A remote attacker can supply crafted JSON data to bypass write-side authorization restrictions and modify view-restricted creator parameters.
This issue occurs when applications use @JsonView as a write-side authorization boundary together with constructor parameters annotated with both @JsonView and @JsonUnwrapped.
5) Incorrect authorization (CVE-ID: CVE-2026-54517)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to bypass access controls and modify view-restricted properties.
The vulnerability exists due to incorrect authorization in BeanDeserializer._deserializeUsingPropertyBased when deserializing property-based input with setterless collection or map creator properties. A remote attacker can send specially crafted JSON input to bypass access controls and modify view-restricted properties.
Only setterless collection or map properties annotated with a restricted @JsonView and processed under an active view are affected.
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to modify object attributes during deserialization.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in POJO deserialization handling when processing crafted JSON input for properties with a renamed getter and an ignored setter. A remote attacker can supply a renamed JSON key to modify object attributes during deserialization.
This issue occurs with private backing fields retained through property inference, allowing the setter's ignore annotation to be bypassed.
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to modify otherwise ignored object attributes.
The vulnerability exists due to improper control of dynamically determined object attributes in BeanDeserializerBase.createContextual() when processing case-insensitive deserialization with per-property @JsonIgnoreProperties exclusions. A remote attacker can send crafted JSON input to modify otherwise ignored object attributes.
Only applications that enable case-insensitive property matching and rely on per-property @JsonIgnoreProperties to keep a field unwritable are vulnerable.
8) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-54514)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause outbound DNS requests and disclose limited network information.
The vulnerability exists due to server-side request forgery in JDKFromStringDeserializer when deserializing untrusted JSON into a type containing an InetSocketAddress field. A remote attacker can supply a crafted hostname value to cause outbound DNS requests and disclose limited network information.
The DNS lookup occurs during readValue before application-level validation or explicit connection logic.
9) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-54513)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to instantiate non-allowlisted types.
The vulnerability exists due to incomplete list of disallowed inputs in BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() when deserializing attacker-controlled JSON containing array subtypes. A remote attacker can supply a crafted array wrapper to instantiate non-allowlisted types.
The issue occurs because array types are allowlisted based only on whether the class is an array, without validating the array component type against the configured allowlist, and no further validator check occurs for elements when per-element type IDs are absent.
10) Deserialization of Untrusted Data (CVE-ID: CVE-2026-54512)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to instantiate arbitrary classes.
The vulnerability exists due to deserialization of untrusted data in DatabindContext._resolveAndValidateGeneric() and PolymorphicTypeValidator handling when processing polymorphic type identifiers with generic parameters during deserialization. A remote attacker can supply a specially crafted type identifier and JSON data to instantiate arbitrary classes.
Only applications that accept untrusted JSON and have polymorphic typing enabled while relying on a configured PolymorphicTypeValidator allow-list are affected.
Remediation
Install update from vendor's website.
References
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w
- https://github.com/FasterXML/jackson-databind/commit/7dc7a17
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v
- https://github.com/FasterXML/jackson-databind/pull/5964
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f
- https://github.com/FasterXML/jackson-databind/pull/5983
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm