Server-Side Request Forgery (SSRF) in jackson-databind - CVE-2026-54514

 

Server-Side Request Forgery (SSRF) in jackson-databind - CVE-2026-54514

Published: July 22, 2026


Vulnerability identifier: #VU139157
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54514
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause outbound DNS requests and disclose limited network information.

The vulnerability exists due to server-side request forgery in JDKFromStringDeserializer when deserializing untrusted JSON into a type containing an InetSocketAddress field. A remote attacker can supply a crafted hostname value to cause outbound DNS requests and disclose limited network information.

The DNS lookup occurs during readValue before application-level validation or explicit connection logic.


Affected software

jackson-databind
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Basesystem Module
Netezza Appliance
Db2 Bridge
CICS Transaction Gateway Desktop Edition
WebSphere Automation
IBM Sterling Connect:Direct Web Services
IBM Maximo Application Suite - Manage Component
IBM Common Licensing
Red Hat build of Quarkus
IBM SPSS Collaboration and Deployment Services
jackson-dataformat-cbor
jackson-annotations
jackson-core
jackson-databind
EntireX

How to mitigate CVE-2026-54514

Install security update from vendor's website.

jackson-databind - addressed in versions 2.18.8, 2.21.4, 3.1.4
Netezza Appliance - update to 1.0.2.0
Db2 Bridge - update to 1.1.5.1
WebSphere Automation - update to 1.13.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.20, 6.4.0.9
IBM Maximo Application Suite - Manage Component - addressed in versions 9.0.28, 9.1.20, 9.2.1
IBM Common Licensing - update to 9.1
jackson-dataformat-cbor - update to 2.18.8-150200.3.21.3
jackson-annotations - update to 2.18.8-150200.3.22.3
jackson-core - update to 2.18.8-150200.3.22.3
jackson-databind - update to 2.18.8-150200.3.28.2
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2
IBM SPSS Collaboration and Deployment Services - addressed in versions 8.4.0.0 IF005, 8.5.0.0 IF005, 8.6.0.0 IF005
EntireX - update to 12.1.0.0003-0779

External References

Related Security Bulletins