Source: jackson-databind
Version: 2.14.0+ds-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/FasterXML/jackson-databind/issues/6156
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for jackson-databind.

CVE-2026-83557[0]:
| DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator
| applied automatically whenever @JsonTypeInfo is used without an
| explicitly configured custom validator. It denies polymorphic
| resolution only for a fixed set of "unsafe base types", and its
| isSafeSubType method returns true unconditionally for every base
| type outside that set. java.lang.Comparable was absent from the list
| despite being implemented by a very large fraction of JDK and
| application classes, comparable in breadth to java.io.Serializable,
| which is on the list for that reason. An application declaring an
| @JsonTypeInfo-annotated property or class with Comparable as its
| base type, and no custom PolymorphicTypeValidator, will accept a
| type identifier for essentially any class implementing Comparable.
| This yields an attacker-controlled object instantiation primitive; a
| demonstrated case constructs a java.io.File for an arbitrary
| attacker-chosen path, which becomes path-traversal-adjacent if the
| application subsequently calls path-sensitive methods on the value.
| No class implementing Comparable has been identified that yields
| code execution through deserialization alone. Global Default Typing
| via activateDefaultTyping is not affected, because that method
| structurally requires an explicit PolymorphicTypeValidator argument.
| This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0
| before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before
| 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before
| 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10,
| 2.21.6, 2.22.2, 3.1.6, or 3.2.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-83557
    https://www.cve.org/CVERecord?id=CVE-2026-83557
[1] 
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j
[2] https://github.com/FasterXML/jackson-databind/issues/6156
[3] https://github.com/FasterXML/jackson-databind/pull/6155

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to