#1148830 jackson-databind: CVE-2026-19032 CVE-2026-91776 CVE-2026-91777

Package:
src:jackson-databind
Source:
src:jackson-databind
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 07:03:02 UTC
Severity:
normal
Tags:
#1148830#5
Date:
2026-09-24 07:02:07 UTC
From:
To:
Hi,

The following vulnerabilities were published for jackson-databind.

CVE-2026-19032[0]:
| jackson-databind's deserializer for java.nio.file.Path resolves an
| attacker-supplied URI without restricting the URI scheme. In
| JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound
| from untrusted JSON is passed to new URI(value) and then to
| Path.of(uri). When that throws FileSystemNotFoundException, the code
| enumerates ServiceLoader<FileSystemProvider> and calls
| provider.getPath(uri) on the first provider whose scheme matches the
| attacker-chosen scheme. Untrusted JSON can therefore select and
| drive an arbitrary registered FileSystemProvider during readValue
| under a default JsonMapper, and forces provider class loading at the
| same time. With only the JDK built-in providers (file, jar/zipfs)
| present, the resolved path is inert and no mount or network I/O
| occurs; further impact requires a side-effecting third-party
| FileSystemProvider on the classpath. This affects
| com.fasterxml.jackson.core:jackson-databind from 2.8.0 before
| 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2,
| and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and
| from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6,
| 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted
| JSON should be avoided regardless of version.


CVE-2026-91776[1]:
| TypeDeserializerBase._findDeserializer() in FasterXML jackson-
| databind caches the resolved deserializer under the raw, attacker-
| supplied type ID. When name-based polymorphism is configured with a
| fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl =
| ...), every distinct unrecognized type ID resolves to the same
| fallback deserializer but is retained as its own key in the
| _deserializers map. That map has no configurable bound and lives for
| the lifetime of the type deserializer, so an attacker who can
| repeatedly supply fresh unknown type IDs causes monotonic memory
| retention across requests. The reporter observed 10,000 retained
| entries from 10,000 distinct unknown IDs, against a single entry for
| a control that repeated one unknown ID the same number of times,
| isolating attacker-controlled key cardinality from request volume.
| Exploitation requires an application that enables name-based
| polymorphism with a defaultImpl or equivalent fallback, accepts
| attacker-influenced type IDs, and reuses a long-lived ObjectMapper
| across requests. The fix stops caching fallback resolutions for
| unrecognized IDs and bounds both the number of cached entries and
| the length of a cacheable type ID.


CVE-2026-91777[2]:
| Forward-reference completion for @JsonIdentityInfo object IDs in
| FasterXML jackson-databind performs a linear scan of the pending-
| reference accumulator for every resolved ID. The affected paths are
| CollectionDeserializer.CollectionReferringAccumulator.resolveForward
| Reference() and the equivalent implementation in MapDeserializer.
| When a document first creates N unresolved object-ID references in
| an identity-enabled collection or map and then defines those same
| IDs in reverse order, completion performs on the order of N * (N +
| 1) / 2 identity comparisons, so a shallow document whose size grows
| linearly causes quadratic CPU work during deserialization. The
| reporter instrumented equals() calls on the ID class and measured
| exactly 2,003,000 comparisons at N = 2,000, against zero comparisons
| in the pending-reference lookup path for an equally sized control in
| which every reference was already resolved. The input requires no
| deep nesting and no syntactically unusual JSON. Exploitation
| requires an application that deserializes attacker-influenced JSON
| into an identity-enabled collection or map. The fix replaces the
| repeated linear lookup with a keyed pending-reference structure.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19032
https://www.cve.org/CVERecord?id=CVE-2026-19032
[1] https://security-tracker.debian.org/tracker/CVE-2026-91776
https://www.cve.org/CVERecord?id=CVE-2026-91776
[2] https://security-tracker.debian.org/tracker/CVE-2026-91777
https://www.cve.org/CVERecord?id=CVE-2026-91777

Regards,
Salvatore