Disclosure summary
### Summary With `@JsonTypeInfo(use = Id.NAME, defaultImpl = ...)`, every distinct unknown raw type ID selects the same fallback deserializer but is retained as a separate key in `TypeDeserializerBase._deserializers`. An attacker who can repeatedly supply new unknown type IDs can grow this process-lifetime cache without a configured bound. ### Details The affected path is `TypeDeserializerBase._findDeserializer()`. After an unknown name-based type ID resolves to the configured fallback/default implementation, jackson-databind caches the result under the attacker-provided raw `typeId`. Although all such IDs select the same fallback deserializer, each new string remains a distinct cache key. The behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1. Current 2.22 and 3.2 source branches retained the unbounded `_deserializers` map and per-raw-ID cache write when rechecked. The earlier affected floor has not been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3. The vulnerable application must enable name-based polymorphism with a `defaultImpl` or equivalent fallback, accept attacker-influenced type IDs, and reuse a long-lived mapper/type deserial
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-wv8q-qhhj-9h54
Open original source · Updated Sep 30, 2026
jackson-databind retains every unknown raw type ID
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | com.fasterxml.jackson.core:jackson-databind | >= 2.0.0, | 2.18.11 |
| maven | com.fasterxml.jackson.core:jackson-databind | >= 2.19.0, | 2.21.7 |
| maven | com.fasterxml.jackson.core:jackson-databind | >= 2.22.0, | 2.22.3 |
| maven | tools.jackson.core:jackson-databind | >= 3.0.0, | 3.1.7 |
| maven | tools.jackson.core:jackson-databind | >= 3.2.0, | 3.2.3 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:36:55-04:00
MODIFIED 2026-09-30T11:36:57-04:00
INGESTED 2026-10-06T11:43:09-04:00