Skip to content

Improve InetSocketAddress deserialization [CVE-2026-54514] - #5951

Merged
cowtowncoder merged 5 commits into
2.18from
tatu/2.18/inet-socket-addr-deser
May 6, 2026
Merged

Improve InetSocketAddress deserialization [CVE-2026-54514]#5951
cowtowncoder merged 5 commits into
2.18from
tatu/2.18/inet-socket-addr-deser

Conversation

@cowtowncoder

@cowtowncoder cowtowncoder commented May 5, 2026

Copy link
Copy Markdown
Member

Should create "unresolved" instances to avoid DNS lookup.

@cowtowncoder cowtowncoder added the 2.18 Issues planned at 2.18 or later label May 5, 2026
@cowtowncoder cowtowncoder added this to the 2.18.8 milestone May 5, 2026
@cowtowncoder
cowtowncoder marked this pull request as ready for review May 6, 2026 00:01
@cowtowncoder
cowtowncoder merged commit 1f5a103 into 2.18 May 6, 2026
5 of 6 checks passed
@cowtowncoder
cowtowncoder deleted the tatu/2.18/inet-socket-addr-deser branch May 6, 2026 00:09
dongjoon-hyun added a commit to apache/spark that referenced this pull request Jun 5, 2026
### What changes were proposed in this pull request?

This PR upgrades `FasterXML` `Jackson` to 2.21.4.

### Why are the changes needed?

- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.21.4 (2026-05-28)
  - FasterXML/jackson-core#1611
  - FasterXML/jackson-databind#5931
  - FasterXML/jackson-databind#5950
  - FasterXML/jackson-databind#5951
  - FasterXML/jackson-databind#5967
  - FasterXML/jackson-databind#5969
  - FasterXML/jackson-databind#5971
  - FasterXML/jackson-databind#5974
  - FasterXML/jackson-databind#5981
  - FasterXML/jackson-databind#5988
  - FasterXML/jackson-databind#5993

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass the CIs.

### Was this patch authored or co-authored using generative AI tooling?

Generated-by: Claude Code (Claude Opus 4.8)

Closes #56338 from dongjoon-hyun/SPARK-57273.

Authored-by: Dongjoon Hyun <dongjoon@apache.org>
Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
@cowtowncoder cowtowncoder changed the title Improve InetSocketAddress deserialization Improve InetSocketAddress deserialization [CVE-2026-54514] Jun 16, 2026
@cowtowncoder cowtowncoder added 2.21 3.1 CVE Issues related to public CVEs (security vuln reports) labels Jun 16, 2026
cowtowncoder added a commit that referenced this pull request Jun 16, 2026
zenosaaur pushed a commit to neteye-platform/keycloak-oidc-groups-mapper that referenced this pull request Jul 28, 2026
> ℹ️ **Note**
> 
> This PR body was truncated due to platform limits.

This PR contains the following updates:

| Package | Type | Update | Change | OpenSSF |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Adoption](https://docs.renovatebot.com/merge-confidence/) |
[Passing](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|---|---|---|
|
[DavidAnson/markdownlint-cli2](https://redirect.github.com/DavidAnson/markdownlint-cli2)
| repository | patch | `v0.23.0` → `v0.23.2` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/DavidAnson/markdownlint-cli2/badge)](https://securityscorecards.dev/viewer/?uri=github.com/DavidAnson/markdownlint-cli2)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/DavidAnson%2fmarkdownlint-cli2/v0.23.2?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/DavidAnson%2fmarkdownlint-cli2/v0.23.2?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/DavidAnson%2fmarkdownlint-cli2/v0.23.0/v0.23.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/DavidAnson%2fmarkdownlint-cli2/v0.23.0/v0.23.2?slim=true)
|
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | patch | `v7.0.0` → `v7.0.1` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/actions/checkout/badge)](https://securityscorecards.dev/viewer/?uri=github.com/actions/checkout)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/actions%2fcheckout/v7.0.1?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/actions%2fcheckout/v7.0.1?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/actions%2fcheckout/v7.0.0/v7.0.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/actions%2fcheckout/v7.0.0/v7.0.1?slim=true)
|
|
[astral-sh/ruff-pre-commit](https://redirect.github.com/astral-sh/ruff-pre-commit)
| repository | minor | `v0.15.21` → `v0.16.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/astral-sh/ruff-pre-commit/badge)](https://securityscorecards.dev/viewer/?uri=github.com/astral-sh/ruff-pre-commit)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/astral-sh%2fruff-pre-commit/v0.16.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/astral-sh%2fruff-pre-commit/v0.16.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/astral-sh%2fruff-pre-commit/v0.15.21/v0.16.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/astral-sh%2fruff-pre-commit/v0.15.21/v0.16.0?slim=true)
|
|
[astral-sh/uv-pre-commit](https://redirect.github.com/astral-sh/uv-pre-commit)
| repository | patch | `0.11.28` → `0.11.33` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/astral-sh/uv-pre-commit/badge)](https://securityscorecards.dev/viewer/?uri=github.com/astral-sh/uv-pre-commit)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/astral-sh%2fuv-pre-commit/0.11.33?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/astral-sh%2fuv-pre-commit/0.11.33?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/astral-sh%2fuv-pre-commit/0.11.28/0.11.33?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/astral-sh%2fuv-pre-commit/0.11.28/0.11.33?slim=true)
|
|
[codespell-project/codespell](https://redirect.github.com/codespell-project/codespell)
| repository | patch | `v2.4.2` → `v2.4.3` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/codespell-project/codespell/badge)](https://securityscorecards.dev/viewer/?uri=github.com/codespell-project/codespell)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/codespell-project%2fcodespell/v2.4.3?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/codespell-project%2fcodespell/v2.4.3?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/codespell-project%2fcodespell/v2.4.2/v2.4.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/codespell-project%2fcodespell/v2.4.2/v2.4.3?slim=true)
|
|
[renovatebot/pre-commit-hooks](https://redirect.github.com/renovatebot/pre-commit-hooks)
| repository | minor | `43.263.1` → `43.285.6` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/renovatebot/pre-commit-hooks/badge)](https://securityscorecards.dev/viewer/?uri=github.com/renovatebot/pre-commit-hooks)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/renovatebot%2fpre-commit-hooks/43.285.6?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/renovatebot%2fpre-commit-hooks/43.285.6?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/renovatebot%2fpre-commit-hooks/43.263.1/43.285.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/renovatebot%2fpre-commit-hooks/43.263.1/43.285.6?slim=true)
|
|
[softprops/action-gh-release](https://redirect.github.com/softprops/action-gh-release)
| action | patch | `v3.0.1` → `v3.0.2` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/softprops/action-gh-release/badge)](https://securityscorecards.dev/viewer/?uri=github.com/softprops/action-gh-release)
|
![age](https://developer.mend.io/api/mc/badges/age/github-tags/softprops%2faction-gh-release/v3.0.2?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/github-tags/softprops%2faction-gh-release/v3.0.2?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/github-tags/softprops%2faction-gh-release/v3.0.1/v3.0.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/softprops%2faction-gh-release/v3.0.1/v3.0.2?slim=true)
|
|
[org.apache.maven.plugins:maven-source-plugin](https://maven.apache.org/plugins/)
([source](https://redirect.github.com/apache/maven-source-plugin)) |
build | minor | `3.2.1` → `3.4.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/maven-source-plugin/badge)](https://securityscorecards.dev/viewer/?uri=github.com/apache/maven-source-plugin)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-source-plugin/3.4.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.apache.maven.plugins:maven-source-plugin/3.4.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.apache.maven.plugins:maven-source-plugin/3.2.1/3.4.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-source-plugin/3.2.1/3.4.0?slim=true)
|
|
[org.apache.maven.plugins:maven-failsafe-plugin](https://maven.apache.org/surefire/)
([source](https://redirect.github.com/apache/maven-surefire)) | build |
patch | `3.5.2` → `3.5.6` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/maven-surefire/badge)](https://securityscorecards.dev/viewer/?uri=github.com/apache/maven-surefire)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-failsafe-plugin/3.5.6?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.apache.maven.plugins:maven-failsafe-plugin/3.5.6?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.apache.maven.plugins:maven-failsafe-plugin/3.5.2/3.5.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-failsafe-plugin/3.5.2/3.5.6?slim=true)
|
|
[org.apache.maven.plugins:maven-surefire-plugin](https://maven.apache.org/surefire/)
([source](https://redirect.github.com/apache/maven-surefire)) | build |
patch | `3.5.2` → `3.5.6` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/maven-surefire/badge)](https://securityscorecards.dev/viewer/?uri=github.com/apache/maven-surefire)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-surefire-plugin/3.5.6?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.apache.maven.plugins:maven-surefire-plugin/3.5.6?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.apache.maven.plugins:maven-surefire-plugin/3.5.2/3.5.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-surefire-plugin/3.5.2/3.5.6?slim=true)
|
|
[org.apache.maven.plugins:maven-compiler-plugin](https://maven.apache.org/plugins/)
([source](https://redirect.github.com/apache/maven-compiler-plugin)) |
build | minor | `3.10.1` → `3.15.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/maven-compiler-plugin/badge)](https://securityscorecards.dev/viewer/?uri=github.com/apache/maven-compiler-plugin)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-compiler-plugin/3.15.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.apache.maven.plugins:maven-compiler-plugin/3.15.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.apache.maven.plugins:maven-compiler-plugin/3.10.1/3.15.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-compiler-plugin/3.10.1/3.15.0?slim=true)
|
|
[com.diffplug.spotless:spotless-maven-plugin](https://redirect.github.com/diffplug/spotless)
| build | minor | `2.44.5` → `2.46.1` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/diffplug/spotless/badge)](https://securityscorecards.dev/viewer/?uri=github.com/diffplug/spotless)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/com.diffplug.spotless:spotless-maven-plugin/2.46.1?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/com.diffplug.spotless:spotless-maven-plugin/2.46.1?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/com.diffplug.spotless:spotless-maven-plugin/2.44.5/2.46.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/com.diffplug.spotless:spotless-maven-plugin/2.44.5/2.46.1?slim=true)
|
|
[com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt)
| test | minor | `10.0.2` → `10.9.1` | |
![age](https://developer.mend.io/api/mc/badges/age/maven/com.nimbusds:nimbus-jose-jwt/10.9.1?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/com.nimbusds:nimbus-jose-jwt/10.9.1?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/com.nimbusds:nimbus-jose-jwt/10.0.2/10.9.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/com.nimbusds:nimbus-jose-jwt/10.0.2/10.9.1?slim=true)
|
|
[com.fasterxml.jackson.core:jackson-databind](https://redirect.github.com/FasterXML/jackson)
([source](https://redirect.github.com/FasterXML/jackson-databind)) |
test | patch | `2.18.2` → `2.18.9` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/FasterXML/jackson-databind/badge)](https://securityscorecards.dev/viewer/?uri=github.com/FasterXML/jackson-databind)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/com.fasterxml.jackson.core:jackson-databind/2.18.9?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/com.fasterxml.jackson.core:jackson-databind/2.18.9?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/com.fasterxml.jackson.core:jackson-databind/2.18.2/2.18.9?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/com.fasterxml.jackson.core:jackson-databind/2.18.2/2.18.9?slim=true)
|
| [org.testcontainers:junit-jupiter](https://java.testcontainers.org)
([source](https://redirect.github.com/testcontainers/testcontainers-java))
| test | minor | `1.20.4` → `1.21.4` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/testcontainers/testcontainers-java/badge)](https://securityscorecards.dev/viewer/?uri=github.com/testcontainers/testcontainers-java)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.testcontainers:junit-jupiter/1.21.4?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.testcontainers:junit-jupiter/1.21.4?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.testcontainers:junit-jupiter/1.20.4/1.21.4?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.testcontainers:junit-jupiter/1.20.4/1.21.4?slim=true)
|
| [org.keycloak.bom:keycloak-spi-bom](http://keycloak.org)
([source](https://redirect.github.com/jboss/jboss-parent-pom)) | import
| minor | `26.6.2` → `26.7.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/jboss/jboss-parent-pom/badge)](https://securityscorecards.dev/viewer/?uri=github.com/jboss/jboss-parent-pom)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.keycloak.bom:keycloak-spi-bom/26.7.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.keycloak.bom:keycloak-spi-bom/26.7.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.keycloak.bom:keycloak-spi-bom/26.6.2/26.7.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.keycloak.bom:keycloak-spi-bom/26.6.2/26.7.0?slim=true)
|
| [org.keycloak:keycloak-services](http://keycloak.org)
([source](https://redirect.github.com/keycloak/keycloak)) | provided |
minor | `26.6.2` → `26.7.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/keycloak/keycloak/badge)](https://securityscorecards.dev/viewer/?uri=github.com/keycloak/keycloak)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.keycloak:keycloak-services/26.7.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.keycloak:keycloak-services/26.7.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.keycloak:keycloak-services/26.6.2/26.7.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.keycloak:keycloak-services/26.6.2/26.7.0?slim=true)
|
| [org.keycloak:keycloak-server-spi-private](http://keycloak.org)
([source](https://redirect.github.com/keycloak/keycloak)) | provided |
patch | `26.6.2` → `26.6.3` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/keycloak/keycloak/badge)](https://securityscorecards.dev/viewer/?uri=github.com/keycloak/keycloak)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.keycloak:keycloak-server-spi-private/26.6.3?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.keycloak:keycloak-server-spi-private/26.6.3?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.keycloak:keycloak-server-spi-private/26.6.2/26.6.3?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.keycloak:keycloak-server-spi-private/26.6.2/26.6.3?slim=true)
|
| [org.keycloak:keycloak-server-spi](http://keycloak.org)
([source](https://redirect.github.com/keycloak/keycloak)) | provided |
minor | `26.6.2` → `26.7.0` | [![OpenSSF
Scorecard](https://api.securityscorecards.dev/projects/github.com/keycloak/keycloak/badge)](https://securityscorecards.dev/viewer/?uri=github.com/keycloak/keycloak)
|
![age](https://developer.mend.io/api/mc/badges/age/maven/org.keycloak:keycloak-server-spi/26.7.0?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.keycloak:keycloak-server-spi/26.7.0?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.keycloak:keycloak-server-spi/26.6.2/26.7.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.keycloak:keycloak-server-spi/26.6.2/26.7.0?slim=true)
|

Note: The `pre-commit` manager in Renovate is not supported by the
`pre-commit` maintainers or community. Please do not report any problems
there, instead [create a Discussion in the Renovate
repository](https://redirect.github.com/renovatebot/renovate/discussions/new)
if you have any questions.

---

### jackson-databind has a PolymorphicTypeValidator bypass via generic
type parameters that allows arbitrary class instantiation
[CVE-2026-54512](https://nvd.nist.gov/vuln/detail/CVE-2026-54512) /
[GHSA-j3rv-43j4-c7qm](https://redirect.github.com/advisories/GHSA-j3rv-43j4-c7qm)

<details>
<summary>More information</summary>

#### Details
`jackson-databind`'s `PolymorphicTypeValidator` (PTV) is the primary
safety mechanism guarding polymorphic deserialization. When polymorphic
typing is enabled and a type identifier contains generic parameters
(i.e. the type ID string contains `<`),
`DatabindContext._resolveAndValidateGeneric()` validates **only the raw
container class name** (the substring before `<`) against the configured
PTV.

If the container type is approved, the method parses the full canonical
type string via `TypeFactory.constructFromCanonical()` and returns the
fully parameterized type **without ever validating the nested type
arguments** against the PTV. The nested type arguments are then
resolved, instantiated, and populated as beans during deserialization.

An attacker who controls the type ID can therefore place a denied class
as a generic type parameter of an allowed container — for example
`java.util.ArrayList<com.evil.Gadget>` when only `java.util.ArrayList`
is allow-listed. The container passes the PTV check; `com.evil.Gadget`
is loaded via `Class.forName(name, true, loader)`, instantiated, and its
properties are set from attacker-controlled JSON. This completely
bypasses an explicitly configured PTV allow-list.

This is the same vulnerability class responsible for the historical
sequence of jackson-databind deserialization CVEs; here it manifests as
a validator bypass rather than a missing deny-list entry.

##### Impact

- **Bypass of the PTV allow-list**, including the recommended
`BasicPolymorphicTypeValidator` configured with name-prefix allow rules.
- **Arbitrary class instantiation** of any type assignable to the
container's element/parameter position, with attacker-controlled
property values (setter/field injection).
- **Potential unauthenticated remote code execution** when a class with
exploitable side effects (JNDI lookup, JDBC/connection-pool
gadgets,`TemplatesImpl`-style loaders, etc.) is present on the
classpath.

Applications that accept untrusted JSON and rely on a configured PTV —
the documented, security-conscious configuration — are affected.

##### Proof of Concept

Configuration restricting polymorphic deserialization to a single safe
container:

```java
BasicPolymorphicTypeValidator ptv = BasicPolymorphicTypeValidator.builder()
        .allowIfSubType("java.util.ArrayList")
        .build();

ObjectMapper mapper = JsonMapper.builder()
        .polymorphicTypeValidator(ptv)
        .build();
```

Malicious payload (`Wrapper.value` is `Object` with `@JsonTypeInfo(use =
Id.CLASS, include = As.WRAPPER_ARRAY)`):

```json
{"value":["java.util.ArrayList<com.evil.EvilGadget>",[{"cmd":"calc.exe"}]]}
```

On vulnerable versions, `com.evil.EvilGadget` is instantiated and its
`cmd` property is set, despite only `java.util.ArrayList` being
allow-listed. On `2.18.8` / `2.21.4` / `3.1.4` the deserialization
throws `InvalidTypeIdException` before instantiation.

**Variant payloads** (all bypass an `ArrayList`/`HashMap` allow-list):

| Type ID | Smuggled type position |
|---|---|
| `java.util.ArrayList<Evil>` | list element |
| `java.util.HashMap<Evil,String>` | map key |
| `java.util.HashMap<String,Evil>` | map value |
| `java.util.ArrayList<java.util.ArrayList<Evil>>` | nested element |
| `java.util.ArrayList<Evil[]>` | array element |

---

##### Patches

Fixed in **2.18.8**, **2.21.4** and **3.1.4** via the changes for
[FasterXML/jackson-databind#5988](https://redirect.github.com/FasterXML/jackson-databind/issues/5988),
commit `434d6c511`. The fix adds recursive validation of each
non-trivial type parameter (and array element types appearing as
parameters) through the full PTV chain, with documented exemptions for
`Object` (wildcard resolution) and `Enum` types.

`PolymorphicTypeValidator` was added in 2.10.0 so vulnerability N/A for
versions prior to that.

#### Severity
- CVSS Score: 8.1 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm)
-
[https://github.com/FasterXML/jackson-databind/issues/5988](https://redirect.github.com/FasterXML/jackson-databind/issues/5988)
-
[https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5](https://redirect.github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-54512](https://nvd.nist.gov/vuln/detail/CVE-2026-54512)
-
[https://github.com/advisories/GHSA-j3rv-43j4-c7qm](https://redirect.github.com/advisories/GHSA-j3rv-43j4-c7qm)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-j3rv-43j4-c7qm)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind has an array subtype allowlist bypass in
BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
[CVE-2026-54513](https://nvd.nist.gov/vuln/detail/CVE-2026-54513) /
[GHSA-rmj7-2vxq-3g9f](https://redirect.github.com/advisories/GHSA-rmj7-2vxq-3g9f)

<details>
<summary>More information</summary>

#### Details
##### Summary
`BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()`
allowlists any array type based only on `clazz.isArray()`, without
validating the array's component (element) type against the configured
allowlist. A PTV built with `allowIfSubTypeIsArray()` plus an explicit
concrete-type allowlist therefore still permits `EvilType[]` even though
`EvilType` is not allowlisted. When Jackson deserializes the elements
and no per-element type IDs are present, it instantiates the component
type directly with no further PTV check, bypassing the allowlist.

##### Impact
Applications using `BasicPolymorphicTypeValidator` with
`allowIfSubTypeIsArray()` as a safeguard get no protection for concrete
array component types; an attacker controlling JSON can instantiate
non-allowlisted types via an array wrapper, re-opening the
gadget-instantiation risk PTV is meant to prevent.

##### Affected / Patched (verified via `git tag --contains`)
- 2.18 line: `>= 2.10.0, < 2.18.8` -> fixed in **2.18.8**
- 2.19-2.21 line: `>= 2.19.0, < 2.21.4` -> fixed in **2.21.4**
- 3.x line: `>= 3.0.0, < 3.1.4` -> fixed in **3.1.4**

`PolymorphicTypeValidator` was added in 2.10.0 so vulnerability N/A for
versions prior to that.

##### Severity / CWE
Maintainer: significant. Reporter: HIGH. CWE-184 (Incomplete List of
Disallowed Inputs); related CWE-502.

##### Upstream fix
FasterXML/jackson-databind#5981; fix PR #&#8203;5983 (`24529da`), 2.18
backport PR #&#8203;5984 (`01d1692`). Released 2026-06-04 in 2.18.8 /
2.21.4 / 3.1.4.

##### Credits
Omkhar Arasaratnam (@&#8203;omkhar) - finder.

#### Severity
- CVSS Score: 8.1 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f)
-
[https://github.com/FasterXML/jackson-databind/issues/5981](https://redirect.github.com/FasterXML/jackson-databind/issues/5981)
-
[https://github.com/FasterXML/jackson-databind/issues/5983](https://redirect.github.com/FasterXML/jackson-databind/issues/5983)
-
[https://github.com/FasterXML/jackson-databind/pull/5984](https://redirect.github.com/FasterXML/jackson-databind/pull/5984)
-
[https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5](https://redirect.github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5)
-
[https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e](https://redirect.github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-54513](https://nvd.nist.gov/vuln/detail/CVE-2026-54513)
-
[https://access.redhat.com/errata/RHSA-2026:36839](https://access.redhat.com/errata/RHSA-2026:36839)
-
[https://access.redhat.com/errata/RHSA-2026:40895](https://access.redhat.com/errata/RHSA-2026:40895)
-
[https://access.redhat.com/security/cve/CVE-2026-54513](https://access.redhat.com/security/cve/CVE-2026-54513)
-
[https://bugzilla.redhat.com/show_bug.cgi?id=2492010](https://bugzilla.redhat.com/show_bug.cgi?id=2492010)
-
[https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json)
-
[https://access.redhat.com/errata/RHSA-2026:41951](https://access.redhat.com/errata/RHSA-2026:41951)
-
[https://access.redhat.com/errata/RHSA-2026:43218](https://access.redhat.com/errata/RHSA-2026:43218)
-
[https://access.redhat.com/errata/RHSA-2026:44271](https://access.redhat.com/errata/RHSA-2026:44271)
-
[https://access.redhat.com/errata/RHSA-2026:44066](https://access.redhat.com/errata/RHSA-2026:44066)
-
[https://access.redhat.com/errata/RHSA-2026:44065](https://access.redhat.com/errata/RHSA-2026:44065)
-
[https://access.redhat.com/errata/RHSA-2026:44064](https://access.redhat.com/errata/RHSA-2026:44064)
-
[https://access.redhat.com/errata/RHSA-2026:44063](https://access.redhat.com/errata/RHSA-2026:44063)
-
[https://access.redhat.com/errata/RHSA-2026:44062](https://access.redhat.com/errata/RHSA-2026:44062)
-
[https://access.redhat.com/errata/RHSA-2026:44061](https://access.redhat.com/errata/RHSA-2026:44061)
-
[https://access.redhat.com/errata/RHSA-2026:43400](https://access.redhat.com/errata/RHSA-2026:43400)
-
[https://github.com/advisories/GHSA-rmj7-2vxq-3g9f](https://redirect.github.com/advisories/GHSA-rmj7-2vxq-3g9f)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-rmj7-2vxq-3g9f)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind: InetSocketAddress deserialization triggers eager
DNS resolution (SSRF)
[CVE-2026-54514](https://nvd.nist.gov/vuln/detail/CVE-2026-54514) /
[GHSA-hgj6-7826-r7m5](https://redirect.github.com/advisories/GHSA-hgj6-7826-r7m5)

<details>
<summary>More information</summary>

#### Details
##### Summary
`JDKFromStringDeserializer` constructed `InetSocketAddress` with `new
InetSocketAddress(host, port)`, which performs eager DNS name resolution
for hostname inputs at deserialization time. An application that binds
untrusted JSON into a type containing an `InetSocketAddress` field
issues an attacker-chosen DNS query during `readValue`, before any
application-level validation or connect logic. The fix uses
`InetSocketAddress.createUnresolved(host, port)`, deferring DNS to an
explicit connect.

##### Impact
An attacker controlling JSON deserialized into an
`InetSocketAddress`-bearing type can force outbound DNS lookups for
attacker-chosen hostnames at deserialization time (SSRF / DNS-based
out-of-band interaction / internal-resolver probing), purely from
binding.

##### Affected / Patched (verified via `git tag --contains` on
`1f5a103`)
- 2.18 line: `>= 2.18.0, < 2.18.8` -> fixed in **2.18.8**
- 2.19-2.21 line: `>= 2.19.0, < 2.21.4` -> fixed in **2.21.4**
- 3.x line: `>= 3.0.0, < 3.1.4` -> fixed in **3.1.4**

##### Severity / CWE
Maintainer: minor. Reporter: LOW. CWE-918 (SSRF).

##### Upstream fix
FasterXML/jackson-databind#5951 ("Improve InetSocketAddress
deserialization"). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.

##### Credits
Omkhar Arasaratnam (@&#8203;omkhar) - finder.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5)
-
[https://github.com/FasterXML/jackson-databind/pull/5951](https://redirect.github.com/FasterXML/jackson-databind/pull/5951)
-
[https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4](https://redirect.github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-54514](https://nvd.nist.gov/vuln/detail/CVE-2026-54514)
-
[https://github.com/advisories/GHSA-hgj6-7826-r7m5](https://redirect.github.com/advisories/GHSA-hgj6-7826-r7m5)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-hgj6-7826-r7m5)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind has case-insensitive deserialization bypasses
per-property @&#8203;JsonIgnoreProperties
[CVE-2026-54515](https://nvd.nist.gov/vuln/detail/CVE-2026-54515) /
[GHSA-5jmj-h7xm-6q6v](https://redirect.github.com/advisories/GHSA-5jmj-h7xm-6q6v)

<details>
<summary>More information</summary>

#### Details
##### Summary
In `BeanDeserializerBase.createContextual()`, per-property
`@JsonIgnoreProperties` exclusions are applied by
`_handleByNameInclusion()`, producing a `contextual` deserializer whose
`BeanPropertyMap` has the ignored properties removed. The subsequent
per-property case-insensitivity block (triggered by
`@JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)`) rebuilds from
`this._beanProperties` (the original, unfiltered map) instead of
`contextual._beanProperties`, then overwrites the filtered map —
restoring every property `_handleByNameInclusion` had just removed. The
ignored property becomes writable again.

##### Impact
An application that both enables case-insensitive matching and relies on
per-property `@JsonIgnoreProperties` to keep a field unwritable can have
that field set from untrusted JSON (mass-assignment-style write).

##### Affected / Patched
Will be fixed in 2.18.9, 2.21.5, 2.22.1 and 3.1.4.

##### Severity / CWE
Maintainer: minor. Reporter: Moderate. CWE-915.

##### Upstream fix
FasterXML/jackson-databind#5962 (PR #&#8203;5964, `0e1b0b2`), milestone
3.1.4. Released 2026-06-04.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v)
-
[https://github.com/FasterXML/jackson-databind/issues/5962](https://redirect.github.com/FasterXML/jackson-databind/issues/5962)
-
[https://github.com/FasterXML/jackson-databind/issues/5964](https://redirect.github.com/FasterXML/jackson-databind/issues/5964)
-
[https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa](https://redirect.github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-54515](https://nvd.nist.gov/vuln/detail/CVE-2026-54515)
-
[https://github.com/advisories/GHSA-5jmj-h7xm-6q6v](https://redirect.github.com/advisories/GHSA-5jmj-h7xm-6q6v)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-5jmj-h7xm-6q6v)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind: @&#8203;JsonIgnore on a Record property is
bypassed with a PropertyNamingStrategy
[CVE-2026-59888](https://nvd.nist.gov/vuln/detail/CVE-2026-59888) /
[GHSA-3pjw-73gf-8qr5](https://redirect.github.com/advisories/GHSA-3pjw-73gf-8qr5)

<details>
<summary>More information</summary>

#### Details
##### Summary
For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()`
records a `@JsonIgnore`-annotated component under its original implicit
name before `_renameUsing()` applies the `PropertyNamingStrategy`. After
the rename, `_ignoredPropertyNames` still holds only the pre-rename
name, so `_ignorableProps` is built from the stale key. The renamed JSON
key passes `IgnorePropertiesUtil.shouldIgnore()` and is assigned to the
Record's constructor parameter, defeating the `@JsonIgnore`.

##### Impact
A Record using a naming strategy that relies on `@JsonIgnore` to keep an
internal/privileged component out of deserialization can have that
component set from the wire via its renamed key (e.g. a role/flag
controlled by an untrusted client).

##### Affected / Patched (verified via `git tag --contains`)
- 2.15-2.18 line: `>= 2.15.0, < 2.18.8` -> fixed in **2.18.8** (backport
`c7c6783`)
- 2.19-2.21 line: `>= 2.19.0, < 2.21.4` -> fixed in **2.21.4**
- 3.x line: `>= 3.0.0, < 3.1.4` -> fixed in **3.1.4** (#&#8203;5974,
`baa2cdf`)

##### Severity / CWE
Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345.

##### Credits
Omkhar Arasaratnam (@&#8203;omkhar) - finder.

#### Severity
- CVSS Score: 6.5 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59888](https://nvd.nist.gov/vuln/detail/CVE-2026-59888)
-
[https://github.com/FasterXML/jackson-databind/pull/5974](https://redirect.github.com/FasterXML/jackson-databind/pull/5974)
-
[https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4](https://redirect.github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4)
-
[https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d](https://redirect.github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d)
-
[https://github.com/advisories/GHSA-3pjw-73gf-8qr5](https://redirect.github.com/advisories/GHSA-3pjw-73gf-8qr5)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-3pjw-73gf-8qr5)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind: `@JsonView` bypass for creator properties with
`@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

[GHSA-mhm7-754m-9p8w](https://redirect.github.com/advisories/GHSA-mhm7-754m-9p8w)

<details>
<summary>More information</summary>

#### Details
##### Summary

In `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`,
the active-view (`@JsonView`) filter was applied only to the regular
bean-property branch; the creator-property branch performed no
`creatorProp.visibleInView(activeView)` check. A constructor parameter
annotated with both `@JsonView(RestrictedView.class)` and
`@JsonTypeInfo(use=Id.NAME,
include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when
a more restrictive view is active.

This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc
(CVE-2026-54518) descriptions cover only the main property-based path
and the unwrapped-creator path respectively; the external-type-id
creator path was fixed on the 3.x line via #&#8203;6004 ("Extend
#&#8203;5969/#&#8203;5971 fixes to ... external-type-id case in regular
BeanDeserializer", commit 7dc7a17, 2026-05-22) but
**the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and
2.18.8 who upgraded per the published advisories remain vulnerable to
the same `@JsonView` bypass technique via a different code path.

##### Vulnerable Code Path

File: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`
Method: `deserializeUsingPropertyBasedWithExternalTypeId`

On 2.21.4 (and 2.18.8), the creator-property branch (around line
1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to
`ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without
ever consulting `visibleInView(activeView)`:

 ```java
  if (creatorProp != null) {
// [databind#1381]: if useInput=FALSE, skip deserialization from input
      if (creatorProp.isInjectionOnly()) { ... }
      // NO visibleInView(activeView) CHECK HERE
      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {
          if (buffer.assignParameter(creatorProp, ...)) { ... }
      }
      continue;
  }
```

On 3.1.4, the same branch contains the additional guard (commit 7dc7a17):

 ```java
   if (creatorProp != null) {
      // [databind#5971]: must honor active view here too
      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {
          p.skipChildren();
          continue;
      }
      ...
  }
```

The 2.21 and 2.18 backport PRs (#&#8203;6005 and #&#8203;6003) only
backported the main-path fixes from #&#8203;5969/#&#8203;5971; the
external-type-id fix from #&#8203;6004 was not backported. The
maintainer closed #&#8203;6005
with "got changes merged forward, looks like it's all covered now", but
the forward-merge did not include the ExtTypeId creator branch.

  Proof of Concept

  Compiles and runs against jackson-databind 2.21.4:
 
```java
  import com.fasterxml.jackson.annotation.*;
  import com.fasterxml.jackson.databind.ObjectMapper;

  public class JsonViewExternalTypeIdBypass {
      public static class PublicView {}
      public static class AdminView extends PublicView {}

      public static abstract class Asset { public String name; }
      public static class PublicAsset extends Asset {}
      public static class AdminAsset extends Asset { public String secret; }

      public static class Container {
          @&#8203;JsonTypeInfo(use = JsonTypeInfo.Id.NAME,
                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,
                  property = "kind")
          @&#8203;JsonSubTypes({
              @&#8203;JsonSubTypes.Type(value = PublicAsset.class, name = "pub"),
              @&#8203;JsonSubTypes.Type(value = AdminAsset.class,  name = "admin")
          })
          @&#8203;JsonView(AdminView.class)
          public Asset asset;

          public String label;

          @&#8203;JsonCreator
          public Container(
                  @&#8203;JsonProperty("label") String label,
                  @&#8203;JsonProperty("asset") @&#8203;JsonView(AdminView.class) Asset asset) {
              this.label = label;
              this.asset = asset;
          }
      }

      public static class Wrapper {
          @&#8203;JsonView(PublicView.class)
          public Container data;
      }

      public static void main(String[] args) throws Exception {
          // Admin-only "asset" should be blocked when reading with PublicView
          String json = "{\"data\":{\"label\":\"hello\",\"kind\":\"admin\","
                      + "\"asset\":{\"name\":\"foo\",\"secret\":\"LEAKED\"}}}";

          ObjectMapper om = new ObjectMapper();
          Wrapper r = om.readerWithView(PublicView.class)
                  .forType(Wrapper.class)
                  .readValue(json);

          System.out.println(r.data);
          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}
          // Expected (secure):  Container{label='hello', asset=null}
          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {
              System.out.println("[!!] BYPASS CONFIRMED — admin-only asset populated under PublicView");
          }
      }
  }
```

A control case that removes include = As.EXTERNAL_PROPERTY (forcing the
normal property-based path) correctly returns asset = null, confirming
the bypass is specific to the ExternalTypeId
  code path and not a misconfiguration.

##### Impact

View-restricted (e.g. admin-only) creator properties can be populated
from untrusted input where @&#8203;JsonView is used as a write-side
authorization boundary. Typical victims are Spring Boot
REST controllers that use @&#8203;JsonView(PublicView.class) on the
request body to whitelist user-settable fields — an attacker can inject
the restricted creator parameter (including choosing
the polymorphic subtype via the sibling kind/type-id property) by
combining it with a polymorphic @&#8203;JsonTypeInfo(EXTERNAL_PROPERTY)
annotation on the same field.

- CWE-863 (Incorrect Authorization)
- Same impact class as CVE-2026-54517 / CVE-2026-54518
- No RCE, no DoS — this is an access-control / mass-assignment bypass

##### Trigger Conditions

Developer code must combine (no opt-in user configuration required):

1. Property-based @&#8203;JsonCreator on the outer type
2. A creator parameter annotated with
@&#8203;JsonView(RestrictedView.class)
3. The same parameter annotated with @&#8203;JsonTypeInfo(use=Id.NAME,
include=As.EXTERNAL_PROPERTY, property="...")

#### Severity
- CVSS Score: 6.5 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w)
-
[https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed](https://redirect.github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed)
-
[https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c](https://redirect.github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c)
-
[https://github.com/advisories/GHSA-mhm7-754m-9p8w](https://redirect.github.com/advisories/GHSA-mhm7-754m-9p8w)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-mhm7-754m-9p8w)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### jackson-databind: @&#8203;JsonView ypassed for @&#8203;JsonUnwrapped
container properties on deserialization
[CVE-2026-59889](https://nvd.nist.gov/vuln/detail/CVE-2026-59889) /
[GHSA-5gvw-p9qm-jgwh](https://redirect.github.com/advisories/GHSA-5gvw-p9qm-jgwh)

<details>
<summary>More information</summary>

#### Details
##### Summary
`UnwrappedPropertyHandler.processUnwrapped()` replays the buffered JSON
for a `@JsonUnwrapped` property by iterating its properties and calling
`prop.deserializeAndSet()` with **no
`prop.visibleInView(ctxt.getActiveView())` guard** — the exact guard
`processUnwrappedCreatorProperties()` received in the #&#8203;5971 /
GHSA-rcqc-6cw3-h962 fix, and the guard
`BeanDeserializer.deserializeWithUnwrapped` applies to directly-matched
properties. As a result, a property annotated with both
`@JsonView(PrivilegedView.class)` and `@JsonUnwrapped` is written from
attacker JSON even when deserializing under a more-restrictive active
view.

**Correction to the original framing (runtime-verified):** the gap is
NOT a per-field inner `@JsonView` (the unwrapped sub-object's own
`BeanDeserializer` gates inner fields correctly). The unchecked gate is
the **view of the unwrapped CONTAINER property**.

##### Intent proof (runtime, 2.x HEAD 21dd70dd and 3.x HEAD 7a5939d6)
An `@JsonView(AdminView)` property that is NOT `@JsonUnwrapped` → `null`
under `PublicView` (correctly gated). The identical property WITH
`@JsonUnwrapped` → fully populated (bypass). The fix the creator path
already received, not applied to the regular-property method.

##### Impact — write-side mass-assignment / privilege escalation
`@JsonView` is commonly used as a write-side authorization guard: a
public endpoint binds the body under `readerWithView(PublicView.class)`
and groups privileged state in a nested object whose container property
is `@JsonView(AdminView)`. When that property is `@JsonUnwrapped`, an
untrusted caller mass-assigns it. PoC: a self-service registration where
`AccountFlags{role,approved,creditBalance}` is `@JsonView(AdminView)
@&#8203;JsonUnwrapped`; attacker JSON
`{role:ADMIN,approved:true,creditBalance:1000000}` under `PublicView`
binds all three → approved admin with arbitrary balance. The failing
gate is a WRITE gate, hence integrity-high (`C:N/I:H/A:N`); no worse
than the C:L/I:L parent and arguably higher as
`@JsonView`-as-write-guard is the exact use case
#&#8203;5971/#&#8203;5969 defended.

##### Affected
- `com.fasterxml.jackson.core:jackson-databind` 2.x: confirmed bypass at
21dd70dd (== released 2.21.4 / 2.22.0 line; includes the #&#8203;5973
backport). `DEFAULT_VIEW_INCLUSION` default=true.
- `tools.jackson.core:jackson-databind` 3.x: confirmed bypass at HEAD
7a5939d6 (latest 3.x). `DEFAULT_VIEW_INCLUSION` default=false → the
stock-config repro is the common shape where privileged inner fields are
individually `@JsonView(PublicView)` and the developer relies on the
container `@JsonView(AdminView)`; the 3.x PoC mass-assigns
role/approved/creditBalance under PublicView. (The other simultaneous
report's PoC was reportedly fixed on 3.x; this distinct
container-property path is not.)

##### Additive variants (runtime-confirmed both branches; all closed by
the same one-line guard)
- nested `@JsonUnwrapped` (unwrapped-in-unwrapped) — recursive bypass.
- merge / `readerWithView(...).withValueToUpdate(...)`
(PATCH/partial-update) — bypass; non-unwrapped merge control gates
correctly.
- builder-based deserializer (`@JsonDeserialize(builder=...)`) —
`BuilderBasedDeserializer` routes through the same `processUnwrapped`.
- Honest non-findings: read-side serialization correctly honors views
(no leak); `@JsonAnySetter`+view and `@JsonTypeInfo`+`@JsonUnwrapped`
are separate/unsupported behaviors, not this bug.

##### Fix
Add `prop.visibleInView(ctxt.getActiveView())` (when
`MapperFeature.DEFAULT_VIEW_INCLUSION`/active-view applies) to the
`processUnwrapped()` property loop, mirroring
`processUnwrappedCreatorProperties()`. One change closes the impact PoC
+ all three variants across `BeanDeserializer` and
`BuilderBasedDeserializer`. Full runnable PoCs (2.x + 3.x) + variant
harnesses available on request.

#### Severity
- CVSS Score: 6.5 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N`

#### References
-
[https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh](https://redirect.github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59889](https://nvd.nist.gov/vuln/detail/CVE-2026-59889)
-
[https://github.com/FasterXML/jackson-databind/issues/6060](https://redirect.github.com/FasterXML/jackson-databind/issues/6060)
-
[https://github.com/FasterXML/jackson-databind/pull/6056](https://redirect.github.com/FasterXML/jackson-databind/pull/6056)
-
[https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b](https://redirect.github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b)
-
[https://github.com/advisories/GHSA-5gvw-p9qm-jgwh](https://redirect.github.com/advisories/GHSA-5gvw-p9qm-jgwh)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-5gvw-p9qm-jgwh)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Keycloak: Policy bypass during WebAuthn credential registration via
client-side JavaScript manipulation
[CVE-2026-8830](https://nvd.nist.gov/vuln/detail/CVE-2026-8830) /
[GHSA-g8vr-x4qh-25qg](https://redirect.github.com/advisories/GHSA-g8vr-x4qh-25qg)

<details>
<summary>More information</summary>

#### Details
A flaw was found in Keycloak. An authenticated user can bypass
configured WebAuthn policies during credential registration by
manipulating client-side JavaScript. This occurs because the server-side
processAction() fails to validate that the newly created credential's
parameters, such as public key algorithms, match the realm's configured
WebAuthn policies. This could lead to the creation of credentials that
do not adhere to administrative security requirements, potentially
weakening the overall security posture of the system by allowing
non-compliant authentication methods.

#### Severity
- CVSS Score: 4.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-8830](https://nvd.nist.gov/vuln/detail/CVE-2026-8830)
-
[https://access.redhat.com/security/cve/CVE-2026-8830](https://access.redhat.com/security/cve/CVE-2026-8830)
-
[https://bugzilla.redhat.com/show_bug.cgi?id=2479565](https://bugzilla.redhat.com/show_bug.cgi?id=2479565)
-
[https://github.com/keycloak/keycloak/issues/49133](https://redirect.github.com/keycloak/keycloak/issues/49133)
-
[https://github.com/keycloak/keycloak/pull/49344](https://redirect.github.com/keycloak/keycloak/pull/49344)
-
[https://github.com/keycloak/keycloak/commit/47b9aef70948564151af85fd52e0d7e508c76490](https://redirect.github.com/keycloak/keycloak/commit/47b9aef70948564151af85fd52e0d7e508c76490)
-
[https://github.com/keycloak/keycloak/commit/d3da77ef363d698e7a74470ba52fcdce09e394c4](https://redirect.github.com/keycloak/keycloak/commit/d3da77ef363d698e7a74470ba52fcdce09e394c4)
-
[https://access.redhat.com/errata/RHSA-2026:25098](https://access.redhat.com/errata/RHSA-2026:25098)
-
[https://access.redhat.com/errata/RHSA-2026:25097](https://access.redhat.com/errata/RHSA-2026:25097)
-
[https://access.redhat.com/errata/RHSA-2026:30049](https://access.redhat.com/errata/RHSA-2026:30049)
-
[https://access.redhat.com/errata/RHSA-2026:30050](https://access.redhat.com/errata/RHSA-2026:30050)
-
[https://github.com/advisories/GHSA-g8vr-x4qh-25qg](https://redirect.github.com/advisories/GHSA-g8vr-x4qh-25qg)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-g8vr-x4qh-25qg)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Keycloak: Insufficient verification proof scoping enables identity
provider account linking attack and account compromise
[CVE-2026-9087](https://nvd.nist.gov/vuln/detail/CVE-2026-9087) /
[GHSA-m6qj-3mpp-57v8](https://redirect.github.com/advisories/GHSA-m6qj-3mpp-57v8)

<details>
<summary>More information</summary>

#### Details
A flaw was found in Keycloak. The cross-session verification proof is
keyed only by (local userId,
idpAlias) and is not bound to the upstream identity that was actually
verified, so a second upstream account on the same IdP can consume it
and get linked to the victim's local account.

#### Severity
- CVSS Score: 6.4 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-9087](https://nvd.nist.gov/vuln/detail/CVE-2026-9087)
-
[https://access.redhat.com/security/cve/CVE-2026-9087](https://access.redhat.com/security/cve/CVE-2026-9087)
-
[https://bugzilla.redhat.com/show_bug.cgi?id=2480172](https://bugzilla.redhat.com/show_bug.cgi?id=2480172)
-
[https://access.redhat.com/errata/RHSA-2026:25098](https://access.redhat.com/errata/RHSA-2026:25098)
-
[https://github.com/keycloak/keycloak/commit/37dabf59d0b5ca3e5b3b272bcd3b2580e67b94dd](https://redirect.github.com/keycloak/keycloak/commit/37dabf59d0b5ca3e5b3b272bcd3b2580e67b94dd)
-
[https://access.redhat.com/errata/RHSA-2026:25097](https://access.redhat.com/errata/RHSA-2026:25097)
-
[https://github.com/keycloak/keycloak/releases/tag/26.6.3](https://redirect.github.com/keycloak/keycloak/releases/tag/26.6.3)
-
[https://access.redhat.com/errata/RHSA-2026:30049](https://access.redhat.com/errata/RHSA-2026:30049)
-
[https://access.redhat.com/errata/RHSA-2026:30050](https://access.redhat.com/errata/RHSA-2026:30050)
-
[https://github.com/advisories/GHSA-m6qj-3mpp-57v8](https://redirect.github.com/advisories/GHSA-m6qj-3mpp-57v8)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-m6qj-3mpp-57v8)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Keycloak Vulnerable to Improper Validation of Specified Quantity in
Input
[CVE-2026-9704](https://nvd.nist.gov/vuln/detail/CVE-2026-9704) /
[GHSA-rr5q-3xwr-f323](https://redirect.github.com/advisories/GHSA-rr5q-3xwr-f323)

<details>
<summary>More information</summary>

#### Details
A flaw was found in Keycloak. An authenticated user with low privileges
can exploit this vulnerability by sending an oversized subject_token
JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a
4000-character limit, it is silently dropped, causing the system to fall
back to client credentials. This allows the user to gain the permissions
of the client's service account, leading to privilege escalation.

#### Severity
- CVSS Score: 6.8 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-9704](https://nvd.nist.gov/vuln/detail/CVE-2026-9704)
-
[https://access.redhat.com/security/cve/CVE-2026-9704](https://access.redhat.com/security/cve/CVE-2026-9704)
-
[https://bugzilla.redhat.com/show_bug.cgi?id=2481877](https://bugzilla.redhat.com/show_bug.cgi?id=2481877)
-
[https://access.redhat.com/errata/RHSA-2026:25098](https://access.redhat.com/errata/RHSA-2026:25098)
-
[https://access.redhat.com/errata/RHSA-2026:25097](https://access.redhat.com/errata/RHSA-2026:25097)
-
[https://access.redhat.com/errata/RHSA-2026:30049](https://access.redhat.com/errata/RHSA-2026:30049)
-
[https://access.redhat.com/errata/RHSA-2026:30050](https://access.redhat.com/errata/RHSA-2026:30050)
-
[https://github.com/keycloak/keycloak/issues/49435](https://redirect.github.com/keycloak/keycloak/issues/49435)
-
[https://github.com/keycloak/keycloak/pull/49472](https://redirect.github.com/keycloak/keycloak/pull/49472)
-
[https://github.com/keycloak/keycloak/commit/f1e5b7776c42938d0782fd5846346b8f75c815e6](https://redirect.github.com/keycloak/keycloak/commit/f1e5b7776c42938d0782fd5846346b8f75c815e6)
-
[https://github.com/advisories/GHSA-rr5q-3xwr-f323](https://redirect.github.com/advisories/GHSA-rr5q-3xwr-f323)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-rr5q-3xwr-f323)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Keycloak Vulnerable to Incorrect Authorization
[CVE-2026-9791](https://nvd.nist.gov/vuln/detail/CVE-2026-9791) /
[GHSA-4q93-v92x-p89f](https://redirect.github.com/advisories/GHSA-4q93-v92x-p89f)

<details>
<summary>More information</summary>

#### Details
A flaw was found in Keycloak. An authenticated user with existing
organization membership can exploit this flaw by accessing user-facing
APIs, such as the account API or by requesting an OpenID Connect (OIDC)
token with the 'organization' scope. This allows organization metadata
to be disclosed in tokens, even after an administrator has explicitly
disabled the Organizations feature, potentially leading to incorrect
authorization decisions by resource servers.

#### Severity
- CVSS Score: 4.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-9791](https://nvd.nist.gov/vuln/detail/CVE-2026-9791)
-
[https://access.redhat.com/security/cve/CVE-2026-9791](https://access.redhat.com/security/cve/CVE-2026-9791)
-
[https://bugzilla.redhat.com/show_bug.cgi?id=2482458](https://bugzilla.redhat.com/show_bug.cgi?id=2482458)
-
[https://access.redhat.com/errata/RHSA-2026:25098](https://access.redhat.com/errata/RHSA-2026:25098)
-
[https://access.redhat.com/errata/RHSA-2026:25097](https://access.redhat.com/errata/RHSA-2026:25097)
-
[https://access.redhat.com/errata/RHSA-2026:30049](https://access.redhat.com/errata/RHSA-2026:30049)
-
[https://access.redhat.com/errata/RHSA-2026:30050](https://access.redhat.com/errata/RHSA-2026:30050)
-
[https://github.com/keycloak/keycloak/issues/49431](https://redirect.github.com/keycloak/keycloak/issues/49431)
-
[https://github.com/keycloak/keycloak/pull/49541](https://redirect.github.com/keycloak/keycloak/pull/49541)
-
[https://github.com/keycloak/keycloak/pull/49678](https://redirect.github.com/keycloak/keycloak/pull/49678)
-
[https://github.com/keycloak/keycloak/pull/49680](https://redirect.github.com/keycloak/keycloak/pull/49680)
-
[https://github.com/keycloak/keycloak/commit/0e706e7c83d1e971b48656ad9e674eec6adc225b](https://redirect.github.com/keycloak/keycloak/commit/0e706e7c83d1e971b48656ad9e674eec6adc225b)
-
[https://github.com/keycloak/keycloak/commit/a77c60f2f3e0793046add44120579871e92553df](https://redirect.github.com/keycloak/keycloak/commit/a77c60f2f3e0793046add44120579871e92553df)
-
[https://github.com/keycloak/keycloak/commit/f19e1f2b4e998116d4e321f50ecf99c0f87b862f](https://redirect.github.com/keycloak/keycloak/commit/f19e1f2b4e998116d4e321f50ecf99c0f87b862f)
- [

> ✂ **Note**
> 
> PR body was truncated to here.

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2.18 Issues planned at 2.18 or later 2.21 3.1 CVE Issues related to public CVEs (security vuln reports)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant