Source: jackson-databind Version: 2.14.0+ds-2 Severity: important Tags: security upstream Forwarded: https://github.com/FasterXML/jackson-databind/issues/6156 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jackson-databind. CVE-2026-83557[0]: | DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator | applied automatically whenever @JsonTypeInfo is used without an | explicitly configured custom validator. It denies polymorphic | resolution only for a fixed set of "unsafe base types", and its | isSafeSubType method returns true unconditionally for every base | type outside that set. java.lang.Comparable was absent from the list | despite being implemented by a very large fraction of JDK and | application classes, comparable in breadth to java.io.Serializable, | which is on the list for that reason. An application declaring an | @JsonTypeInfo-annotated property or class with Comparable as its | base type, and no custom PolymorphicTypeValidator, will accept a | type identifier for essentially any class implementing Comparable. | This yields an attacker-controlled object instantiation primitive; a | demonstrated case constructs a java.io.File for an arbitrary | attacker-chosen path, which becomes path-traversal-adjacent if the | application subsequently calls path-sensitive methods on the value. | No class implementing Comparable has been identified that yields | code execution through deserialization alone. Global Default Typing | via activateDefaultTyping is not affected, because that method | structurally requires an explicit PolymorphicTypeValidator argument. | This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 | before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before | 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before | 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, | 2.21.6, 2.22.2, 3.1.6, or 3.2.2. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-83557 https://www.cve.org/CVERecord?id=CVE-2026-83557 [1] https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j [2] https://github.com/FasterXML/jackson-databind/issues/6156 [3] https://github.com/FasterXML/jackson-databind/pull/6155 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

