mediumCVSS 5.6Vulnerability

CVE-2026-83557

### Summary `DefaultBaseTypeLimitingValidator` — the `PolymorphicTypeValidator` used automatically whenever `@JsonTypeInfo` is applied without an explicitly configured custom validator — denies polymorphic resolution only for nine specific "unsafe base types" (`Object`, `Serializable`, `Closeable`, `AutoCloseable`, `Cloneable`, `Runnable`, `java.util.logging.Handler`, `javax.naming.Referenceable`, `javax.sql.DataSource`). Its `isSafeSubType()` returns `true` unconditionally for every other base type. `java.lang.Comparable` is not in that list, despite being implemented by a very large fraction of JDK and application classes — comparable in breadth to `Serializable`, which is denylisted for exactly that reason. An application with an `@JsonTypeInfo`-annotated `Comparable`-typed property, and no custom validator configured, will accept a type identifier for essentially any class implementing `Comparable`. ### Details **Affected file:** `src/main/java/tools/jackson/databind/jsontype/DefaultBaseTypeLimitingValidator.java` ```java private final static class UnsafeBaseTypes { private final Set<String> UNSAFE = new HashSet<>(); { UNSAFE.add(Object.class.getName()); UNSAFE.add(java.io.Closeable.class.getName()); UNSAFE.add(java.io.Serializable.class.getName()); UNSAFE.add(AutoCloseable.class.getName()); UNSAFE.add(Cloneable.class.getName()); UNSAFE.add(Runnable.class.getName()); // [databind#5014] UNSAFE.add("java.util.logging.Handler"); UNSAFE.add("javax.naming.Referenceable"); UNSAFE.add("javax.sql.DataSource"); // java.lang.Comparable is NOT present here } } protected boolean isSafeSubType(DatabindContext ctxt, JavaType baseType, JavaType subType) { return true; // unconditional for every base type not in UNSAFE } ``` The class's own JavaDoc acknowledges the design (*"Note that when using potentially unsafe base type like `java.lang.Object` a custom impl

Properties

severity
medium
summary
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
cvss_score
5.6
retrieved_at
2026-09-29T00:57:22+00:00
ghsa_published
2026-09-28T20:44:25Z
source_url
https://github.com/advisories/GHSA-gx83-3vf8-gh7j
ghsa_updated
2026-09-28T20:44:27Z
ghsa_id
GHSA-gx83-3vf8-gh7j
last_source
GitHub Advisory Database
cve_id
CVE-2026-83557
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-29T00:57:22+00:00
is_ghsa_only
false

Related Entities (7)

VULNERABLE_TO (2)

←[Software]maven/com.fasterxml.jackson.core:jackson-databind
←[Software]maven/tools.jackson.core:jackson-databind

AFFECTS (2)

→[Software]maven/tools.jackson.core:jackson-databind
→[Software]maven/com.fasterxml.jackson.core:jackson-databind

HAS_WEAKNESS (2)

→[Weakness]Deserialization of Untrusted Data
→[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-83557 (CVSS 5.6) — Ninja Signal Threat Intelligence | Ninja Signal