highCVSS 7.5Vulnerability

CVE-2026-91776

### Summary With `@JsonTypeInfo(use = Id.NAME, defaultImpl = ...)`, every distinct unknown raw type ID selects the same fallback deserializer but is retained as a separate key in `TypeDeserializerBase._deserializers`. An attacker who can repeatedly supply new unknown type IDs can grow this process-lifetime cache without a configured bound. ### Details The affected path is `TypeDeserializerBase._findDeserializer()`. After an unknown name-based type ID resolves to the configured fallback/default implementation, jackson-databind caches the result under the attacker-provided raw `typeId`. Although all such IDs select the same fallback deserializer, each new string remains a distinct cache key. The behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1. Current 2.22 and 3.2 source branches retained the unbounded `_deserializers` map and per-raw-ID cache write when rechecked. The earlier affected floor has not been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3. The vulnerable application must enable name-based polymorphism with a `defaultImpl` or equivalent fallback, accept attacker-influenced type IDs, and reuse a long-lived mapper/type deserializer across requests. Suggested correction: avoid caching each unknown raw ID when every such ID resolves to the same fallback, use a fallback sentinel, or use an explicitly bounded concurrency-safe cache. A regression should contrast many distinct unknown IDs with repetitions of one unknown ID across requests. ### PoC Configure a polymorphic base type with `@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class)` and deserialize inputs containing unknown type names through the same mapper. Inspect `TypeDeserializerBase._deserializers` after the run. On affected 2.x and 3.x versions, 10,000 distinct unknown raw type IDs produce 10,000 retained cache entries even though every input selects the same fallback deserializer. A matched control that repeats one unknown ID

Properties

summary
jackson-databind retains every unknown raw type ID
severity
high
cvss_score
7.5
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T15:36:55Z
source_url
https://github.com/advisories/GHSA-wv8q-qhhj-9h54
ghsa_updated
2026-09-30T15:36:57Z
ghsa_id
GHSA-wv8q-qhhj-9h54
last_source
GitHub Advisory Database
cve_id
CVE-2026-91776
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
false

Related Entities (6)

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (2)

←[Software]maven/tools.jackson.core:jackson-databind
←[Software]maven/com.fasterxml.jackson.core:jackson-databind

AFFECTS (2)

→[Software]maven/com.fasterxml.jackson.core:jackson-databind
→[Software]maven/tools.jackson.core:jackson-databind

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-91776 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal