Executive brief
FasterXML jackson-databind is a widely used Java library for converting data between JSON and Java objects. A vulnerability in how it handles network address data allows an attacker to force the application to perform unauthorized DNS lookups. This could be used by an attacker to map internal network infrastructure or facilitate data exfiltration through DNS-based side channels.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in jackson-databind's JDKFromStringDeserializer. When deserializing JSON data into a type containing an InetSocketAddress field, the library uses a constructor that triggers an immediate DNS lookup for the provided hostname. This occurs during the readValue process before any application-level validation can take place. An unauthenticated remote attacker can exploit this by submitting crafted JSON to trigger DNS queries to arbitrary hostnames, which can be used for internal network probing or out-of-band data exfiltration. The issue is resolved by using InetSocketAddress.createUnresolved() to defer resolution until an explicit connection is made. Fixes are available in versions 2.18.8, 2.21.4, and 3.1.4.
Affected products
- FasterXML jackson-databind >= 2.0.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4
Timeline
- 2026-05-06: patched: Fix merged into 2.18 branch
- 2026-06-04: other: Release of fixed versions 2.18.8, 2.21.4, and 3.1.4
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD