Junglewise Threat Intelligence

CVE-2026-54515: FasterXML jackson-databind property exclusion bypass in BeanDeserializerBase

CVE-2026-54515 · Severity: medium · CVSS 5.3 · Published 2026-06-23

Technologies: FasterXML Jackson Databind. Vendors: FasterXML.

Executive brief

Jackson-databind is a widely used Java library for converting data between JSON and Java objects. A flaw in how it handles specific configuration settings allows attackers to modify data fields that were intended to be protected or ignored. This could lead to unauthorized data changes, similar to a 'mass assignment' attack, where an attacker updates sensitive internal object properties that should not be accessible via public APIs.

Technical details

A vulnerability exists in BeanDeserializerBase.createContextual() where per-property @JsonIgnoreProperties exclusions are bypassed. When @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES) is used, the deserializer rebuilds its property map from the original unfiltered map (this._beanProperties) instead of the filtered contextual map. This action overwrites the exclusions applied by _handleByNameInclusion(), making ignored properties writable again. An attacker can exploit this via a network request to perform a mass-assignment attack against affected Java objects. The issue is fixed in versions 2.18.9, 2.21.5, and 3.1.4.

Affected products

  • FasterXML jackson-databind >= 2.8.0, < 2.18.9; >= 2.19.0, < 2.21.5; >= 3.1.0, < 3.1.4

Timeline

  • 2026-05-06: disclosed: Issue reported and fix developed in GitHub repository
  • 2026-06-04: patched: Official release of fixed versions
  • 2026-06-16: advisory: GitHub Security Advisory published
  • 2026-06-23: advisory: NVD publication date

References

Related threats