Executive brief
Jackson-databind is a popular Java library used to convert data between JSON and Java objects. A flaw in how it handles data restrictions allows attackers to modify sensitive information, such as administrative settings or internal lists, even when those fields are marked as restricted. This could lead to unauthorized data changes or 'mass-assignment' attacks where an attacker updates fields they should not have access to.
Technical details
A vulnerability exists in jackson-databind's BeanDeserializer._deserializeUsingPropertyBased where @JsonView filters are incorrectly applied. While creator properties were properly filtered, the regular property-buffering branch lacked a visibility check. Due to a change where SetterlessProperty.isMerging() returns true, setterless Collection and Map properties are routed through this unguarded path. An attacker can exploit this by providing JSON input for fields that should be excluded by the active view, leading to an incorrect authorization (CWE-863) or mass-assignment vulnerability. The issue is fixed in versions 2.21.4 and 3.1.4.
Affected products
- FasterXML jackson-databind >= 2.21.0, < 2.21.4
- FasterXML jackson-databind >= 3.0.0, < 3.1.4
Timeline
- 2026-05-06: patched: Fix merged into 3.x branch
- 2026-05-07: patched: Fix backported to 2.21 branch
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD
References
- https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d
- https://github.com/FasterXML/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962
- https://github.com/FasterXML/jackson-databind/pull/5969
- https://github.com/FasterXML/jackson-databind/pull/5970
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38