Vulnerability GHSA-wv8q-qhhj-9h54

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
September 30, 2026 at 03:36 PM UTC
jackson-databind retains every unknown raw type ID
2.4.0 - 2.4.1 and 2.4.6 and 2.8.0 - 2.8.1 and 2.8.9 - 2.9.1 and 2.9.10 - 2.11.0 and 2.12.7 and 2.13.3 - 2.13.5
2.4.0 - 2.4.1 and 2.4.6 and 2.8.0 - 2.8.1 and 2.8.9 - 2.9.1 and 2.9.10 - 2.11.0 and 2.12.7 and 2.13.3 - 2.13.5

Summary

jackson-databind retains every unknown raw type ID

Details

Summary

With @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unknown raw type ID selects the same fallback deserializer but is retained as a separate key in TypeDeserializerBase._deserializers. An attacker who can repeatedly supply new unknown type IDs can grow this process-lifetime cache without a configured bound.

Details

The affected path is TypeDeserializerBase._findDeserializer(). After an unknown name-based type ID resolves to the configured fallback/default implementation, jackson-databind caches the result under the attacker-provided raw typeId. Although all such IDs select the same fallback deserializer, each new string remains a distinct cache key.

The behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1. Current 2.22 and 3.2 source branches retained the unbounded _deserializers map and per-raw-ID cache write when rechecked. The earlier affected floor has not been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.

The vulnerable application must enable name-based polymorphism with a defaultImpl or equivalent fallback, accept attacker-influenced type IDs, and reuse a long-lived mapper/type deserializer across requests.

Suggested correction: avoid caching each unknown raw ID when every such ID resolves to the same fallback, use a fallback sentinel, or use an explicitly bounded concurrency-safe cache. A regression should contrast many distinct unknown IDs with repetitions of one unknown ID across requests.

PoC

Configure a polymorphic base type with @JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class) and deserialize inputs containing unknown type names through the same mapper. Inspect TypeDeserializerBase._deserializers after the run.

On affected 2.x and 3.x versions, 10,000 distinct unknown raw type IDs produce 10,000 retained cache entries even though every input selects the same fallback deserializer. A matched control that repeats one unknown ID 10,000 times produces one retained entry. This isolates attacker-controlled key cardinality from ordinary request count.

Impact

Where the stated polymorphic fallback configuration is exposed to attacker-influenced type IDs, distinct inputs cause incremental process-lifetime memory retention and eventual availability pressure or denial of service. This is not claimed as a single-request allocation spike, and no fixed bytes-per-ID or time-to-out-of-memory value is asserted. No confidentiality, integrity, or code-execution impact is claimed.

Requested credit: Daniel Birtwhistle

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 hours ago
jackson-databind quadratic forward-reference completion
>=2.5.0 <2.5.6, >=2.6.0 <2.6.8, ==2.10.0, ==2.10.0.pr1, ==2.10.0.pr2, ==2.10.0.pr3, >=2.10.1 <2.10.6, ==2.10.5.1, ==2.11.0, ==2.11.0.rc1, >=2.11.1 <2.11.5, >=2.12.0 <2.12.7, ==2.12.6.1, ==2.12.7, ==2.12.7.1, ==2.12.7.2, >=2.13.0 <2.13.3, ==2.13.2.1, ==2.13.2.2, ==2.13.3, ==2.13.4, ==2.13.4.1, ==2.13.4.2, ==2.13.5, >=2.14.0 <2.14.4, >=2.15.0 <2.15.5, >=2.16.0 <2.16.3, >=2.17.0 <2.17.4, >=2.18.0 <2.18.11, >=2.19.0 <2.19.5, >=2.20.0 <2.20.3, >=2.21.0 <2.21.7, ==2.6.7.1, ==2.6.7.2, ==2.6.7.3, ==2.6.7.4, ==2.6.7.5, >=2.7.0 <2.7.10, ==2.7.9.1, ==2.7.9.2, ==2.7.9.3, ==2.7.9.4, ==2.7.9.5, ==2.7.9.6, ==2.7.9.7, ==2.8.0, ==2.8.0.rc1, ==2.8.0.rc2, ==2.8.1, ==2.8.10, ==2.8.11, ==2.8.11.1, ==2.8.11.2, ==2.8.11.3, ==2.8.11.4, ==2.8.11.5, ==2.8.11.6, >=2.8.2 <2.8.9, ==2.8.8.1, ==2.8.9, ==2.9.0, ==2.9.0.pr1, ==2.9.0.pr2, ==2.9.0.pr3, ==2.9.0.pr4, ==2.9.1, ==2.9.10, ==2.9.10.1, ==2.9.10.2, ==2.9.10.3, ==2.9.10.4, ==2.9.10.5, ==2.9.10.6, ==2.9.10.7, ==2.9.10.8, >=2.9.2 <2.9.10, >=2.22.0 <2.22.3, ==2.9.9.1, ==2.9.9.2, ==2.9.9.3 GHSA-cxp5-3px4-pw24
>=2.5.0 <2.5.6, >=2.6.0 <2.6.8, ==2.10.0, ==2.10.0.pr1, ==2.10.0.pr2, ==2.10.0.pr3, >=2.10.1 <2.10.6, ==2.10.5.1, ==2.11.0, ==2.11.0.rc1, >=2.11.1 <2.11.5, >=2.12.0 <2.12.7, ==2.12.6.1, ==2.12.7, ==2.12.7.1, ==2.12.7.2, >=2.13.0 <2.13.3, ==2.13.2.1, ==2.13.2.2, ==2.13.3, ==2.13.4, ==2.13.4.1, ==2.13.4.2, ==2.13.5, >=2.14.0 <2.14.4, >=2.15.0 <2.15.5, >=2.16.0 <2.16.3, >=2.17.0 <2.17.4, >=2.18.0 <2.18.11, >=2.19.0 <2.19.5, >=2.20.0 <2.20.3, >=2.21.0 <2.21.7, ==2.6.7.1, ==2.6.7.2, ==2.6.7.3, ==2.6.7.4, ==2.6.7.5, >=2.7.0 <2.7.10, ==2.7.9.1, ==2.7.9.2, ==2.7.9.3, ==2.7.9.4, ==2.7.9.5, ==2.7.9.6, ==2.7.9.7, ==2.8.0, ==2.8.0.rc1, ==2.8.0.rc2, ==2.8.1, ==2.8.10, ==2.8.11, ==2.8.11.1, ==2.8.11.2, ==2.8.11.3, ==2.8.11.4, ==2.8.11.5, ==2.8.11.6, >=2.8.2 <2.8.9, ==2.8.8.1, ==2.8.9, ==2.9.0, ==2.9.0.pr1, ==2.9.0.pr2, ==2.9.0.pr3, ==2.9.0.pr4, ==2.9.1, ==2.9.10, ==2.9.10.1, ==2.9.10.2, ==2.9.10.3, ==2.9.10.4, ==2.9.10.5, ==2.9.10.6, ==2.9.10.7, ==2.9.10.8, >=2.9.2 <2.9.10, >=2.22.0 <2.22.3, ==2.9.9.1, ==2.9.9.2, ==2.9.9.3 GHSA-cxp5-3px4-pw24
High Risk
3 hours ago
jackson-databind quadratic forward-reference completion
>=3.0.0 <3.0.5, >=3.1.0 <3.1.7, >=3.2.0 <3.2.3 GHSA-cxp5-3px4-pw24
>=3.0.0 <3.0.5, >=3.1.0 <3.1.7, >=3.2.0 <3.2.3 GHSA-cxp5-3px4-pw24
Medium Risk
1 day ago
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
Medium Risk
1 day ago
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
3.2.0 - 3.2.1 GHSA-gx83-3vf8-gh7j
High Risk
1 day ago
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
2.22.0 - 2.22.1 GHSA-q4xh-88c3-wmh7
2.22.0 - 2.22.1 GHSA-q4xh-88c3-wmh7
View all vulnerabilities for these packages

Timeline

Published
3 hours ago
September 30, 2026 at 03:36 PM UTC
Fixed (2.18.11)
Unknown
Unknown
Fixed (2.21.7)
Unknown
Unknown
Fixed (2.22.3)
Unknown
Unknown
Fixed (3.1.7)
Unknown
Unknown
Fixed (3.2.3)
Unknown
Unknown
Last Modified
3 hours ago
September 30, 2026 at 03:46 PM UTC