Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-91776

jackson-databind retains every unknown raw type ID
Back to all
CVE

CVE-2026-91776

jackson-databind retains every unknown raw type ID

Summary

With @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unknown

raw type ID selects the same fallback deserializer but is retained as a

separate key in TypeDeserializerBase._deserializers. An attacker who can

repeatedly supply new unknown type IDs can grow this process-lifetime cache

without a configured bound.

Details

The affected path is TypeDeserializerBase._findDeserializer(). After an

unknown name-based type ID resolves to the configured fallback/default

implementation, jackson-databind caches the result under the attacker-provided

raw typeId. Although all such IDs select the same fallback deserializer, each

new string remains a distinct cache key.

The behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1.

Current 2.22 and 3.2 source branches retained the unbounded _deserializers

map and per-raw-ID cache write when rechecked. The earlier affected floor has

not been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.

The vulnerable application must enable name-based polymorphism with a

defaultImpl or equivalent fallback, accept attacker-influenced type IDs, and

reuse a long-lived mapper/type deserializer across requests.

Suggested correction: avoid caching each unknown raw ID when every such ID

resolves to the same fallback, use a fallback sentinel, or use an explicitly

bounded concurrency-safe cache. A regression should contrast many distinct

unknown IDs with repetitions of one unknown ID across requests.

PoC

Configure a polymorphic base type with

@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class) and

deserialize inputs containing unknown type names through the same mapper.

Inspect TypeDeserializerBase._deserializers after the run.

On affected 2.x and 3.x versions, 10,000 distinct unknown raw type IDs produce

10,000 retained cache entries even though every input selects the same

fallback deserializer. A matched control that repeats one unknown ID 10,000

times produces one retained entry. This isolates attacker-controlled key

cardinality from ordinary request count.

Impact

Where the stated polymorphic fallback configuration is exposed to

attacker-influenced type IDs, distinct inputs cause incremental

process-lifetime memory retention and eventual availability pressure or

denial of service. This is not claimed as a single-request allocation spike,

and no fixed bytes-per-ID or time-to-out-of-memory value is asserted. No

confidentiality, integrity, or code-execution impact is claimed.

Requested credit: Daniel Birtwhistle

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Related Resources

No items found.

References

https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54, https://nvd.nist.gov/vuln/detail/CVE-2026-91776, https://github.com/FasterXML/jackson-databind/issues/6203, https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577, https://github.com/FasterXML/jackson-databind, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7, https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3

Severity

7.5

CVSS Score
0
10

Basic Information

Base CVSS
7.5
EPSS Probability
0.0045%
EPSS Percentile
0.3691%
Introduced Version
2.0.0,3.0.0,3.0.0-rc1,3.2.0,2.0.0-RC1,2.19.0-rc2,2.22.0,0
Fix Available
2.18.11,3.1.7,3.2.3,2.21.7,2.22.3,2.0.0-r10,5.19.11-r2,6.2.10-r2,6.3.0-r3,2.19.0-r5,2.19.0-r3,4.0.13-r8,4.2.4-r8,4.0.13-r7,4.2.4-r7,3.0.0-r34,3.1.0-r41,3.2.3-r20,3.3.2-r4,3.0.0-r16,3.1.0-r17,3.2.3-r15,3.3.2-r6,10.2.0-r2,3.3.3-r4,3.3.3-r2,8.8.40-r2,8.6.39-r15,8.7.42-r2,5.0.9-r9,5.0.8-r17,5.0.1-r4,0.6.3-r19,8.5.0.254-r1,2.5.146-r6,1.7.0.1-r3,4.14.4-r2,5.1.1-r1,1.6.1-r6,1.6.1-r5,8.19.22-r2,9.2.8-r18,9.3.8-r11,8.19.22-r3,9.2.8-r17,9.3.8-r4,1.16.1-r2,1.16.1-r3,0.13.0-r3,13.9.0-r1,2.27.6-r4,2.28.5-r4,3.0.1-r6,8.14.5-r9,9.8.0-r2,1.6.0-r19,3.3.6-r20,2.7.0-r44,15.0.22-r19,15.1.7-r31,15.2.6-r29,16.0.15-r2,16.1.4-r13,16.2.3-r1,5.6.3-r5,1.5.0-r16,1.5.0-r9,3.7.2-r62,3.8.1-r64,3.9.2-r17,4.0.2-r14,4.1.2-r11,4.2.2-r2,4.3.1-r11,1.1.0-r4,1.1.0-r5,4.1.2-r13,4.2.2-r1,4.3.1-r9,1.23.0-r2,2026.3.5-r2,6.5.1-r20,1.20.3-r19,1.21.5-r6,1.22.3-r17,1.23.1-r7,1.20.3-r18,1.21.5-r10,1.22.3-r14,1.23.1-r8,9.4.7-r4,9.5.4-r4,0.1.126-r2,0.1.126-r1,0.63.19-r0,2026.02.3-r7,2026.04.0-r6,2026.05.0-r15,2026.06.0-r12,2026.07.1-r5,5.26.31-r2,26.04.6-r4,2023.45-r18,2025.20-r4,5.5.0-r26,5.5.0-r21,2.19.6-r17,3.9.0-r1,3.6.3-r2,26.5.7-r30,26.6.7-r3,0.5.2-r3,0.5.2-r4,4.1.1-r2,2.7.0-r11,10.0.0-r15,10.0.0-r8,2.0.7-r7,0.18.0-r3,0.18.0-r2,1.2.0-r7,1.2.0-r6,0.10.5-r33,4.3.1.5-r3,3.8.2-r2,6.16.0-r2,6.16.0-r1,483-r9,13.9-r32,41.0.1-r4,3.6.1-r30,3.8.7-r2,3.9.6-r3,3.8.7-r3,3.9.6-r2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading