5.3
CVE-2026-77310
- EPSS 0.19%
- Veröffentlicht 24.08.2026 19:24:59
- Zuletzt bearbeitet 09.09.2026 21:06:39
- Erkennungen
jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFasterXML
≫
Produkt
com.fasterxml.jackson.core:jackson-databind
Version
>= 2.0.0, < 2.18.9
Status
affected
Version
>= 2.19.0, < 2.21.5
Status
affected
Version
>= 2.22.0, < 2.22.1
Status
affected
HerstellerFasterXML
≫
Produkt
tools.jackson.core:jackson-databind
Version
>= 3.0.0, < 3.1.5
Status
affected
Version
>= 3.2.0, < 3.2.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.083 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6