PT-2026-97133 · Unknown · Jackson-Databind

·

CVE-2026-91776

·

Published

2026-09-23

·

Updated

2026-09-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions jackson-databind (affected versions not specified)
Description The findDeserializer() function in TypeDeserializerBase caches resolved deserializers using the raw type ID provided by the user. In configurations using name-based polymorphism with a fallback, such as @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), each unique unrecognized type ID is stored as a separate key in the deserializers map, even though they all resolve to the same fallback deserializer. Because this map lacks a configurable bound and persists for the lifetime of the type deserializer, an attacker can cause continuous memory retention by supplying numerous unique unknown type IDs. This issue occurs when an application enables name-based polymorphism with a defaultImpl or similar fallback, accepts user-influenced type IDs, and utilizes a long-lived ObjectMapper across requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91776
GHSA-WV8Q-QHHJ-9H54
OPENSUSE-SU-2026:11877-1
SUSE-SU-2026:4394-1

Affected Products

Jackson-Databind