PT-2026-97133 · Unknown · Jackson-Databind
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
jackson-databind (affected versions not specified)
Description
The
findDeserializer() function in TypeDeserializerBase caches resolved deserializers using the raw type ID provided by the user. In configurations using name-based polymorphism with a fallback, such as @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), each unique unrecognized type ID is stored as a separate key in the deserializers map, even though they all resolve to the same fallback deserializer. Because this map lacks a configurable bound and persists for the lifetime of the type deserializer, an attacker can cause continuous memory retention by supplying numerous unique unknown type IDs. This issue occurs when an application enables name-based polymorphism with a defaultImpl or similar fallback, accepts user-influenced type IDs, and utilizes a long-lived ObjectMapper across requests.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jackson-Databind