CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-83557

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

Alon Barad
Alon Barad
Software Engineer

Sep 28, 2026·6 min read·1 visit

Executive Summary (TL;DR)

Incomplete polymorphic type validation in Jackson Databind allows arbitrary object instantiation of Comparable subtypes, exposing applications to file path validation bypasses and class loading attacks.

An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.

Vulnerability Overview

The FasterXML jackson-databind library provides robust framework-level capabilities for serializing and deserializing Java objects to and from JSON formats. In many enterprise applications, polymorphism is a core requirement, allowing properties to be defined using abstract classes or interface types. Jackson enables this through annotations such as @JsonTypeInfo, which instruct the deserializer to parse type metadata directly from the incoming payload and resolve it to a concrete subclass.

To prevent arbitrary class loading and the instantiation of malicious payload classes—commonly known as 'gadget' chains—Jackson utilizes a series of validators to control which subtypes can be resolved from abstract base declarations. When developers do not configure a custom class validator, Jackson invokes the DefaultBaseTypeLimitingValidator by default to enforce limits on highly generic, abstract base classes. The objective is to block incoming payloads from invoking types that expose wide, systemic interfaces.

The core of the vulnerability in CVE-2026-83557 lies in the omission of java.lang.Comparable from this default set of unsafe base types. Because Comparable is implemented by an extensive library of classes throughout both the standard Java Development Kit (JDK) and external classpaths, this omission provides an attacker with a robust primitive to trigger arbitrary class instantiation. Unauthenticated remote attackers can leverage this bypass to construct custom payloads that force the application to instantiate unexpected types such as java.io.File.

Root Cause Analysis

Polymorphic deserialization operates by mapping JSON fields to concrete Java objects based on class names supplied inside the JSON payload. If an application declares an object property using a wide-reaching interface like java.io.Serializable or java.lang.Object, any class implementing that interface is a candidate for instantiation. To mitigate the risk of attackers instantiating arbitrary classes, Jackson employs a static denylist of unsafe base types within DefaultBaseTypeLimitingValidator.

Historically, this denylist blocked highly abstract classes and interfaces such as java.lang.Object, java.io.Serializable, java.lang.AutoCloseable, and java.lang.Cloneable. However, java.lang.Comparable was omitted from this blocklist. Because countless standard classes—including files, paths, and URI representations—implement Comparable, treating this interface as a safe base type allows attackers to bypass the validator's structural checks.

When a polymorphic field is typed as java.lang.Comparable and serialized without a custom validator, the library processes the class resolution. Since java.lang.Comparable is not evaluated as an unsafe base type, DefaultBaseTypeLimitingValidator.isSafeSubType() accepts the user-supplied subtype class name, as long as that subtype itself is not on a specific blocked list. This architectural omission directly exposes the application to unauthenticated object instantiation.

Code Analysis

The vulnerability was resolved by directly patching DefaultBaseTypeLimitingValidator.java to include java.lang.Comparable in the UnsafeBaseTypes list. In the vulnerable versions, the static initializer block of UnsafeBaseTypes declared several core JDK classes as unsafe but left Comparable out. Below is an abstract view of the vulnerability remediation:

// Vulnerable Code: DefaultBaseTypeLimitingValidator.java
private final static class UnsafeBaseTypes {
    static {
        Set<String> s = new HashSet<>();
        s.add(Object.class.getName());
        s.add(java.io.Serializable.class.getName());
        s.add(AutoCloseable.class.getName());
        s.add(Cloneable.class.getName());
        // Missing java.lang.Comparable
        UNSAFE = s;
    }
}

To resolve this issue, the maintainers explicitly added Comparable.class.getName() to the UNSAFE set in commit eb3b7fc0f9c0d27f471550ac3316b17d1987388f. The patched implementation prevents polymorphic resolution when the declared field type is a standard Comparable interface:

// Patched Code: DefaultBaseTypeLimitingValidator.java
private final static class UnsafeBaseTypes {
    static {
        Set<String> s = new HashSet<>();
        s.add(Object.class.getName());
        s.add(java.io.Serializable.class.getName());
        s.add(AutoCloseable.class.getName());
        s.add(Cloneable.class.getName());
        // [databind#6156]: "Comparable" added as well
        s.add(Comparable.class.getName());
        UNSAFE = s;
    }
}

Additionally, the unit tests inside AnnotatedPolymorphicValidationTest.java were expanded to assert that attempts to deserialize payloads targeting Comparable properties will fail by default with an InvalidDefinitionException. Developers who explicitly require polymorphic handling of Comparable must now implement a custom validator subclass and override isUnsafeBaseType() alongside strict validation of safe subtypes within isSafeSubType().

Exploitation Methodology

To successfully exploit CVE-2026-83557, the target application must expose a deserialization endpoint that accepts JSON data bound to a Java class containing a property of type java.lang.Comparable (or a subtype), decorated with polymorphic typing annotations like @JsonTypeInfo.

An attacker can craft a payload containing a class identifier such as java.io.File inside the polymorphic type array, followed by the path argument. When the payload is processed, the validator allows the class loading, resulting in the instant creation of the java.io.File object mapping to the attacker's designated target:

{
  "value": ["java.io.File", "/etc/passwd"]
}

While this instantiation does not immediately execute code on the system, the danger arises from the subsequent lifecycle of the deserialized object. If the application invokes file-related operations, comparisons, or path validation routines on the instantiated Comparable property, the attacker can leverage the primitive to execute path traversal attacks, local file read validations, or state manipulation within the business logic.

Impact Assessment

The vulnerability carries a CVSS v3.1 base score of 5.6, reflecting a 'Medium' severity profile. The vector breakdown CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L illustrates that while the attack can be launched remotely without privileges, its execution complexity is high because it requires target properties to use highly specific polymorphic typing parameters.

The potential impact is highly contingent on the application's runtime environment and classpath. If the classpath contains complex classes implementing Comparable that execute side effects during construction or setter execution, the security impact could escalate. Furthermore, being able to arbitrarily instantiate classes like java.io.File allows attackers to interact with internal filesystem state depending on how the deserialized object is handled.

From a secure coding perspective, this vulnerability highlights the structural fragility of relying on denylists or blocklists to secure deserialization frameworks. Any omission of wide-ranging classes or interfaces in the library's built-in validation mechanism can expose application endpoints to unexpected behaviors, underlining the necessity of strict allowlisting strategies.

Remediation & Mitigation Guidance

The primary remediation path for CVE-2026-83557 is upgrading jackson-databind to a fully patched version. Organizations utilizing the Jackson 2.x ecosystem must upgrade to 2.18.10, 2.21.6, or 2.22.2 depending on their release line. Organizations transitioning to Jackson 3.x must migrate to 3.1.6 or 3.2.2 to ensure the validator blocks the Comparable base type.

If upgrading the library is not immediately feasible, developers can mitigate the risk by refactoring vulnerable class models. Properties should not be typed with extremely generic interfaces like java.lang.Comparable under polymorphic configurations. Instead, define strict, domain-specific base classes or interfaces to restrict the possible space of candidate subtypes.

Additionally, developers can configure an explicit allowlist-based validation model utilizing BasicPolymorphicTypeValidator. By manually defining which base types and subtypes are permitted to resolve, applications can isolate their deserialization endpoints and insulate themselves against potential omissions in the default library validator.

Fix Analysis (1)

Technical Appendix

CVSS Score
5.6/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Probability
0.59%
Top 53% most exploited

Affected Systems

FasterXML jackson-databind (com.fasterxml.jackson.core)FasterXML jackson-databind (tools.jackson.core)

Affected Versions Detail

Product
Affected Versions
Fixed Version
com.fasterxml.jackson.core:jackson-databind
FasterXML
>= 2.11.0, < 2.18.102.18.10
com.fasterxml.jackson.core:jackson-databind
FasterXML
>= 2.19.0, < 2.21.62.21.6
com.fasterxml.jackson.core:jackson-databind
FasterXML
>= 2.22.0, < 2.22.22.22.2
tools.jackson.core:jackson-databind
FasterXML
>= 3.0.0, < 3.1.63.1.6
tools.jackson.core:jackson-databind
FasterXML
>= 3.2.0, < 3.2.23.2.2
AttributeDetail
CWE IDCWE-502 / CWE-915
Attack VectorNetwork
CVSS v3.1 Score5.6 (Medium)
EPSS Score0.00586 (Percentile: 46.72%)
ImpactArbitrary Object Instantiation / Bypass
Exploit StatusNone
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1059Command and Scripting Interpreter
Execution
CWE-502
Deserialization of Untrusted Data

The application deserializes untrusted data without sufficient verification of the resulting object's type, leading to arbitrary object instantiation or execution.

Vulnerability Timeline

Fix commit merged into jackson-databind
2026-08-11
GHSA-gx83-3vf8-gh7j and CVE-2026-83557 published
2026-09-01
NVD database entry populated with CVSS and CWE vectors
2026-09-08

References & Sources

  • [1]GitHub Security Advisory GHSA-gx83-3vf8-gh7j
  • [2]Fix Commit eb3b7fc0f
  • [3]GitHub Issue #6156
  • [4]GitHub Pull Request #6155
  • [5]CVE-2026-83557 Record
  • [6]NVD Vulnerability Details
  • [7]Wiz Vulnerability Analysis Profile

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-101914
6.5

CVE-2026-101914: Authorization Bypass via Case-Insensitive Path Matching in @grpc/grpc-js-xds

An authorization bypass vulnerability exists in the @grpc/grpc-js Node.js package (specifically within the xDS plugin wrapper @grpc/grpc-js-xds) due to a logical error in its Role-Based Access Control (RBAC) path matching component. When case-insensitive path matching is enabled, the matching logic performs a prefix comparison using the startsWith method instead of a strict equality comparison. This logic flaw allows unauthenticated or low-privilege clients with access to a shorter path to gain unauthorized access to longer, more privileged method names that share the same prefix.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 6 hours ago•CVE-2026-61834
4.3

CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.

Alon Barad
Alon Barad
6 views•6 min read
•about 7 hours ago•GHSA-456V-XQ2P-R4CJ
7.8

GHSA-456V-XQ2P-R4CJ: OS Command Injection in code-ollama grep_search Tool

An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.

Amit Schendel
Amit Schendel
7 views•5 min read
•about 7 hours ago•CVE-2026-76460
10.0

CVE-2026-76460: Cisco Identity Services Engine Authentication Bypass Vulnerability

On September 16, 2026, Cisco disclosed a critical authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows unauthenticated, remote attackers to bypass the administrative interface controls and execute privileged API requests. Due to active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog with an immediate remediation deadline.

Alon Barad
Alon Barad
16 views•4 min read
•3 days ago•CVE-2026-53493
6.9

CVE-2026-53493: Uncontrolled Resource Consumption in containerd Image-Pull Descriptor Graph Resolution

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. The vulnerability occurs because containerd's image-pull descriptor graph resolution handlers processed OCI image indices and manifests recursively without enforcing boundaries on traversal depth or breadth, and without maintaining a global visited registry to count duplicate references.

Alon Barad
Alon Barad
35 views•6 min read
•3 days ago•GHSA-62MM-XWMV-CRHG
7.5

GHSA-62MM-XWMV-CRHG: Unauthenticated Path Traversal in Khoj Static File Serving Endpoint

An unauthenticated path traversal vulnerability exists in the Khoj AI assistant platform via the static file serving endpoint `/home/{file_path:path}`. Due to improper path sanitization when handling user input with Python's pathlib module, a remote attacker can read arbitrary files from the server's filesystem.

Alon Barad
Alon Barad
13 views•5 min read