jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID
Summary
| CVE | CVE-2026-91776 |
|---|---|
| State | PUBLISHED |
| Assigner | HeroDevs |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-23 03:17:04 UTC |
| Updated | 2026-09-24 20:43:32 UTC |
| Description | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from 36c7be3b-2937-45df-85ea-ca7133ea542c
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.004500000 probability, percentile 0.364950000 (date 2026-09-25)
Problem Types: CWE-400 | CWE-400 CWE-400 Uncontrolled Resource Consumption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 36c7be3b-2937-45df-85ea-ca7133ea542c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | FasterXML | Jackson-databind | affected 2.0.0 2.18.10 maven | Not specified |
| CNA | FasterXML | Jackson-databind | affected 2.19.0 2.21.6 maven | Not specified |
| CNA | FasterXML | Jackson-databind | affected 2.22.0 2.22.2 maven | Not specified |
| CNA | FasterXML | Jackson-databind | affected 3.0.0 3.1.6 maven | Not specified |
| CNA | FasterXML | Jackson-databind | affected 3.2.0 3.2.2 maven | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/FasterXML/jackson-databind/issues/6203 | 36c7be3b-2937-45df-85ea-ca7133ea542c | github.com | |
| github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Daniel Birtwhistle (dabirt) (en)
Additional Advisory Data
Solutions
CNA: Upgrade to com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7 or 2.22.3, or to tools.jackson.core:jackson-databind 3.1.7 or 3.2.3. Lines 2.0.x through 2.17.x, 2.19.x, 2.20.x and 3.0.x received no fix on their own branch and are no longer maintained upstream.
Workarounds
CNA: Where the polymorphic shape allows it, avoid defaultImpl or another catch-all fallback for name-based type resolution so that unrecognized type IDs fail rather than resolving, or restrict accepted type IDs with a custom TypeIdResolver that rejects unknown names before resolution. Shortening ObjectMapper or type deserializer lifetime limits accumulation but does not eliminate it.