CVE-2026-59889
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9
CVSS
6.5
Medio
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 14 jul 2026 · Última mod.: 16 jul 2026 · CWE-863
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.
- github.comhttps://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b
- github.comhttps://github.com/FasterXML/jackson-databind/issues/6060
- github.comhttps://github.com/FasterXML/jackson-databind/pull/6056
- github.comhttps://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh