CVE-2026-83557: CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

# security# cve# cybersecurity
CVE-2026-83557: CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.ComparableCVE Reports

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via...

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

Vulnerability ID: CVE-2026-83557
CVSS Score: 5.6
Published: 2026-09-28

An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.

TL;DR

Incomplete polymorphic type validation in Jackson Databind allows arbitrary object instantiation of Comparable subtypes, exposing applications to file path validation bypasses and class loading attacks.


Technical Details

  • CWE ID: CWE-502 / CWE-915
  • Attack Vector: Network
  • CVSS v3.1 Score: 5.6 (Medium)
  • EPSS Score: 0.00586 (Percentile: 46.72%)
  • Impact: Arbitrary Object Instantiation / Bypass
  • Exploit Status: None
  • KEV Status: Not Listed

Affected Systems

  • FasterXML jackson-databind (com.fasterxml.jackson.core)
  • FasterXML jackson-databind (tools.jackson.core)
  • com.fasterxml.jackson.core:jackson-databind: >= 2.11.0, < 2.18.10 (Fixed in: 2.18.10)
  • com.fasterxml.jackson.core:jackson-databind: >= 2.19.0, < 2.21.6 (Fixed in: 2.21.6)
  • com.fasterxml.jackson.core:jackson-databind: >= 2.22.0, < 2.22.2 (Fixed in: 2.22.2)
  • tools.jackson.core:jackson-databind: >= 3.0.0, < 3.1.6 (Fixed in: 3.1.6)
  • tools.jackson.core:jackson-databind: >= 3.2.0, < 3.2.2 (Fixed in: 3.2.2)

Code Analysis

Commit: eb3b7fc

Add java.lang.Comparable to unsafe base types in DefaultBaseTypeLimitingValidator to mitigate polymorphic deserialization bypasses.

Mitigation Strategies

  • Upgrade jackson-databind to the latest secure version (2.18.10+, 2.21.6+, 2.22.2+, 3.1.6+, or 3.2.2+)
  • Avoid utilizing wide-reaching interfaces like java.lang.Comparable for polymorphic deserialization properties
  • Implement a strict BasicPolymorphicTypeValidator allowlist to specify allowed subtypes explicitly

Remediation Steps:

  1. Audit application classpaths and find jackson-databind dependencies within build files (pom.xml, build.gradle)
  2. Update the jackson-databind version to one of the patched releases
  3. Scan codebase for properties annotated with @JsonTypeInfo where the declared type implements java.lang.Comparable
  4. Replace wide property types with narrow, concrete domain transfer classes

References


Read the full report for CVE-2026-83557 on our website for more details including interactive diagrams and full exploit analysis.