CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable
Vulnerability ID: CVE-2026-83557
CVSS Score: 5.6
Published: 2026-09-28
An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.
TL;DR
Incomplete polymorphic type validation in Jackson Databind allows arbitrary object instantiation of Comparable subtypes, exposing applications to file path validation bypasses and class loading attacks.
Technical Details
-
CWE ID: CWE-502 / CWE-915
-
Attack Vector: Network
-
CVSS v3.1 Score: 5.6 (Medium)
-
EPSS Score: 0.00586 (Percentile: 46.72%)
-
Impact: Arbitrary Object Instantiation / Bypass
-
Exploit Status: None
-
KEV Status: Not Listed
Affected Systems
- FasterXML jackson-databind (com.fasterxml.jackson.core)
- FasterXML jackson-databind (tools.jackson.core)
-
com.fasterxml.jackson.core:jackson-databind: >= 2.11.0, < 2.18.10 (Fixed in:
2.18.10)
-
com.fasterxml.jackson.core:jackson-databind: >= 2.19.0, < 2.21.6 (Fixed in:
2.21.6)
-
com.fasterxml.jackson.core:jackson-databind: >= 2.22.0, < 2.22.2 (Fixed in:
2.22.2)
-
tools.jackson.core:jackson-databind: >= 3.0.0, < 3.1.6 (Fixed in:
3.1.6)
-
tools.jackson.core:jackson-databind: >= 3.2.0, < 3.2.2 (Fixed in:
3.2.2)
Code Analysis
Add java.lang.Comparable to unsafe base types in DefaultBaseTypeLimitingValidator to mitigate polymorphic deserialization bypasses.
Mitigation Strategies
- Upgrade jackson-databind to the latest secure version (2.18.10+, 2.21.6+, 2.22.2+, 3.1.6+, or 3.2.2+)
- Avoid utilizing wide-reaching interfaces like java.lang.Comparable for polymorphic deserialization properties
- Implement a strict BasicPolymorphicTypeValidator allowlist to specify allowed subtypes explicitly
Remediation Steps:
- Audit application classpaths and find jackson-databind dependencies within build files (pom.xml, build.gradle)
- Update the jackson-databind version to one of the patched releases
- Scan codebase for properties annotated with @JsonTypeInfo where the declared type implements java.lang.Comparable
- Replace wide property types with narrow, concrete domain transfer classes
References
Read the full report for CVE-2026-83557 on our website for more details including interactive diagrams and full exploit analysis.