CVE-2026-83557: 
Java vulnerability analysis and mitigation

Overview

CVE-2026-83557 is a deserialization vulnerability in FasterXML jackson-databind caused by an incomplete denylist in DefaultBaseTypeLimitingValidator, which omits java.lang.Comparable from its set of unsafe polymorphic base types. Reported by @prvazsahnazarov and disclosed on September 1, 2026, it affects com.fasterxml.jackson.core:jackson-databind versions 2.11.0–2.18.9, 2.19.0–2.21.5, and 2.22.0–2.22.1, as well as tools.jackson.core:jackson-databind versions 3.0.0–3.1.5 and 3.2.0–3.2.1. It carries a CVSS v3.1 base score of 5.6 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an incomplete denylist in DefaultBaseTypeLimitingValidator (CWE-502, CWE-915, CWE-1287): the validator's isSafeSubType() method returns true unconditionally for any base type not in its fixed set of "unsafe" types, and java.lang.Comparable was absent from that set despite being implemented by a very large fraction of JDK and application classes — comparable in breadth to java.io.Serializable, which is already denylisted. When an application uses @JsonTypeInfo on a Comparable-typed property without an explicitly configured custom PolymorphicTypeValidator, an attacker can supply a crafted JSON payload specifying any class implementing Comparable as the type identifier. The demonstrated exploit constructs a java.io.File object for an attacker-chosen path (e.g., {"value":["java.io.File","/etc/passwd"]}), which becomes path-traversal-adjacent if the application subsequently invokes path-sensitive methods on the deserialized value. Note that activateDefaultTyping() is not affected because it structurally requires an explicit PolymorphicTypeValidator argument (GitHub Advisory, GitHub Issue).

Impact

Successful exploitation grants an unauthenticated network attacker an attacker-controlled object instantiation primitive, enabling construction of arbitrary Comparable-implementing objects such as java.io.File with attacker-chosen paths. If the application subsequently performs path-sensitive operations (e.g., file reads, writes, or existence checks) on the deserialized value, this translates to a path traversal attack with low confidentiality, integrity, and availability impact. No gadget class implementing Comparable has been identified that yields remote code execution through deserialization alone, limiting the immediate severity (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the official GitHub Security Advisory, including concrete JSON payloads and step-by-step reproduction instructions demonstrating java.io.File instantiation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "poc" with "no" automatable exploitation and "partial" technical impact. The EPSS score is approximately 0.586%, and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the disclosure date (Feedly). Exploitation requires the target application to use @JsonTypeInfo on a Comparable-typed property without a custom PolymorphicTypeValidator, which is a specific but not uncommon configuration.

Exploitation steps

  1. Reconnaissance: Identify Java applications using jackson-databind in affected versions (2.11.0–2.18.9, 2.19.0–2.21.5, 2.22.0–2.22.1, or 3.0.0–3.1.5, 3.2.0–3.2.1) that expose JSON deserialization endpoints accepting polymorphic types.
  2. Identify vulnerable endpoint: Locate API endpoints or input fields that deserialize JSON into objects with @JsonTypeInfo-annotated properties typed as java.lang.Comparable and no custom PolymorphicTypeValidator configured.
  3. Craft malicious payload: Construct a JSON payload specifying a target class implementing Comparable as the type identifier, for example:
    {"value":["java.io.File","/etc/passwd"]}
  4. Submit payload: Send the crafted JSON to the vulnerable endpoint via HTTP POST or other applicable transport. The DefaultBaseTypeLimitingValidator will accept the type identifier because java.lang.Comparable is not in its unsafe base types denylist.
  5. Trigger path-sensitive operation: If the application subsequently calls path-sensitive methods (e.g., exists(), getAbsolutePath(), listFiles()) on the deserialized java.io.File object, the attacker achieves path traversal, potentially reading directory listings or influencing file-based logic with an attacker-controlled path (GitHub Advisory).

Indicators of compromise

  • Network: Unusual JSON POST requests to application endpoints containing type arrays with JDK class names (e.g., ["java.io.File","<path>"]) in fields expected to hold application-specific types.
  • Logs: Application logs showing InvalidDefinitionException or unexpected java.io.File object instantiation from JSON deserialization; Jackson deserialization errors referencing Comparable base type resolution.
  • Application Behavior: Unexpected file system access patterns originating from the application's deserialization layer, particularly to sensitive paths like /etc/passwd, /etc/shadow, or Windows equivalents.
  • Process: Java process accessing file paths that do not correspond to normal application operation, especially paths supplied externally via API input.

Mitigation and workarounds

Upgrade to one of the patched versions: com.fasterxml.jackson.core:jackson-databind 2.18.10, 2.21.6, or 2.22.2; or tools.jackson.core:jackson-databind 3.1.6 or 3.2.2, which add java.lang.Comparable to the UnsafeBaseTypes denylist (GitHub Advisory, GitHub Commit). If immediate patching is not possible, explicitly configure a restrictive custom PolymorphicTypeValidator (e.g., BasicPolymorphicTypeValidator) for any @JsonTypeInfo-annotated properties or classes, rather than relying on the default validator. Alternatively, avoid deserializing untrusted input into types with Comparable as the base type (Red Hat Bugzilla).

Community reactions

The vulnerability was reported by researcher @prvazsahnazarov and acknowledged by the jackson-databind maintainer (@cowtowncoder), who merged the fix on August 11, 2026, and published the advisory on September 1, 2026. The maintainer noted the gap is consistent with the incremental nature of the unsafe base types list, referencing a similar prior fix for Runnable (issue #5014). Netflix's Spectator project also bumped its bundled jackson-databind to 2.22.2 specifically to address this advisory (GitHub PR, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

jackson-databind

Affected

sid

jackson-databind

Affected

trixie

jackson-databind

Affected

Ubuntu

Unknown

bionic (esm-apps)

jackson-databind

Unknown

devel

jackson-databind

Unknown

focal (esm-apps)

jackson-databind

Unknown

jammy

jackson-databind

Unknown

jammy (esm-apps)

jackson-databind

Unknown

noble

jackson-databind

Unknown

noble (esm-apps)

jackson-databind

Unknown

resolute

jackson-databind

Unknown

RHEL / CentOS

Affected

RHEL 8

pki-core:10.6/pki-core.src

Affected

RHEL 9

assertj-core.src

Affected

RHEL 10

assertj-core.src

Affected

Source: This report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61741CRITICAL9.3
  • Java logoJava
  • org.http4s:http4s-scala-xml_2.12
NoYesSep 24, 2026
CVE-2026-77422HIGH7.5
  • Java logoJava
  • hadoop-client-modules
NoYesSep 23, 2026
CVE-2026-77421MEDIUM6.5
  • Java logoJava
  • zookeeper-fips-3.8
NoYesSep 23, 2026
CVE-2026-77420MEDIUM5.5
  • Java logoJava
  • jline
NoYesSep 23, 2026
CVE-2026-57168NONEN/A
  • Java logoJava
  • io.openremote:openremote-manager
NoYesSep 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management