
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-83557 is a deserialization vulnerability in FasterXML jackson-databind caused by an incomplete denylist in DefaultBaseTypeLimitingValidator, which omits java.lang.Comparable from its set of unsafe polymorphic base types. Reported by @prvazsahnazarov and disclosed on September 1, 2026, it affects com.fasterxml.jackson.core:jackson-databind versions 2.11.0–2.18.9, 2.19.0–2.21.5, and 2.22.0–2.22.1, as well as tools.jackson.core:jackson-databind versions 3.0.0–3.1.5 and 3.2.0–3.2.1. It carries a CVSS v3.1 base score of 5.6 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an incomplete denylist in DefaultBaseTypeLimitingValidator (CWE-502, CWE-915, CWE-1287): the validator's isSafeSubType() method returns true unconditionally for any base type not in its fixed set of "unsafe" types, and java.lang.Comparable was absent from that set despite being implemented by a very large fraction of JDK and application classes — comparable in breadth to java.io.Serializable, which is already denylisted. When an application uses @JsonTypeInfo on a Comparable-typed property without an explicitly configured custom PolymorphicTypeValidator, an attacker can supply a crafted JSON payload specifying any class implementing Comparable as the type identifier. The demonstrated exploit constructs a java.io.File object for an attacker-chosen path (e.g., {"value":["java.io.File","/etc/passwd"]}), which becomes path-traversal-adjacent if the application subsequently invokes path-sensitive methods on the deserialized value. Note that activateDefaultTyping() is not affected because it structurally requires an explicit PolymorphicTypeValidator argument (GitHub Advisory, GitHub Issue).
Successful exploitation grants an unauthenticated network attacker an attacker-controlled object instantiation primitive, enabling construction of arbitrary Comparable-implementing objects such as java.io.File with attacker-chosen paths. If the application subsequently performs path-sensitive operations (e.g., file reads, writes, or existence checks) on the deserialized value, this translates to a path traversal attack with low confidentiality, integrity, and availability impact. No gadget class implementing Comparable has been identified that yields remote code execution through deserialization alone, limiting the immediate severity (GitHub Advisory).
A proof-of-concept exploit is publicly available in the official GitHub Security Advisory, including concrete JSON payloads and step-by-step reproduction instructions demonstrating java.io.File instantiation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "poc" with "no" automatable exploitation and "partial" technical impact. The EPSS score is approximately 0.586%, and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the disclosure date (Feedly). Exploitation requires the target application to use @JsonTypeInfo on a Comparable-typed property without a custom PolymorphicTypeValidator, which is a specific but not uncommon configuration.
@JsonTypeInfo-annotated properties typed as java.lang.Comparable and no custom PolymorphicTypeValidator configured.Comparable as the type identifier, for example:{"value":["java.io.File","/etc/passwd"]}DefaultBaseTypeLimitingValidator will accept the type identifier because java.lang.Comparable is not in its unsafe base types denylist.exists(), getAbsolutePath(), listFiles()) on the deserialized java.io.File object, the attacker achieves path traversal, potentially reading directory listings or influencing file-based logic with an attacker-controlled path (GitHub Advisory).["java.io.File","<path>"]) in fields expected to hold application-specific types.InvalidDefinitionException or unexpected java.io.File object instantiation from JSON deserialization; Jackson deserialization errors referencing Comparable base type resolution./etc/passwd, /etc/shadow, or Windows equivalents.Upgrade to one of the patched versions: com.fasterxml.jackson.core:jackson-databind 2.18.10, 2.21.6, or 2.22.2; or tools.jackson.core:jackson-databind 3.1.6 or 3.2.2, which add java.lang.Comparable to the UnsafeBaseTypes denylist (GitHub Advisory, GitHub Commit). If immediate patching is not possible, explicitly configure a restrictive custom PolymorphicTypeValidator (e.g., BasicPolymorphicTypeValidator) for any @JsonTypeInfo-annotated properties or classes, rather than relying on the default validator. Alternatively, avoid deserializing untrusted input into types with Comparable as the base type (Red Hat Bugzilla).
The vulnerability was reported by researcher @prvazsahnazarov and acknowledged by the jackson-databind maintainer (@cowtowncoder), who merged the fix on August 11, 2026, and published the advisory on September 1, 2026. The maintainer noted the gap is consistent with the incremental nature of the unsafe base types list, referencing a similar prior fix for Runnable (issue #5014). Netflix's Spectator project also bumped its bundled jackson-databind to 2.22.2 specifically to address this advisory (GitHub PR, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
jackson-databind
sid
jackson-databind
trixie
jackson-databind
bionic (esm-apps)
jackson-databind
devel
jackson-databind
focal (esm-apps)
jackson-databind
jammy
jackson-databind
jammy (esm-apps)
jackson-databind
noble
jackson-databind
noble (esm-apps)
jackson-databind
resolute
jackson-databind
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."