SCA: security update for com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind (GHSA-wjgm-6hv5-3cvf)

medium Tenable Self-Hosted Container Security Plugin ID 448453

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without
restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from
untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws
FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls
provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted
JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a
default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in
providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs;
further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects
com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from
2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0
before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path
from untrusted JSON should be avoided regardless of version. (CVE-2026-19032)

Solution

Update the com.fasterxml.jackson.core:jackson-databind library and its related packages to version 2.18.10 or later.

See Also

https://github.com/advisories/GHSA-wjgm-6hv5-3cvf

Plugin Details

Severity: Medium

ID: 448453

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-19032

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/23/2026

Reference Information

CVE: CVE-2026-19032