SCA: security update for com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind (GHSA-gx83-3vf8-gh7j)

medium Tenable Self-Hosted Container Security Plugin ID 448456

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever
@JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution
only for a fixed set of "unsafe base types", and its isSafeSubType method returns true unconditionally for
every base type outside that set. java.lang.Comparable was absent from the list despite being implemented
by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable,
which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or
class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type
identifier for essentially any class implementing Comparable. This yields an attacker-controlled object
instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen
path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods
on the value. No class implementing Comparable has been identified that yields code execution through
deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that
method structurally requires an explicit PolymorphicTypeValidator argument. This affects
com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and
from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0
before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. (CVE-2026-83557)

Solution

Update the com.fasterxml.jackson.core:jackson-databind library and its related packages to version 2.18.10 or later.

See Also

https://github.com/advisories/GHSA-gx83-3vf8-gh7j

Plugin Details

Severity: Medium

ID: 448456

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 95.86

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-83557

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/1/2026

Reference Information

CVE: CVE-2026-83557