CVE-2026-91776: CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind
CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind Vulnerability ID: CVE-2026-91776 CVSS Score: 7.5 Published: 2026-09-30 CVE-2026-91776 is a high-severity Denial of Service (DoS)
CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind
Vulnerability ID: CVE-2026-91776
CVSS Score: 7.5
Published: 2026-09-30
CVE-2026-91776 is a high-severity Denial of Service (DoS) vulnerability in the FasterXML jackson-databind library. The vulnerability is caused by uncontrolled resource consumption (CWE-400) where raw, unrecognized polymorphic type IDs are cached indefinitely without boundaries inside TypeDeserializerBase. When name-based polymorphic deserialization is configured with a fallback mechanism (such as a default implementation or custom problem handlers), remote attackers can send crafted payloads containing unique unknown type IDs, causing heap exhaustion, Garbage Collection (GC) overhead limit exhaustion, and an Out-of-Memory (OOM) crash.
TL;DR
An unauthenticated remote attacker can crash Java applications using Jackson-databind by transmitting JSON payloads with high-cardinality, unrecognized polymorphic type IDs, causing unbounded memory retention and JVM heap exhaustion.
β οΈ Exploit Status: POC
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network
- CVSS Severity: 7.5 (High)
- Exploit Status: Proof-of-Concept Available
- KEV Status: Not Listed
- Vulnerability Class: Uncontrolled Resource Consumption
Affected Systems
- FasterXML jackson-databind versions 2.0.0 through 2.18.10
- FasterXML jackson-databind versions 2.19.0 through 2.21.6
- FasterXML jackson-databind versions 2.22.0 through 2.22.2
- FasterXML jackson-databind versions 3.0.0 through 3.1.6
- FasterXML jackson-databind versions 3.2.0 through 3.2.2
-
jackson-databind: >= 2.0.0, <= 2.18.10 (Fixed in:
2.18.11) -
jackson-databind: >= 2.19.0, <= 2.21.6 (Fixed in:
2.21.7) -
jackson-databind: >= 2.22.0, <= 2.22.2 (Fixed in:
2.22.3) -
jackson-databind: >= 3.0.0, <= 3.1.6 (Fixed in:
3.1.7) -
jackson-databind: >= 3.2.0, <= 3.2.2 (Fixed in:
3.2.3)
Code Analysis
Commit: 2870d1d
Bound the cache used for type deserializers in TypeDeserializerBase to address CVE-2026-91776
@@ -23,6 +23,22 @@ public abstract class TypeDeserializerBase\n+\n+ final static int MAX_CACHED_TYPE_IDS = 1000;\n+ final static int MAX_CACHED_TYPE_ID_LENGTH = 256;\n...\n+ if (typeId.length() > MAX_CACHED_TYPE_ID_LENGTH) {\n+ return deser;\n+ }\n+ if (_deserializers.size() >= MAX_CACHED_TYPE_IDS) {\n+ _deserializers.clear();\n+ }\n+ _deserializers.put(typeId, deser);
Exploit Details
- GitHub: Issue report detailing reproduction steps and JUnit test cases for uncontrolled polymorphic cache growth.
Mitigation Strategies
- Upgrade the jackson-databind library to a patched version immediately.
- Refactor polymorphic type definitions to remove defaultImpl fallback configurations where possible.
- Implement a custom TypeIdResolver that strictly validates type IDs against an allowlist before resolution.
- Deploy WAF rules to drop payloads containing abnormally long polymorphic type identifiers.
Remediation Steps:
- Analyze dependency structures (using Maven or Gradle) to identify references to vulnerable jackson-databind versions.
- Update Maven pom.xml or Gradle build.gradle files to specify a patched version (e.g., 2.18.11, 2.21.7, 2.22.3, 3.1.7, or 3.2.3).
- Run integration tests to confirm compatibility with the updated library, paying special attention to polymorphic deserialization tests.
- Deploy the updated build artifacts to staging and production environments.
References
- GitHub Security Advisory GHSA-wv8q-qhhj-9h54
- FasterXML Jackson Databind Issue #6203
- Fix Commit 2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577
- Wiz Vulnerability Database Entry for CVE-2026-91776
- CVE-2026-91776 Record on CVE.org
Read the full report for CVE-2026-91776 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.