Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

CVE-2026-91776: CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind

CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind Vulnerability ID: CVE-2026-91776 CVSS Score: 7.5 Published: 2026-09-30 CVE-2026-91776 is a high-severity Denial of Service (DoS)

CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind

Vulnerability ID: CVE-2026-91776
CVSS Score: 7.5
Published: 2026-09-30

CVE-2026-91776 is a high-severity Denial of Service (DoS) vulnerability in the FasterXML jackson-databind library. The vulnerability is caused by uncontrolled resource consumption (CWE-400) where raw, unrecognized polymorphic type IDs are cached indefinitely without boundaries inside TypeDeserializerBase. When name-based polymorphic deserialization is configured with a fallback mechanism (such as a default implementation or custom problem handlers), remote attackers can send crafted payloads containing unique unknown type IDs, causing heap exhaustion, Garbage Collection (GC) overhead limit exhaustion, and an Out-of-Memory (OOM) crash.

TL;DR

An unauthenticated remote attacker can crash Java applications using Jackson-databind by transmitting JSON payloads with high-cardinality, unrecognized polymorphic type IDs, causing unbounded memory retention and JVM heap exhaustion.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400
  • Attack Vector: Network
  • CVSS Severity: 7.5 (High)
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed
  • Vulnerability Class: Uncontrolled Resource Consumption

Affected Systems

  • FasterXML jackson-databind versions 2.0.0 through 2.18.10
  • FasterXML jackson-databind versions 2.19.0 through 2.21.6
  • FasterXML jackson-databind versions 2.22.0 through 2.22.2
  • FasterXML jackson-databind versions 3.0.0 through 3.1.6
  • FasterXML jackson-databind versions 3.2.0 through 3.2.2
  • jackson-databind: >= 2.0.0, <= 2.18.10 (Fixed in: 2.18.11)
  • jackson-databind: >= 2.19.0, <= 2.21.6 (Fixed in: 2.21.7)
  • jackson-databind: >= 2.22.0, <= 2.22.2 (Fixed in: 2.22.3)
  • jackson-databind: >= 3.0.0, <= 3.1.6 (Fixed in: 3.1.7)
  • jackson-databind: >= 3.2.0, <= 3.2.2 (Fixed in: 3.2.3)

Code Analysis

Commit: 2870d1d

Bound the cache used for type deserializers in TypeDeserializerBase to address CVE-2026-91776

@@ -23,6 +23,22 @@ public abstract class TypeDeserializerBase\n+\n+    final static int MAX_CACHED_TYPE_IDS = 1000;\n+    final static int MAX_CACHED_TYPE_ID_LENGTH = 256;\n...\n+            if (typeId.length() > MAX_CACHED_TYPE_ID_LENGTH) {\n+                return deser;\n+            }\n+            if (_deserializers.size() >= MAX_CACHED_TYPE_IDS) {\n+                _deserializers.clear();\n+            }\n+            _deserializers.put(typeId, deser);

Exploit Details

  • GitHub: Issue report detailing reproduction steps and JUnit test cases for uncontrolled polymorphic cache growth.

Mitigation Strategies

  • Upgrade the jackson-databind library to a patched version immediately.
  • Refactor polymorphic type definitions to remove defaultImpl fallback configurations where possible.
  • Implement a custom TypeIdResolver that strictly validates type IDs against an allowlist before resolution.
  • Deploy WAF rules to drop payloads containing abnormally long polymorphic type identifiers.

Remediation Steps:

  1. Analyze dependency structures (using Maven or Gradle) to identify references to vulnerable jackson-databind versions.
  2. Update Maven pom.xml or Gradle build.gradle files to specify a patched version (e.g., 2.18.11, 2.21.7, 2.22.3, 3.1.7, or 3.2.3).
  3. Run integration tests to confirm compatibility with the updated library, paying special attention to polymorphic deserialization tests.
  4. Deploy the updated build artifacts to staging and production environments.

References

Read the full report for CVE-2026-91776 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.