CVE-2026-54515Disclosure(fasterxml / jackson-databind)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jackson-databind

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
jackson-databind

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Technical Details · 2026-06-23: 206-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-54515 Deserialization Property Bypass in jackson-databind via Case-Insensitivity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54515

    Post summary

    The post lists CVE‑2026‑54515 with a brief description of a deserialization property bypass in jackson‑databind, but offers no PoC, exploit code, active usage, patch or detailed technical metrics.

    0000089
    4.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Jackson-databind, Case-Insensitive Deserialization Bypass, #CVE-2026-54515 (Medium) -DC-Jun2026-603 https://dailycve.com/jackson-databind-case-insensitive-deserialization-bypass-cve-2026-54515-medium-dc-jun2026-603/

    Post summary

    The post announces a new moderate‑severity CVE (CVE-2026-54515) affecting Jackson‑databind, identifying a case‑insensitive deserialization bypass, without providing PoC, exploit, or patch details.

    0000044
    216 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfasterxmljackson-databind---
Appfasterxmljackson-databind2.22.0--

Explore more