
A Record component annotated JsonIgnore. A request body sending "is_admin": true. It gets through anyway. CVE-2026-59888 — 6.5 Medium in jackson-databind. The ignore list is built before the naming strategy renames the key, so the renamed key never matches it. Fixed in 2.18.8, 2.21.4, 3.1.4. Spring Boot 3.1–3.4 are EOL and won't get it. #Java #Jackson #SpringBoot
Post summary
The post explains CVE‑2026‑59888 in jackson‑databind, how the ignore-list bug permits bypass of JsonIgnore, and confirms it is patched in recent releases while older Spring Boot versions will not receive updates.
