CVE-2026-59888Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 208-17
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Full discourse2 posts
  • HeroDevs@herodevs
    Patch

    A Record component annotated JsonIgnore. A request body sending "is_admin": true. It gets through anyway. CVE-2026-59888 — 6.5 Medium in jackson-databind. The ignore list is built before the naming strategy renames the key, so the renamed key never matches it. Fixed in 2.18.8, 2.21.4, 3.1.4. Spring Boot 3.1–3.4 are EOL and won't get it. #Java #Jackson #SpringBoot

    Post summary

    The post explains CVE‑2026‑59888 in jackson‑databind, how the ignore-list bug permits bypass of JsonIgnore, and confirms it is patched in recent releases while older Spring Boot versions will not receive updates.

    10020250
    2.7K followersView on X
  • HeroDevs@herodevs
    Disclosure

    Learn more 🔗 https://www.herodevs.com/blog-posts/cve-2026-59888-jackson-record-jsonignore-bypass-via-naming-strategy?utm_source=x-twitter&utm_medium=organic-social&utm_campaign=compliance-clock_global&utm_content=post_none_20260817_a

    Post summary

    The tweet links to a blog post about CVE‑2026‑59888, detailing a Jackson @JsonIgnore bypass via naming strategy. No evidence of an active exploit, PoC, or patch is mentioned.

    0000043
    2.7K followersView on X

Explore more