Feed/CVE-2026-59888
CVE-2026-59888MEDIUMCVSS 6.5

CVE-2026-59888

Published Jul 14, 2026·Updated Jul 21, 2026

NVD Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

Affected Packages (2)

tools.jackson.core:jackson-databindMAVEN
From 3.0.0
Fixed in 3.1.4
com.fasterxml.jackson.core:jackson-databindMAVEN
From 2.15.0
Fixed in 2.18.8

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free