CVE-2026-54514: medium-severity vulnerability in FasterXML jackson-databind
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
FasterXML · jackson-databindRelated CVEs — FasterXML jackson-databind
In the same product, most dangerous first.
CVE-2017-7525—CVE-2017-7525EPSS 37.7%CVE-2017-15095—CVE-2017-15095EPSS 8.4%CVE-2026-54513HIGHjackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)EPSS 1.2%CVE-2026-54512HIGHjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEPSS 1.0%CVE-2026-83557MEDIUMjackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base typesEPSS 0.7%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%