FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

jackson-databind -- multiple vulnerabilities

Affected packages
jackson-databind < 2.22.2

Details

VuXML ID 0cb401f9-9f19-11f1-a655-3497f65b111b
Discovery 2026-05-28
Entry 2026-08-23

The Jackson project reports:

PolymorphicTypeValidator needs to validate generic type parameters too

BasicPolymorphicTypeValidator setting allowIfSubTypeIsArray() should validate element type

Add java.lang.Comparable in set of "unsafe" polymorphic base types

@JsonView by-passed for @JsonUnwrapped Field/Setter properties

@JsonView by-passed for some "setterless" creator properties

@JsonView by-passed for unwrapped creator parameters

Honor @JsonView for external-type-id (EXTERNAL_PROPERTY) properties

Renamed @JsonIgnore'd setters can deserialize via private fields

@JsonIgnore on Record property ignored with PropertyNamingStrategy

Case-insensitive deserialization may use wrong @JsonIgnoreProperties

Do not allow DNS resolution when deserializing InetAddress

Improve InetSocketAddress deserialization

Limit the supported URL schemes for java.nio.file.Path deserialization

Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration

References

CVE Name CVE-2026-19032
CVE Name CVE-2026-54512
CVE Name CVE-2026-54513
CVE Name CVE-2026-54514
CVE Name CVE-2026-54515
CVE Name CVE-2026-54516
CVE Name CVE-2026-54517
CVE Name CVE-2026-54518
CVE Name CVE-2026-59888
CVE Name CVE-2026-59889
CVE Name CVE-2026-68497
CVE Name CVE-2026-77310
URL https://github.com/advisories/GHSA-mhm7-754m-9p8w
URL https://github.com/FasterXML/jackson-databind/blob/2.x/release-notes/VERSION-2.x